What to Look for in Your Identity Cloud Provider
Download resourcesAbout this session
Jeffrey Carpenter of ForgeRock walks through the components of a modern identity cloud from the point of view of the customer, represented by an empty chair on stage: REST APIs and microservices in the Netflix model, an OAuth 2.0 authorization server backed by a token validation service, a registration engine that supports progressive profiling, social login and distributed identity, an orchestration layer of if-then flows, secure impersonation and CIBA so call-centre agents can act for a caller, an identity management directory for personalisation, and an authentication service moving toward passwordless. He then contrasts shared multi-tenant architectures, where one customer's traffic burst slows everyone else and a breach has a wide blast radius, with ForgeRock's isolated tenancy of dedicated endpoints, database and Kubernetes cluster. He closes with five things to check in an identity cloud provider: full capabilities including workforce and IoT identities, hybrid IT support, user experience across channels, security and compliance including data sovereignty and Schrems II, and predictability with dedicated backup and restore. One audience question covers building trust with older users.
Identity cloud providers may seem to offer similar services, but they are not the same. And in today's environment of escalating threats and growing regulatory requirements, it’s important to know the difference so that you can make an informed choice. You must consider security architecture, privacy controls, performance, and resilience — all essential ingredients of an identity cloud, and key to achieving your goal of stronger security and a great user experience. Join ForgeRock to unpack the essentials of a modern identity cloud. We will explore various architecture models and their impact on cloud resources. We’ll address data residency and data sovereignty through the privacy lens, and we’ll discuss architectural solutions for better breach protection. You’ll leave this session with a better understanding of the differences in architectural approaches, and you’ll learn what questions to ask identity cloud providers to ensure you get the solution you need.
Key takeaways
- Keep first-contact registration light and use progressive profiling: ask for an email or province, then collect more on later visits rather than a full enrolment up front.
- Design authentication as orchestration, a set of if-then flows that handle lost passwords, missing phones and step-up for high-value transactions without dropping the user.
- Ask an identity cloud provider whether tenants are isolated (own endpoints, database, compute) or share resources; shared tenancy means noisy-neighbour throttling and a wider breach blast radius.
- Treat IoT devices and service accounts as full identities with an owner, a lifecycle, authentication and authorization, since they now outnumber employees.
- Check data sovereignty and backup: data should never leave its region, and backups should be dedicated to your tenant rather than pooled with other customers.
Speakers

Jeff is passionate about securing identities of all types – human and machine. He is a seasoned professional with broad experience in access control, cryptography, biometrics, virtualization, cloud, mobile and network security. Having spent much of… Read moreRead less
Jeff is passionate about securing identities of all types – human and machine. He is a seasoned professional with broad experience in access control, cryptography, biometrics, virtualization, cloud, mobile and network security. Having spent much of his career in cyber security and identity, he has worked for leading companies in this space including RSA and HID Global. He finds his true calling bringing new and innovative solutions to market that ultimately enable us to interact and do more online. Jeff holds both CISSP and CCSP certifications.

