← All services
Service · Security

Identity management

One identity per person, provisioned and revoked in one place.

Typical timeline
3–8 weeks
Ongoing cadence
Quarterly review
Delivered by
ClearPath engineers

Identity is the real perimeter now. We consolidate applications behind your identity provider, enforce MFA and conditional access everywhere it can be enforced, and automate joiner-mover-leaver so access matches employment status without anyone remembering to check.

How we do the work

01 · Assess

We inventory apps, accounts, and auth methods, including legacy.

02 · Architect

We design the identity model: groups, roles, conditional access, privileged separation.

03 · Deploy

We federate apps behind the identity provider and retire legacy auth.

04 · Configure

We configure and test MFA, conditional access, and SCIM provisioning.

05 · Maintain

We review access quarterly and monitor sign-in risk with an honest joiner-mover-leaver process.

What the engagement includes

  • Application and account inventory
  • Group, role, and conditional access design
  • SSO federation and legacy auth retirement
  • Automated provisioning and deprovisioning
  • Quarterly access reviews

What you are left holding

  • Identity and access model documentation
  • Conditional access policy set
  • Provisioning workflow documentation
  • Quarterly access review report

Documentation is yours to keep, whether or not we keep working together.

You probably need this if…

  • Offboarding depends on someone remembering every system
  • Service accounts with non-expiring passwords
  • Legacy authentication still enabled tenant-wide

How you engage us

Same engineers either way. The difference is how much of the ongoing work stays with your team.

Option 01 · Project

Fixed scope, fixed outcome. We assess, architect, deploy, and hand over with documentation. Your team runs it from there.

Option 02 · Most common · Co-managed

We own the design, the hard changes, and after-hours cover. Your team keeps day-to-day control with our engineers on call.

Option 03 · Fully managed

End-to-end ownership against an SLA: monitoring, maintenance, and reporting, with a named engineer who knows your environment.

Let's scope Identity management against your environment.

An hour with one of our engineers gets you a realistic scope, a timeline, and an honest read on what to do first.