PageSourceSearch

https://goauthentik.io/assets/js/14079d13.7d2fa6a5.js

js goauthentik.io collected 2026-09-24 08:39:09 UTC 20,236 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunk_goauthentik_www=self.webpackChunk_goauthentik_www||[]).push([["41649"],{5025(e,t,n){n.r(t),n.d(t,{assets:()=>l,contentTitle:()=>a,default:()=>c,frontMatter:()=>r,metadata:()=>i,toc:()=>h});var i=n(68066),s=n(94686),o=n(23191);let r={title:"Consolidating IAM without disruption",description:"Breaking up with your identity provider(s) doesn't have to be painful.",slug:"2026-07-28-consolidating-iam",authors:["fletcher"],hide_table_of_contents:!1},a,l={authorsImageUrls:[void 0]},h=[{value:"Fragmentation is an inevitable byproduct",id:"fragmentation-is-an-inevitable-byproduct",level:2},{value:"The real cost isn&#39;t just the SaaS invoice",id:"the-real-cost-isnt-just-the-saas-invoice",level:2},{value:"The goal: consolidation without rip-and-replace",id:"the-goal-consolidation-without-rip-and-replace",level:2},{value:"Step 0: Name your single source of truth",id:"step-0-name-your-single-source-of-truth",level:2},{value:"Step 1: Decide what to consolidate, retire, or keep",id:"step-1-decide-what-to-consolidate-retire-or-keep",level:2},{value:"Step 2: Stand up a proven system <em>before</em> you migrate anything",id:"step-2-stand-up-a-proven-system-before-you-migrate-anything",level:2},{value:"Step 3: Keep user friction to a bare minimum",id:"step-3-keep-user-friction-to-a-bare-minimum",level:2},{value:"Step 4: When legacy has to stay, automate the seam",id:"step-4-when-legacy-has-to-stay-automate-the-seam",level:2},{value:"Step 5: Let modern tooling do the work",id:"step-5-let-modern-tooling-do-the-work",level:2},{value:"Make the cost of the status quo impossible to ignore",id:"make-the-cost-of-the-status-quo-impossible-to-ignore",level:2},{value:"What consolidation success actually looks like",id:"what-consolidation-success-actually-looks-like",level:2}];function d(e){let t={a:"a",blockquote:"blockquote",em:"em",h2:"h2",hr:"hr",img:"img",li:"li",ol:"ol",p:"p",strong:"strong",ul:"ul",...(0,o.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.p,{children:"Every identity environment we've seen looks the same after a few years: too many directories, too many login screens, and nobody who can say with certainty who has access to what. Nobody designs it this way. It emerges over time."}),"\n",(0,s.jsx)(t.p,{children:"This post is a practical playbook for pulling IAM together: how to decide what to consolidate, retire, or leave alone, where the real friction lives, and how to modernize legacy identity without a single disruptive cutover."}),"\n",(0,s.jsx)(t.h2,{id:"fragmentation-is-an-inevitable-byproduct",children:"Fragmentation is an inevitable byproduct"}),"\n",(0,s.jsx)(t.p,{children:"If you inherited a messy identity environment, you're not alone. Fragmentation is what happens naturally as an organization grows, and it tends to arrive from four directions at once:"}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Legacy apps"})," \u2014 on-prem directories that pre-date the cloud and were never meant to talk to anything outside the building."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Cloud & SaaS"})," \u2014 every new service showing up with its own login, its own user groups, its own features and limitations."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Acquisitions"})," \u2014 whole identity stacks and teams inherited overnight, complete with their own quirks and technical debt."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"YOLO"})," \u2014 teams standing up whatever they needed, whenever they needed it, because waiting for a centralized solution wasn't an option."]}),"\n"]}),"\n",(0,s.jsx)(t.p,{children:"None of these are bad decisions in isolation, but they add up to a tangled web of user directories and partial IAM solutions."}),"\n",(0,s.jsx)(t.h2,{id:"the-real-cost-isnt-just-the-saas-invoice",children:"The real cost isn't just the SaaS invoice"}),"\n",(0,s.jsx)(t.p,{children:"Fragmentation is expensive in ways that don't show up cleanly on a bill:"}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Harder to maintain."})," Every platform has its own upgrade path, its own on-call rotation, and its own unique set of failure modes. Multiply that by however many identity systems you're running, and you've got a permanent tax on your engineering org."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Harder to secure."})," Inconsistent policies across systems, orphaned accounts that nobody remembers creating, and no single view of who actually has access to what, leading to needlessly complex systems and breaches."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"More expensive to run."})," Duplicate users mean duplicate licenses stacked on top of each other, and licenses are rarely the only cost. The real cost is the time spent keeping all of it alive."]}),"\n"]}),"\n",(0,s.jsxs)(t.p,{children:["The largest line item is almost never the SaaS invoice. It's the ",(0,s.jsx)(t.strong,{children:"engineering hours"})," spent babysitting fragmented systems. And the hardest cost to quantify \u2014 but arguably the most important \u2014 is the ",(0,s.jsx)(t.strong,{children:"reputation cost"})," of unreliable authentication. When login breaks, everything breaks, and your company's reputation suffers the fallout."]}),"\n",(0,s.jsx)(t.h2,{id:"the-goal-consolidation-without-rip-and-replace",children:"The goal: consolidation without rip-and-replace"}),"\n",(0,s.jsx)(t.p,{children:"You can't afford a \"day zero\" cutover for thousands or millions of users across dozens of critical systems. A hard switch is a single point of failure for everyone's ability to log in and access your systems."}),"\n",(0,s.jsxs)(t.p,{children:["The strategy that actually works is a ",(0,s.jsx)(t.strong,{children:"seamless, gradual migration"})," \u2014 standing up new systems alongside what already exists, testing them out, and migrating without surprises. Below is the step-by-step guide to implementing that strategy."]}),"\n",(0,s.jsx)(t.hr,{}),"\n",(0,s.jsx)(t.h2,{id:"step-0-name-your-single-source-of-truth",children:"Step 0: Name your single source of truth"}),"\n",(0,s.jsxs)(t.p,{children:["Before touching any migration tooling, pick the one place where user data must be accurate \u2014 ",(0,s.jsx)(t.strong,{children:"the source of truth"})," for every other system."]}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:["Every other directory becomes a ",(0,s.jsx)(t.strong,{children:"downstream consumer"}),", not a peer."]}),"\n",(0,s.jsxs)(t.li,{children:["This source ",(0,s.jsx)(t.em,{children:"can"})," change over the course of a migration, but there needs to be exactly ",(0,s.jsx)(t.strong,{children:"one at a time"}),"."]}),"\n"]}),"\n",(0,s.jsx)(t.p,{children:"For some organizations, this is simple: Active Directory is their source of truth, full stop. For others, especially those mid-acquisition or mid-migration, the source of truth might shift across multiple identity providers in a deliberate, multi-step process. Either way, name it explicitly before you do anything else."}),"\n",(0,s.jsx)(t.h2,{id:"step-1-decide-what-to-consolidate-retire-or-keep",children:"Step 1: Decide what to consolidate, retire, or keep"}),"\n",(0,s.jsx)(t.p,{children:"Once you know your source of truth, sort every existing identity system into one of three buckets:"}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Consolidate"})," active systems with overlapping purpose \u2014 but only once you've confirmed feature parity in whatever remains. Don't consolidate away functionality people actually depend on. For our customers, this typically takes the form of a very detailed spreadsheet comparing the features and functionality of each system that are actually relied upon."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Retire"})," low-value, unmaintained systems in phases. Sunset them only after functionality and data have already been migrated elsewhere \u2014 never before."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Keep"})," the systems you genuinely can't remove yet. Integrate with them and automate the handoff instead; more on that below."]}),"\n"]}),"\n",(0,s.jsxs)(t.p,{children:["Your source of truth might be functionally limited, for instance if it's just a simple legacy directory. That doesn't mean your ",(0,s.jsx)(t.em,{children:"consolidated IAM system"})," has to inherit those limitations. The target state can be far more capable than what you're migrating away from."]}),"\n",(0,s.jsxs)(t.h2,{id:"step-2-stand-up-a-proven-system-before-you-migrate-anything",children:["Step 2: Stand up a proven system ",(0,s.jsx)(t.em,{children:"before"})," you migrate anything"]}),"\n",(0,s.jsx)(t.p,{children:"This is the step most rip-and-replace horror stories skip. Before you migrate a single user, you need a tested, production-grade parallel path, not a leap-of-faith cutover."}),"\n",(0,s.jsx)(t.p,{children:"In practice, that looks like:"}),"\n",(0,s.jsxs)(t.ol,{children:["\n",(0,s.jsxs)(t.li,{children:["Build the consolidated system out in a ",(0,s.jsx)(t.strong,{children:"test environment"})," first."]}),"\n",(0,s.jsxs)(t.li,{children:["Then run it ",(0,s.jsx)(t.strong,{children:"alongside production, in parallel"})," \u2014 not replacing anything yet."]}),"\n",(0,s.jsxs)(t.li,{children:["Integrate it into your existing systems and let it ",(0,s.jsx)(t.strong,{children:"carry real traffic"})," before it ever becomes part of the critical path."]}),"\n",(0,s.jsxs)(t.li,{children:["Only migrate and consolidate once it's fully synced and ",(0,s.jsx)(t.strong,{children:"proven"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:"Cloudflare"})," is a good example of this process in practice. When they migrated to authentik in under three weeks, the first two weeks were spent standing up and testing a production-grade instance against every system and app in their environment, making sure all user and group data was fully synced. Once that instance had proven itself, employees were seamlessly redirected to authentik to authenticate as usual, allowing the previous provider to be retired."]}
1),"\n",(0,s.jsx)(t.h2,{id:"step-3-keep-user-friction-to-a-bare-minimum",children:"Step 3: Keep user friction to a bare minimum"}),"\n",(0,s.jsx)(t.p,{children:"Every manual step you ask an end user to take is another hazard to a smooth migration \u2014 another support ticket, another point of failure, another reason people notice the change at all. The goal is for the migration to be invisible to the people going through it."}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Redirect login pages:"})," Point existing login URLs at the new provider, so users do not need to learn a new address."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Hand off sessions silently:"})," Adopt existing user data and sessions, mapping attributes as needed without requiring any user action."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Avoid re-enrollment:"})," Do not require users to reset passwords, re-register MFA, or re-enter profile data; otherwise, the migration is no longer invisible."]}),"\n"]}),"\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:"SUSE"})," managed exactly this kind of transition for every customer, partner, and community member during their recent ",(0,s.jsx)(t.a,{href:"https://www.suse.com/c/empowering-our-ecosystem-enhancing-security-and-sovereignty-with-suseid/",children:"identity migration"}),", with authentik tying everything together behind the scenes. The messaging to end users said it plainly:"]}),"\n",(0,s.jsxs)(t.blockquote,{children:["\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.em,{children:'"Your experience remains unchanged. You will continue to navigate to your usual portals and log in with your existing credentials."'})}),"\n"]}),"\n",(0,s.jsx)(t.p,{children:"The only visible change was a refreshed login screen and a new URL \u2014 everything else was invisible to the end user."}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.a,{href:"https://www.suse.com/c/empowering-our-ecosystem-enhancing-security-and-sovereignty-with-suseid/",children:(0,s.jsx)(t.img,{alt:"SUSEID blog post",src:n(17399).A+"",width:"1890",height:"1568"})})}),"\n",(0,s.jsx)(t.h2,{id:"step-4-when-legacy-has-to-stay-automate-the-seam",children:"Step 4: When legacy has to stay, automate the seam"}),"\n",(0,s.jsxs)(t.p,{children:["Some systems genuinely can't move, whether because of regulatory requirements, vendor lock-in, or because they're too deeply embedded to touch. In those cases, the goal changes: you\u2019re not trying to get rid of the system \u2014 you're trying to get rid of the ",(0,s.jsx)(t.strong,{children:"burden"})," of maintaining it."]}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:["Put ",(0,s.jsx)(t.strong,{children:"APIs and automations"})," in front of the legacy system to hand off user data cleanly."]}),"\n",(0,s.jsx)(t.li,{children:"The legacy system stays exactly where it is \u2014 but the manual maintenance around it disappears. Even when a system doesn't support SSO, a modern identity provider should be able to layer on SSO with a reverse proxy in front of the legacy tech."}),"\n"]}),"\n",(0,s.jsx)(t.p,{children:"These sorts of limitations show up frequently with our customers in financial and healthcare spaces, where certain legacy systems and datastores are effectively immovable. Modern tooling can absorb the effort of interfacing with these systems through data mapping and automation, so the legacy system becomes a quiet dependency instead of an ongoing operational headache."}),"\n",(0,s.jsx)(t.h2,{id:"step-5-let-modern-tooling-do-the-work",children:"Step 5: Let modern tooling do the work"}),"\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:'"We\'d have to reconfigure hundreds of apps by hand"'})," is the single most common blocker that teams cite when they consider consolidation. Good news: this is now a largely solved problem and ",(0,s.jsx)(t.em,{children:"much"})," easier to handle than just a couple of years ago. This work should mostly be automatable and testable, not a manual slog."]}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Automate SSO configuration:"}
1)," Configure hundreds of applications through scripts or by importing settings from an existing provider, rather than relying on error-prone ClickOps one login flow at a time."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Provision and validate in staging:"})," Use automation to identify configuration issues before they reach production. Agents can automate much of the work, but always validate the results before applying to production."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Use APIs for everything:"})," A modern identity platform should expose APIs for every core function, so you can retire the homegrown, manually maintained glue scripts built out of necessity."]}),"\n"]}),"\n",(0,s.jsx)(t.hr,{}),"\n",(0,s.jsx)(t.h2,{id:"make-the-cost-of-the-status-quo-impossible-to-ignore",children:"Make the cost of the status quo impossible to ignore"}),"\n",(0,s.jsx)(t.p,{children:"Getting buy-in for a consolidation project is its own challenge, and often just as important to handle as the technical migration. Some strategies that we have seen work well:"}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Start small:"})," Motivate the change with a standalone project or an IdP backup solution \u2014 something low-risk, low-cost, and with a visible win attached."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Prove, then expand:"})," Show the new system working before asking anyone to bet the rest of the org on it. Grow its scope gradually and replace old systems as confidence builds."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Make the cost obvious:"})," Name the ongoing costs beyond the SaaS subscription line \u2014 system reliability and the engineering time spent keeping fragmented systems alive."]}),"\n"]}),"\n",(0,s.jsxs)(t.p,{children:["Swiss retailer ",(0,s.jsx)(t.strong,{children:"On"}),' is a good illustration of the "start small" path. They first deployed authentik for their customer returns portal, an important but self-contained rollout. The success of that project gave their team the evidence they needed to demonstrate the value of a full IAM replacement to management. From there, they were able to grow the deployment into a consolidated identity system that will serve millions of user accounts.']}),"\n",(0,s.jsx)(t.h2,{id:"what-consolidation-success-actually-looks-like",children:"What consolidation success actually looks like"}),"\n",(0,s.jsx)(t.p,{children:"If you get all of this right, the end state looks like:"}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"A single source of truth:"})," Reflected consistently everywhere else."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"An invisible user experience:"})," No re-enrollment, no new URLs to memorize, and no support tickets asking why login broke."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"A clear business case:"})," The real cost of the status quo is visible beyond the SaaS subscription line."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"A proven migration path:"})," No hard cutovers or leap-of-faith weekends."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.strong,{children:"Automated legacy operations:"})," Systems that cannot move do not need a dedicated team babysitting them forever."]}),"\n"]}),"\n",(0,s.jsx)(t.p,{children:"Consolidation doesn't have to mean disruption. Done right, the change is invisible to the people who depend on it every day \u2014 and that's exactly the goal."}),"\n",(0,s.jsxs)(t.p,{children:["We have helped hundreds of users and organizations consolidate their IAM stacks. If you are ready to take control of your identity and access needs, ",(0,s.jsx)(t.a,{href:"https://docs.goauthentik.io/enterprise/",children:"get in touch with our team"}),"."]})]})}function c(e={}){let{wrapper:t}={...(0,o.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},17399(e,t,n){n.d(t,{A:()=>i});let i=n.p+"assets/images/image1-a98f316a1f0730d48320173aa85c685d.png"}
1,23191(e,t,n){n.d(t,{R:()=>r,x:()=>a});var i=n(92990);let s={},o=i.createContext(s);function r(e){let t=i.useContext(o);return i.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:r(e.components),i.createElement(o.Provider,{value:t},e.children)}},68066(e){e.exports=JSON.parse('{"permalink":"/blog/2026-07-28-consolidating-iam","source":"@site/blog/2026-07-28-consolidating-iam/item.md","title":"Consolidating IAM without disruption","description":"Breaking up with your identity provider(s) doesn\'t have to be painful.","date":"2026-07-28T00:00:00.000Z","tags":[],"readingTime":9.04,"hasTruncateMarker":true,"authors":[{"name":"Fletcher Heisler","title":"CEO at Authentik Security Inc","url":"https://www.linkedin.com/in/fheisler/","page":{"permalink":"/blog/authors/fletcher"},"imageURL":"/img/people/fletcher.png","key":"fletcher"}],"frontMatter":{"title":"Consolidating IAM without disruption","description":"Breaking up with your identity provider(s) doesn\'t have to be painful.","slug":"2026-07-28-consolidating-iam","authors":["fletcher"],"hide_table_of_contents":false},"unlisted":false,"prevItem":{"title":"authentik version 2026.8 is here!","permalink":"/blog/2026-09-01-authentik-version-2026-8"},"nextItem":{"title":"authentik version 2026.5 is here!","permalink":"/blog/2026-05-22-authentik-version-2026-5"}}')}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.