Different perspective here: we @ GBG are in the process of moving our business to business applications away from local user identities in each app to a federated solution so our customers can use their IAM solution (typically Azure AD via OIDC), which is a win-win:

  • we no longer have to maintain multiple IAM systems (significant amounts of the codebase in multiple stove pipe products)
  • they retain control of access for individuals through their IAM processes, avoiding having to manage the same identities elsewhere
  • they get SSO for our services.
