---
title: CIAM - Flexible authentication
---

- [Download a trial](https://www.openiam.com/download-a-trial)
- [Sales](https://www.openiam.com/contact-sales)
- [Support](https://openiam-help.freshdesk.com/support/login)
- [Login](https://help.openiam.com/knowledge)

[![logo](https://www.openiam.com/hubfs/logo.svg "logo")](https://www.openiam.com/?hsLang=en)

- [Home](https://www.openiam.com)
- Products
- Solutions
- Partners
- About Us
- Consulting
- Resources

[Request a Quote** ](https://www.openiam.com/request-a-quote?hsLang=en)

- Workforce Identity* *
- Customer Identity* *
- Comparison* *
- Subscriptions* *

<https://www.openiam.com/workforce-identity?hsLang=en>

#### All Features

Overview of all features in Workforce Identity

<https://www.openiam.com/automate-user-onboarding-and-offboarding?hsLang=en>

#### User Onboarding and Offboarding

Automate joiner, mover, leaver processes

<https://www.openiam.com/workflow-based-access-request?hsLang=en>

#### Access Request

Access requests with multi-step approvals

<https://www.openiam.com/user-access-reviews?hsLang=en>

#### User Access Reviews

Save time with user access reviews

<https://www.openiam.com/self-service-portal-wfi?hsLang=en>

#### Self-Service Portal

Self-service portal for all end user activities

<https://www.openiam.com/segregation-of-duties?hsLang=en>

#### Segregation of Duties

Detect and remediate SoD violations

<https://www.openiam.com/password-management?hsLang=en>

#### Password Management

Enforce password policies and enable synchronization

<https://www.openiam.com/single-sign-on?hsLang=en>

#### Single Sign-On (SSO)

Enable SSO using standards - SAML, oAuth, OIDC

<https://www.openiam.com/authentication-and-mfa-wfi?hsLang=en>

#### Authentication and MFA

Improve security with adaptive authentication and MFA

<https://www.openiam.com/3rd-party-idp-integration?hsLang=en>

#### 3rd Party IdP Integration

Integrate with your existing identity provider

<https://www.openiam.com/integration-api?hsLang=en>

#### Integration API

Use the REST API to add identity into your applications

<https://www.openiam.com/connector-library?hsLang=en>

#### Connector Library

Integrate on-premise and SaaS applications

<https://www.openiam.com/modern-architecture?hsLang=en>

#### Modern Architecture

Microservice architecture that supports deployment using RPM, Kubernetes or OpenShift

<https://www.openiam.com/workforce-identity-concepts?hsLang=en>

#### Workforce Identity Concepts

<https://www.openiam.com/customer-identity?hsLang=en>

#### All Features

Overview of all features in Customer IAM

<https://www.openiam.com/authentication-and-mfa-wfi?hsLang=en>

#### Authentication and MFA

Improve security with adaptive authentication and MFA 

<https://www.openiam.com/single-sign-on?hsLang=en>

#### Single Sign-On (SSO)

Enable SSO using standards - SAML, oAuth, OIDC

<https://www.openiam.com/password-management?hsLang=en>

#### Password Management

Enforce password policies and enable synchronization

<https://www.openiam.com/modern-architecture?hsLang=en>

#### Modern Architecture

Microservice architecture that supports deployment using RPM, Kubernetes or OpenShift

<https://www.openiam.com/customer-identity-concepts?hsLang=en>

#### Customer Identity Concepts

<https://www.openiam.com/ce-vs-ee?hsLang=en>

#### Community vs Enterprise

Summary of the differences between the Community and Enterprise editions

<https://www.openiam.com/subscriptions?hsLang=en>

#### Subscription Benefits

Overview of the benefits provided by an OpenIAM subscription

- Integrations* *
- Verticals * *
- Workforce Use Cases* *
- CIAM Use Cases* *
- Compliance* *
- Data Breach Mitigation* *

<https://www.openiam.com/solutions-for-managing-active-directory?hsLang=en>

#### Active Directory

<https://www.openiam.com/solutions-for-azure-o365?hsLang=en>

#### Azure (O365)

<https://www.openiam.com/solutions/sap-compliance?hsLang=en>

#### SAP

<https://www.openiam.com/solutions-for-workday?hsLang=en>

#### Workday

<https://www.openiam.com/solutions-for-aws?hsLang=en>

#### AWS

<https://www.openiam.com/solutions-for-linux-server?hsLang=en>

#### Linux Server

<https://www.openiam.com/solutions-for-ldap?hsLang=en>

#### LDAP

<https://www.openiam.com/solutions-for-sql-server?hsLang=en>

#### Microsoft SQL Server

<https://www.openiam.com/solutions-for-google-cloud?hsLang=en>

#### Google Cloud

<https://www.openiam.com/solutions-for-windows-server?hsLang=en>

#### Windows Server

<https://www.openiam.com/solutions-for-oracle-ebs?hsLang=en>

#### Oracle EBS

<https://www.openiam.com/solutions-for-servicenow?hsLang=en>

#### ServiceNow

<https://www.openiam.com/solutions-for-oracle-fusion?hsLang=en>

#### Oracle Fusion

<https://www.openiam.com/solutions-for-entra-id?hsLang=en>

#### Entra ID

<https://www.openiam.com/solutions-for-salesforce?hsLang=en>

#### Salesforce

<https://www.openiam.com/solutions-for-keycloak?hsLang=en>

#### Keycloak

<https://www.openiam.com/solutions-for-custom-applications?hsLang=en>

#### Custom Applications

<https://www.openiam.com/solutions-for-education?hsLang=en>

#### Education

Manage identity for students, staff and alumni

<https://www.openiam.com/solutions-for-financial-services?hsLang=en>

#### Financial Services

Address the compliance and security challenges of the financial sector

<https://www.openiam.com/solutions/manufacturing?hsLang=en>

#### Manufacturing

<https://www.openiam.com/use-cases/identity-governance?hsLang=en>

#### Identity Governance That Works in Practice

<https://www.openiam.com/solutions/access-governance?hsLang=en>

#### Access Governance

<https://www.openiam.com/use-cases/ciam-for-regulated-industries?hsLang=en>

#### CIAM for Regulated Industries

<https://www.openiam.com/solutions-nis2-compliance?hsLang=en>

#### NIS2

Achieve compliance with the EU directive for cybersecurity frameworks.

<https://www.openiam.com/solutions-dora-compliance?hsLang=en>

#### DORA

Comply with the Digital Operational Resilience Act for the EU.

<https://www.openiam.com/solutions-for-hipaa-compliance?hsLang=en>

#### HIPAA

For healthcare organizations seeking HIPAA compliance.

<https://www.openiam.com/solutions-for-pci-compliance?hsLang=en>

#### PCI DSS

Compliance with the Payment Card Industry Data Security Standard

<https://www.openiam.com/solutions-for-soc-2-compliance?hsLang=en>

#### SOC 2

Solutions for organizations subject to SOC 2 audits

<https://www.openiam.com/solutions-for-gdpr-compliance?hsLang=en>

#### GDPR

Take advantage of OpenIAM to comply with the General Data Protection Regulation

<https://www.openiam.com/social-engineering-attacks?hsLang=en>

#### Social Engineering Attacks

- Partners* *

<https://www.openiam.com/current-partners?hsLang=en>

#### Current Partners

Our Current Partners

<https://www.openiam.com/partner-registration?hsLang=en>

#### Partner Registration

- About Us* *

<https://www.openiam.com/about-openiam?hsLang=en>

#### About OpenIAM

Learn about OpenIAM

<https://www.openiam.com/press-releases?hsLang=en>

#### Press Releases

References to OpenIAM press releases

#### OpenIAM in the Media

References to OpenIAM in the media

<https://www.openiam.com/careers?hsLang=en>

#### Careers

Learn about open positions at OpenIAM.

- Consulting* *

<https://www.openiam.com/coming-soon?hsLang=en>

#### Proof of Value

Customized engagement to confirm defined proof of value objectives

<https://www.openiam.com/coming-soon?hsLang=en>

#### Jump Start

Customized engagement to rapidly deliver a solution into production

<https://www.openiam.com/coming-soon?hsLang=en>

#### Solution Implementation

Engagement with the objective to deliver a complete IAM solution based on customer requirements

- Resources* *

<https://www.youtube.com/c/OpeniamLLC>

#### Videos

Collection of videos describing how OpenIAM can be used to solve common use cases

<https://community.openiam.com/>

#### Community Portal

Collaborative community portal to learn more about OpenIAM

<https://docs.openiam.com/docs-4.2.1.15/>

#### CE Documentation

Documentation for the Community Edition

<https://www.openiam.com/blog?hsLang=en>

#### Blog

Musings on identity penned by the OpenIAM team

<https://www.openiam.com/webinar-calendar?hsLang=en>

#### Webinar Calendar

Upcoming webinars and training sessions

<https://www.openiam.com/workforce-identity-concepts?hsLang=en>

#### Workforce Identity Concepts

<https://www.openiam.com/customer-identity-concepts?hsLang=en>

#### Customer Identity Concepts

<https://www.openiam.com/resources/sap-sod-guide?hsLang=en>

#### SAP SoD Risk Reference for Manufacturing

# Use cases

## Problem

While some of the access that a user has can be defined as birthright access (access that is automatically granted based on some criteria), there may be other access that is not automatic. This access needs to be requested.

![image-06](https://www.openiam.com/hubfs/image-06.jpg)

### Organizations that have not implemented an IAM solution try to solve this problem using either:

- Excel-based forms that end-users complete and then submit to AD
- Service desk solutions like ServiceNow, Remedy or FreshService

### The problem with the first approach is that it’s cumbersome at best:

- The user has no visibility into a request
- Service desk staff must transfer the content manually
- No audit information

![image-07](https://www.openiam.com/hubfs/image-07.jpg)

![image-06](https://www.openiam.com/hubfs/image-06.jpg)

### Using a service desk solution also has problems:

- The service desk solutions are not connected with target systems and have no easy way to maintain an entitlement catalog
- Audit information is now distributed across applications which again increases the complexity of performing regular SOC-2 audits.

## Solution overview

OpenIAM’s Workforce Identity solution provides a comprehensive, easy to use access request solution.   
The sections below describe how OpenIAM can simplify access requests for both users  
and administrators.

### Rich entitlement catalog

Entitlements for each application can be imported into OpenIAM using the connectors or through a CSV file. Once loaded, these applications and their entitlements are available through the catalog in the self-service portal.

### Multi-level workflows

OpenIAM supports N levels of approvals. Approval flows can be defined at either the application or entitlement level. If there is consistency in the approval flow, then it can be defined at the application level and then over-ridden at the entitlement level if a particular entitlement has a different approval flow.

### Time-based access

OpenIAM supports the ability to request access for a specified length of time. Entitlements can also be configured with a “max duration period” where access cannot be requested for duration longer than is allowed by the duration parameter.

### Reminders and escalations

All workflows in OpenIAM support the ability to send reminders and to escalate when requests have not been processed in a timely manner.

### Delegation

In some cases, requests need to be reassigned to another reviewer. OpenIAM allows both individual and bulk delegation of requests. Similarly, out-of-office delegation can also be defined where requests are routed to another person. In the case of senior executives who do not want to receive such requests, a permanent delegate can be defined.

### Audit and compliance

With all operations being processed by OpenIAM, there is a detailed audit log which can be provided to auditors that shows how, why and when access was granted.

### Integration with ticket systems such as ServiceNow

Customers that use ServiceNow, FreshService or another ticket system can also leverage the OpenIAM catalog. Requestors can create tickets in OpenIAM and once the request has been approved, a notification is sent to the ticket system where service desk staff can follow their normal processes to full request.

## Let’s Connect

#### Managing identity can be complex. Let OpenIAM simplify how you manage all of your identities from a converged modern platform hosted on-premises or in the cloud.

For 15 years, OpenIAM has been helping mid to large enterprises globally improve security and end user satisfaction while lowering operational costs.

[Download a Trial** ](https://www.openiam.com/download-a-trial?hsLang=en) [Contact Sales** ](https://www.openiam.com/contact-sales?hsLang=en)

![footer-top-logo](https://www.openiam.com/hubfs/OpenIAM-2022/Images/SVG-Icons/footer-top-logo.svg)

[![openIAM-white-logo](https://www.openiam.com/hubfs/OpenIAM-2022/Site-Logo/openIAM-white-logo.svg "openIAM-white-logo")](https://openiam.com?hsLang=en)

All modules of our IAM platform share a common infrastructure allowing customers to see one unified identity solution versus a collection of disparate products.

- [![linkedin-icon](https://www.openiam.com/hubfs/OpenIAM-2022/Images/SVG-Icons/linkedin-icon.svg) ](https://www.linkedin.com/company/openiam-llc)
- [![facebook-icon](https://www.openiam.com/hubfs/OpenIAM-2022/Images/SVG-Icons/facebook-icon.svg) ](https://www.facebook.com/openiam)
- [![twitter-icon](https://www.openiam.com/hubfs/OpenIAM-2022/Images/SVG-Icons/twitter-icon.svg) ](https://twitter.com/openiam)
- [![youtube-icon](https://www.openiam.com/hubfs/OpenIAM-2022/Images/SVG-Icons/youtube-icon.svg) ](https://www.youtube.com/c/OpeniamLLC/featured)

[sales@openiam.com](mailto:sales@openiam.com)

[(858)935-7561](tel:(858)935-7561)

![](https://www.openiam.com/hubfs/OpenIAM-2022/Images/Pattern-Images/footer-bg-pattern.svg)

 Copyright © 2026 OpenIAM. All rights reserved.

- [Privacy Policy](https://www.openiam.com/privacy-policy)