Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
An identity platform holds who exists, proves they are who they claim with one or more factors, and decides — per application, per device, per risk signal — whether this sign-in proceeds. Everything else on a vendor’s slide is a variation on those three jobs.
Microsoft Entra ID P1 lists at roughly $6–7 per user per month and is already inside Microsoft 365 E3. Most estates that buy a second identity provider are buying one specific gap: the VPN, the legacy application, or the SaaS Microsoft does not reach well.
Already decided — before the demo
Still yours to weigh
Three layers that get sold as one. The directory is the list of who exists and what they belong to. Single sign-on lets one authenticated session open many applications, so people stop keeping a password per system. Multi-factor authentication adds proof beyond the password — and the kind of proof matters enormously, because a push notification can be tapped by a tired person under attack and a hardware key cannot be phished at all.
The fourth thing, which no brochure leads with: most of what signs in is not a person. Service accounts, API consumers, CI/CD pipelines and now AI agents acting on a user’s behalf authenticate constantly, and workforce identity platforms handle them thinly. The vault-and-secrets half of that problem is the PAM guide; proving the access anyone holds was correct is the governance guide.
The most common mis-purchase
Customer identity bought as workforce identity, or the reverse. CIAM is priced per monthly active user at consumer volume; workforce identity is priced per employee. Put a million customers on a workforce meter and the bill is catastrophic; put employees on a CIAM platform and you have no lifecycle, no governance and no conditional access worth the name.
Often confused withPAM — what the most dangerous accounts may do once inside →·Identity Governance — proving the access granted was correct →·UEM & MDM — device trust as a condition of sign-in →·Zero Trust Access — ZTNA is only as good as the identity behind it →
The three routes of identity and access — and which one is yours →
Four words used interchangeably in the same sentence, plus the one split that changes the price by orders of magnitude. These are adjacent scopes, not tiers.
Directory
The list: who exists, what groups they belong to, what attributes they carry. Active Directory on premises, Entra ID, Okta Universal Directory, Google's directory. Everything else authenticates against it. Answers: does this person exist here, and what are they? It authenticates nothing on its own for modern SaaS.
SSO — single sign-on
One authenticated session opening many applications through SAML, OIDC or OAuth. Answers: how do people reach fifty applications without fifty passwords? It says nothing about how strongly the first sign-in was proved — which is why SSO without strong factors just makes one stolen password more useful.
MFA — multi-factor authentication
Proof beyond the password. Not one thing: SMS and push are phishable and vulnerable to fatigue attacks; FIDO2 security keys and passkeys are phishing-resistant by design. 'Supports MFA' is not an answer — ask which factors, and which accounts must use the strong ones.
Workforce vs customer identity (CIAM)
Same vocabulary, different products. Workforce identity governs employees and contractors: lifecycle, groups, conditional access, per-user pricing. CIAM handles customers at consumer volume: registration, social login, consent, progressive profiling, priced per monthly active user. Buying one for the other is the expensive mistake in this category.
Seven variables decide this purchase. The instrument tests what documentation establishes (audience, factors, legacy protocols, deployment, policy depth, India); what you already own and the machine-identity gap are prose, because the honest answer depends on your invoice and your pipelines.
What you already have, and where it stops
Entra ID P1 or P2, Google Workspace tier, on-premises Active Directory. Each covers real ground and stops somewhere specific — usually legacy protocols, non-Microsoft SaaS depth, or governance.
Workforce vs customer identity
Different products despite shared vocabulary, and different meters: per employee versus per monthly active user. The single most expensive thing to get wrong here.
Phishing-resistant MFA
FIDO2 security keys and passkeys versus push and one-time codes. Push fatigue is a live attack technique, not a theoretical one — documented FIDO2 support is recorded here per product, and marked unknown where the documentation does not establish it.
Directory sync and legacy application support
LDAP, RADIUS, header-based access and Kerberos for the applications that cannot speak SAML. This list decides shortlists more often than modern features do.
Conditional access depth
Full risk-based policy using device, network, location and behaviour signals — versus a simple allow rule. Depth is usually tier-gated, so read which tier the demo was on.
Machine and service-account authentication
Non-human identities outnumber human ones in most estates and workforce IAM handles them thinly. Know whether this platform is expected to cover them before you assume it does.
India residency for identity data
India-built and India-hosted options, documented in-country tenants (Okta launched these in 2026), or not documented — flagged rather than assumed.
Set what is true for you. A product that misses a constraint fades with its reason printed on it; where vendor documentation does not settle a capability it is flagged and stays. Every chip is reversible.
The applications you cannot replace
Who signs in
How it must run
Policy depth
Authentication strength
The machine half
India
Estate size
What you already own, push fatigue and the machine half are in the notes below rather than chips — the first depends on your invoice, and the other two are read across every product at once.

per user / month from the Workforce Identity starter list (SSO, adaptive MFA, Universal Directory); the Essentials bundle lists around $17 with governance and privileged access included; India in-country tenants launched 2026
Estates that want the vendor-neutral identity provider with the deepest application catalogue — thousands of pre-built integrations and no argument with any cloud.
The catch: Priced per user per month for each capability, so the total climbs fast — a mid-size estate wanting SSO plus lifecycle plus governance is realistically $18–25 per user per month before API security or device access. Service and workload authentication is not its strength.

bundled into the Workforce Identity tiers rather than sold alone; FIDO2 security keys and passkeys, device and network context, and risk-based step-up
Organisations moving off SMS and push onto phishing-resistant factors with risk signals deciding when to challenge at all.
The catch: Adaptive policy depth is tied to the tier you buy, and the strongest risk signals sit in the higher bundles. It authenticates people; workloads and service accounts are another conversation.

included in Workforce Identity tiers; a cloud directory that can be the source of truth or sit downstream of Active Directory and HR systems
Estates consolidating several directories, or moving the source of truth out of on-premises Active Directory without a big-bang migration.
The catch: It is a directory you rent: leaving means re-homing every profile, group and attribute mapping. Directory sync is the piece that breaks quietly, and it is your job to monitor.

per monthly active user, on a curve that starts free for small volumes and is quoted at scale; the Auth0 developer platform with passwordless, social login and machine-to-machine tokens
Product teams building sign-in for customers rather than employees — where volume is millions, not thousands, and the login page is part of the product.
The catch: Customer identity priced per monthly active user behaves nothing like workforce identity: at consumer scale the bill is a function of your growth, and buying it as workforce IAM (or the reverse) is the classic catastrophic mis-purchase.

add-on to Workforce Identity on quote; continuous session risk assessment with Universal Logout — ITDR, not authentication
Okta estates that want session hijacking and post-authentication risk handled continuously rather than only at the login prompt.
The catch: It detects and responds; it does not authenticate. Okta-centric by design — third-party signal ingestion is partner-dependent, and it is an extra line on an already per-capability bill.

workforce identity published from ₹180 per user / month; SAML, OAuth and OpenID Connect with unusually broad legacy support and an on-premises deployment option
Indian estates that want SSO at a fraction of the global list price, including for the legacy applications that cannot speak SAML.
The catch: The value option: documented deployments are smaller than Okta's or Microsoft's, and the application catalogue and ecosystem are narrower — flagged rather than ruled out above 10,000 users.

per user / month from the same published INR tiers; 15+ authentication methods including FIDO2 keys, passkeys, TOTP, push and hardware tokens
Cost-sensitive estates rolling out MFA broadly — including to contractors and shared-device workers where per-user global pricing hurts most.
The catch: Breadth of methods over depth of risk analytics: adaptive policy is present but less sophisticated than Okta's or Microsoft's. Mid-market scale.

per monthly active user or per-tenant quote, in INR; customer registration, social login, consent and progressive profiling with an India-hosted option
Indian consumer products that need customer sign-in with data kept in country and a price that survives millions of users.
The catch: Smaller ecosystem than Auth0 for developer tooling and extensibility; documented deployments are smaller. Consumer-scale references are the thing to ask for.

per user, quoted in INR; a cloud directory and LDAP service for estates with no Active Directory, or with one they are leaving
Organisations without an on-premises directory that still need LDAP-speaking applications to authenticate someone.
The catch: A directory rather than a full identity platform — the policy, MFA and SSO capabilities are the sibling SKUs. Phishing-resistant factors are documented at the MFA product, not here.

per user / month across the Essentials, Advantage and Premier tiers; MFA, device trust and Duo Passport, with VPN and RADIUS integration as a core strength
Estates whose priority is MFA in front of everything — including the VPN, the RDP jump box and the legacy application — with device health as a condition of access.
The catch: Authentication and device trust rather than a full identity provider: it does not replace your directory or run lifecycle. An India data region is not documented — flagged, not ruled out.

per module / year list (ADManager Plus, ADSelfService Plus, ADAudit Plus from about $595 each) bundled as AD360; India-built (Zoho), on-premises first, priced per module rather than per user
Active Directory estates that want SSO, MFA, self-service password reset, provisioning and AD auditing on their own servers, licensed per module.
The catch: Built around Active Directory: an AD-less, cloud-native estate is not its ground. Module licensing means the capability you add next is a new line item, and per-module lists are per component, not per user.

licensed by user capacity on a hardware or virtual appliance, quoted through the channel; RADIUS, SAML and certificate authority services alongside FortiToken
Fortinet estates that want authentication, certificates and two-factor tokens inside the fabric they already run, on premises.
The catch: Fabric-centric and appliance-shaped: as a general-purpose SSO for a SaaS-heavy estate it is far behind the identity-first vendors. Conditional access is basic compared with Okta or Entra.

per user / month, quoted in INR; multi-factor authentication built alongside InstaSafe's zero-trust access products, India-built and India-hosted
Indian estates buying MFA together with zero-trust application access from one India-built vendor, in INR.
The catch: Documented FIDO2 and passkey support could not be established from vendor documentation — marked unknown rather than assumed. Smaller catalogue and scale than the global options; strongest when bought with the ZTNA products.

per user, quoted in INR; the authenticator application itself — push, TOTP and device binding for InstaSafe and third-party services
Estates standardising on an India-hosted authenticator app rather than a global vendor's.
The catch: An authenticator, not an identity platform: no SSO, no directory, no lifecycle. Push-based factors are phishable — the reason phishing-resistant support matters, and it is not documented here.
per user, quoted in INR; identity and access with certificate-based and passwordless authentication from an Indian licensed certifying authority, with PKI for machine and document identity alongside
Indian regulated estates that want certificate-backed, passwordless identity from a domestic certifying authority — where the same vendor also issues the digital signatures the business already uses.
The catch: Strongest where PKI is the requirement; as a general workforce SSO the application catalogue is narrower than the identity-first vendors'. Documented deployment scale is smaller — flagged, not ruled out.

priced within Scalefusion's UEM plans rather than standalone; identity, conditional access and single sign-on tied to device trust from the UEM agent already on the endpoint
Scalefusion UEM estates that want sign-in conditioned on the device posture their management agent already reports, without a second vendor.
The catch: Device-trust-first identity: it assumes you run Scalefusion UEM, and as a standalone identity provider for a mixed estate it is not the purchase. FIDO2 and passkey support is not established from documentation.

priced inside Hexnode UEM plans; a directory and identity provider for managed devices, with conditional access driven by device compliance
Hexnode UEM estates wanting one console for the device and the identity on it, with compliance as a sign-in condition.
The catch: Bound to the Hexnode-managed fleet: unmanaged devices, contractors and the SaaS-only estate are not its ground. Phishing-resistant factor support is not documented.
LDAP applicationsRules out Okta Adaptive MFA, Okta Customer Identity (Auth0), Okta Identity Threat Protection, miniOrange MFA, miniOrange CIAM, InstaSafe MFA and InstaSafe Authenticator — LDAP application support not documented. That leaves Okta Single Sign-On, Okta Universal Directory, miniOrange SSO, miniOrange Directory, Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator, eMudhra SecurePass, Scalefusion OneIdP and Hexnode IdP.
RADIUS and VPNRules out Okta Universal Directory, Okta Customer Identity (Auth0), Okta Identity Threat Protection, miniOrange CIAM, miniOrange Directory, InstaSafe Authenticator, Scalefusion OneIdP and Hexnode IdP — RADIUS support not documented. That leaves Okta Single Sign-On, Okta Adaptive MFA, miniOrange SSO, miniOrange MFA, Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator, InstaSafe MFA and eMudhra SecurePass.
KerberosRules out Okta Single Sign-On, Okta Adaptive MFA, Okta Customer Identity (Auth0), Okta Identity Threat Protection, miniOrange MFA, miniOrange CIAM, Cisco Duo, InstaSafe MFA, InstaSafe Authenticator, eMudhra SecurePass, Scalefusion OneIdP and Hexnode IdP — Kerberos support not documented. That leaves Okta Universal Directory, miniOrange SSO, miniOrange Directory, ManageEngine AD360 and Fortinet FortiAuthenticator.
Workforce identityRules out Okta Customer Identity (Auth0) and miniOrange CIAM — a customer identity product, priced per monthly active user. That leaves Okta Single Sign-On, Okta Adaptive MFA, Okta Universal Directory, Okta Identity Threat Protection, miniOrange SSO, miniOrange MFA, miniOrange Directory, Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator, InstaSafe MFA, InstaSafe Authenticator, eMudhra SecurePass, Scalefusion OneIdP and Hexnode IdP.
Customer identityRules out Okta Single Sign-On, Okta Adaptive MFA, Okta Identity Threat Protection, miniOrange Directory, Cisco Duo, ManageEngine AD360, Fortinet FortiAuthenticator, InstaSafe MFA, InstaSafe Authenticator, Scalefusion OneIdP and Hexnode IdP — workforce identity; per-user pricing does not survive consumer scale. That leaves Okta Universal Directory, Okta Customer Identity (Auth0), miniOrange SSO, miniOrange MFA, miniOrange CIAM and eMudhra SecurePass.
Self-hosted deploymentRules out Okta Single Sign-On, Okta Adaptive MFA, Okta Universal Directory, Okta Customer Identity (Auth0), Okta Identity Threat Protection, Cisco Duo, InstaSafe MFA, InstaSafe Authenticator, Scalefusion OneIdP and Hexnode IdP — SaaS only. That leaves miniOrange SSO, miniOrange MFA, miniOrange CIAM, miniOrange Directory, ManageEngine AD360, Fortinet FortiAuthenticator and eMudhra SecurePass.
Conditional accessRules out miniOrange Directory, Fortinet FortiAuthenticator and InstaSafe Authenticator — basic policy only, not risk-based conditional access. That leaves Okta Single Sign-On, Okta Adaptive MFA, Okta Universal Directory, Okta Customer Identity (Auth0), Okta Identity Threat Protection, miniOrange SSO, miniOrange MFA, miniOrange CIAM, Cisco Duo, ManageEngine AD360, InstaSafe MFA, eMudhra SecurePass, Scalefusion OneIdP and Hexnode IdP.
Phishing-resistant factorsRules nothing out on published terms. It flags miniOrange Directory — FIDO2 / passkey support not established from vendor documentation, InstaSafe MFA — FIDO2 / passkey support not established from vendor documentation, InstaSafe Authenticator — FIDO2 / passkey support not established from vendor documentation, Scalefusion OneIdP — FIDO2 / passkey support not established from vendor documentation and Hexnode IdP — FIDO2 / passkey support not established from vendor documentation — marked on the cards, not removed.
Service and workload authenticationRules nothing out on published terms. It flags Okta Single Sign-On — Authenticates people well; service accounts and workloads are handled thinly, Okta Adaptive MFA — Authenticates people well; service accounts and workloads are handled thinly, Okta Universal Directory — Authenticates people well; service accounts and workloads are handled thinly, Okta Customer Identity (Auth0) — Workload authentication not established from documentation, Okta Identity Threat Protection — Authenticates people well; service accounts and workloads are handled thinly, miniOrange SSO — Authenticates people well; service accounts and workloads are handled thinly, miniOrange MFA — Authenticates people well; service accounts and workloads are handled thinly, miniOrange CIAM — Authenticates people well; service accounts and workloads are handled thinly, miniOrange Directory — Authenticates people well; service accounts and workloads are handled thinly, Cisco Duo — Authenticates people well; service accounts and workloads are handled thinly, ManageEngine AD360 — Authenticates people well; service accounts and workloads are handled thinly, Fortinet FortiAuthenticator — Authenticates people well; service accounts and workloads are handled thinly, InstaSafe MFA — Authenticates people well; service accounts and workloads are handled thinly, InstaSafe Authenticator — Authenticates people well; service accounts and workloads are handled thinly, eMudhra SecurePass — Workload authentication not established from documentation, Scalefusion OneIdP — Authenticates people well; service accounts and workloads are handled thinly and Hexnode IdP — Authenticates people well; service accounts and workloads are handled thinly — marked on the cards, not removed.
Identity data in IndiaRules nothing out on published terms. It flags Okta Single Sign-On — Documented India residency (Okta launched in-country tenants in 2026), Okta Adaptive MFA — Documented India residency (Okta launched in-country tenants in 2026), Okta Universal Directory — Documented India residency (Okta launched in-country tenants in 2026), Okta Customer Identity (Auth0) — Documented India residency (Okta launched in-country tenants in 2026), Okta Identity Threat Protection — Documented India residency (Okta launched in-country tenants in 2026), Cisco Duo — India data residency not documented and Fortinet FortiAuthenticator — India data residency not documented — marked on the cards, not removed.
Above 10,000 usersRules nothing out on published terms. It flags miniOrange SSO — Unverified above 10,000 users, miniOrange MFA — Unverified above 10,000 users, miniOrange CIAM — Unverified above 10,000 users, miniOrange Directory — Unverified above 10,000 users, InstaSafe MFA — Unverified above 10,000 users, InstaSafe Authenticator — Unverified above 10,000 users, eMudhra SecurePass — Unverified above 10,000 users, Scalefusion OneIdP — Unverified above 10,000 users and Hexnode IdP — Unverified above 10,000 users — marked on the cards, not removed.
What you already own, and where it stopsMicrosoft Entra ID P1 (about $6–7 per user per month, and inside Microsoft 365 E3) gives SSO, full conditional access and hybrid identity; P2 (about $9–10, and inside E5) adds Privileged Identity Management and risk-based sign-in; the Entra ID Governance add-on is roughly $4–7 per user per month on top depending on the base. Google's Cloud Identity Premium lists around $6 per user per month. On-premises Active Directory gives you Kerberos, LDAP and group policy and nothing for SaaS. The honest question on this page is not 'which IdP' but 'where does the one on my invoice stop' — and the answer is usually legacy protocols, non-Microsoft SaaS depth, or governance.
Push fatigue is an attack, not an inconvenienceAttackers with a valid password send approval prompts until someone taps accept. Number matching and context help; only phishing-resistant factors — FIDO2 security keys and passkeys — remove the class. Documented FIDO2 support here: Okta, miniOrange, Cisco Duo, ManageEngine AD360, FortiAuthenticator and eMudhra SecurePass. Not established from documentation: InstaSafe MFA and Authenticator, Scalefusion OneIdP, Hexnode IdP — flagged, never ruled out. Ask for the specific factor, not the word MFA.
The legacy exception that becomes permanentEvery estate has applications that cannot speak SAML or OIDC — a manufacturing system, a bank's core, an application whose vendor is gone. Password vaulting, header-based access or a RADIUS bridge covers them; miniOrange, ManageEngine, FortiAuthenticator, Cisco Duo and Okta all document some path. Write that list before the demo, because it decides the shortlist more often than the modern features do.
Workforce IAM and machine identityEverything on this page authenticates people well. Service accounts, workload identities and the tokens applications and AI agents carry are handled thinly here by design — Okta Customer Identity (Auth0) and eMudhra document machine-to-machine credentials, the rest are limited. Non-human identities outnumber human ones in most estates: the vault and secrets side of that problem is the PAM guide, and it is a separate purchase.
Under 100 usersRules nothing out on published terms: miniOrange, Cisco Duo and the UEM-bundled identity products (Scalefusion OneIdP, Hexnode IdP) are sold to small estates, and Entra ID P1 or Google Cloud Identity may already cover it. Okta and ManageEngine publish no floor but carry minimums through the channel — current minimums by vendor: [TechBag to confirm].
Each shortlist names the specific gap being filled, because almost nobody arrives here with no identity provider at all. If Microsoft 365 is your estate, start from the first row.
Why: Entra ID P1 already gives SSO and conditional access for the Microsoft world. Duo adds MFA and device trust in front of VPN, RDP and legacy applications Entra does not reach; Okta and miniOrange add breadth of non-Microsoft SaaS and legacy protocol support.
The trade-off: Adding a second identity layer to Entra means two policy engines and two places a rule can be wrong. Only do it for a gap you can name — usually the VPN, the legacy application, or the non-Microsoft SaaS estate.
Why: All three document FIDO2 security keys and passkeys with policy that can require them for the accounts that matter most, while leaving weaker factors for the long tail.
The trade-off: Hardware keys cost money per person and get lost; passkeys need modern devices and a recovery story. Roll out to administrators and finance first — the accounts an attacker actually wants.
Why: miniOrange documents the widest legacy coverage here (LDAP, RADIUS, header-based and Kerberos) with an on-premises option; AD360 is built around Active Directory's own protocols; FortiAuthenticator brings RADIUS and certificates inside the Fortinet fabric.
The trade-off: Every legacy bridge is a permanent exception with its own upgrade path. Price the bridge, and put a date on the application it is bridging.
Why: Auth0 is the developer platform with the deepest extensibility; miniOrange CIAM is the India-hosted alternative with INR pricing and a consent model built for local regulation.
The trade-off: Per-monthly-active-user pricing is a function of your growth — model it at your three-year user projection, not today's. Never buy workforce IAM for this; the meter breaks catastrophically at consumer scale.
Why: miniOrange, eMudhra and ManageEngine are India-built with on-premises or India-hosted options; eMudhra adds certificate-based passwordless from a licensed Indian certifying authority. Okta launched in-country tenants in 2026 — confirm it covers your tenant.
The trade-off: The India-built options are flagged unverified above 10,000 users. Residency and scale pull in opposite directions here; ask for a named reference at your size.
Why: Scalefusion OneIdP and Hexnode IdP turn the management agent's compliance signal into a sign-in condition from one console; Duo does the same vendor-neutrally with device health checks.
The trade-off: The UEM-bundled options assume that UEM. If half the estate is unmanaged — contractors, BYOD, partners — device trust cannot be the only condition, and neither product is a general identity provider.
Why: Okta Universal Directory can be the source of truth or sit downstream of AD during a migration; miniOrange Directory gives cloud LDAP for estates that never had a domain.
The trade-off: A rented directory is a real lock-in: every profile, group and attribute mapping is re-homed if you leave. Decide deliberately where the source of truth lives before you sync it anywhere.
Why: miniOrange publishes from ₹180 per user per month and Duo's Essentials tier starts around $3 — both survive a broad rollout where per-user global lists do not; InstaSafe is the India-built option quoted in INR.
The trade-off: InstaSafe's FIDO2 support is not documented — if phishing-resistant factors are the goal, confirm it first. Cheap MFA everywhere beats expensive MFA on half the estate, but not if the factor is phishable.
Identity platforms are sold by feature and bought by population. Place your estate on all four before comparing lists — most organisations have three of them and have priced one.
Population 1
Employees on modern SaaS
The easy case every vendor demos: SAML or OIDC, conditional access, a directory sync. Almost anything here works; price and ecosystem decide it.
Population 2
Employees on applications that can't do SAML
LDAP, RADIUS, Kerberos, header-based. The permanent exception list — and the reason estates keep an on-premises identity component for years longer than planned.
Population 3
Customers, at consumer volume
Registration, social login, consent, progressive profiling — priced per monthly active user. A different product with a different meter and a different team buying it.
Population 4
Services, workloads and agents
Non-human identities: service accounts, API consumers, pipelines, AI agents. They outnumber your people, they authenticate constantly, and workforce IAM covers them thinly — the PAM and secrets guide is where this is solved.
The factor test
Ask these before the price, in this order.
The India layer
Residency, and the vendors that make it easy.
Identity scales by populations and by exceptions, not by user count alone. The bill follows the per-user list; the work follows the applications that will not cooperate.
What you already own is the constraint
Put this in your PoC
List every application people sign into. If more than three cannot do SAML, that list is your shortlist criterion.
Exceptions and factors are the constraint
Put this in your PoC
Price the same estate on Okta's bundle, Entra P2 plus governance, and miniOrange. The spread will be several times, and each is defensible.
Populations and residency are the constraint
Put this in your PoC
Count your non-human identities against your human ones. If services outnumber staff and only staff are governed, the next project just named itself.
Okta, Cisco Duo, ManageEngine and FortiAuthenticator document large estates; miniOrange, eMudhra, InstaSafe, Scalefusion OneIdP and Hexnode IdP are flagged unverified above 10,000 users. Where a specific product strains for your user population: [TechBag to confirm].
The identity provider sits in front of everything. Switching it is not a data migration — it is re-federating every application, re-enrolling every factor and re-writing every policy, while both platforms are live.
Re-federating applications
Every SAML and OIDC integration is rebuilt and re-tested against the new provider, application by application. The catalogue size you paid for is the work you now repeat.
Re-enrolling factors
Every user re-registers their authenticator, key or passkey. It is a communications project as much as a technical one, and the help desk feels it for a month.
The directory and its attributes
If the old provider was the source of truth, profiles, groups and attribute mappings are re-homed. If it merely synced, you keep the source and rebuild the sync.
The legacy bridges
LDAP, RADIUS and header-based exceptions are per platform and rebuilt from scratch — usually last, and usually by whoever understands the application least.
Application re-federation effort and factor re-enrolment plan for your estate: [TechBag to confirm] — TechBag scopes it from your application inventory and factor mix.
What you may already hold, the products priced per user at three estate sizes in USD and INR, and what the licence line leaves out — which, for identity, is the migration and the exceptions.
Four places an identity provider may already sit. Three are real; the question is where each stops.
If the identity provider on your invoice already reaches your gap, we say so. It costs us a sale and saves you one.
Published and reported per-user lists (INR for scale), worked at 100 / 1,000 / 10,000 users per year. The India-built options are priced explicitly — they are absent from every comparison written outside India, and they are frequently a fifth of the global list.
The meters — and why one line is not per user at all
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
Re-federating every application, re-enrolling every factor, rebuilding every legacy bridge — the switching-cost section above. It is the largest number in a replacement project and appears in no licence. Your figure: [TechBag to confirm].
Every application that cannot speak SAML needs a bridge, an owner and a review date. Each one is small; together they are why identity programmes run long.
Hardware security keys cost money per person and get lost; passkeys need modern devices; SMS costs per message and is the weakest factor you can buy. Budget the physical layer and the recovery process, not just the licence.
Documented behaviour and rollout outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover after the incident.
MFA rolled out to everyone except the accounts that mattered
Employees got MFA; the service accounts, the break-glass admin and the VPN's local users did not. Attackers look for the exception list first.
Push fatigue against a rollout that assumed push was enough
Valid password, repeated prompts, one tired approval at midnight. Number matching helps; phishing-resistant factors remove the class.
Legacy apps that can't do SAML and become a permanent exception
The bridge was temporary in the design document and is now four years old with no owner. Name the application, the bridge and the retirement date together.
CIAM bought as workforce IAM and priced catastrophically at scale
Per-employee pricing met a million customers. The meter, not the feature set, is what breaks — model at three-year volume before signing.
Directory sync breaking silently
Leavers stayed active for weeks because a sync job failed without alerting anyone. Monitor the sync as a production service, because it is one.
Conditional access written once and never reviewed
Policies accumulated exclusions until the strongest rule applied to almost nobody. Review the exclusion list quarterly — it is where the real policy lives.
Buying a second identity provider without naming the gap
Two policy engines, two directories to keep in step, and no capability the first one lacked. Name the gap in one sentence, or do not buy.
Machines outside the identity programme entirely
Every employee had MFA and every service account had a static password in a config file. Non-human identities outnumber human ones — that is the PAM and secrets problem, and it needs its own plan.
Vendor-neutral. No gated content.