Skip to main content
JIVA Technologies logo
EUC & VDI

Workplace Identity, SSO & Conditional Access

One identity per person, governed across every application.

Workplace-identity engagements consult, design, integrate and support enterprise identity on Microsoft Entra ID, Okta and Ping Identity — federated SSO, MFA, passwordless, conditional access, privileged access management and HRIS-driven joiner-mover-leaver automation so access follows employment in real time.

"Identity is the new perimeter."
Identity Providers
Multi-platform

Microsoft Entra ID, Okta and Ping Identity coverage.

Access Model
Compliance-aware

MFA, conditional access and device compliance signals from UEM.

Governance Model
HRIS-driven

Joiner-mover-leaver automation and access-review evidence.

Platform ecosystem

Multi-vendor by design — platforms are matched to workforce persona, security posture, integration surface and operating model.

  • Microsoft Entra ID
  • Okta
  • Ping Identity
  • MFA · Passwordless · FIDO2
  • Conditional Access
  • PIM · PAM
  • HRIS-driven JML

Scope in detail

  1. Enterprise Identity Providers (Entra ID, Okta, Ping)

    Cloud identity architecture on Microsoft Entra ID, Okta or Ping Identity — SSO across SaaS and internal applications, SCIM provisioning, group-based licensing and application-catalogue governance.

  2. SSO, Federation & Application Onboarding

    SAML, OIDC and WS-Federation integration for SaaS and legacy web applications, coordinated onboarding pipelines and centralised entitlement management so one identity works across every application.

  3. MFA & Passwordless Authentication

    FIDO2 security keys, Windows Hello for Business, platform authenticators and phishing-resistant push — reducing password dependence for the majority of the workforce while preserving governed break-glass paths.

  4. Conditional Access & Zero Trust

    Risk-based sign-in policies, device compliance signals from unified endpoint management, session controls and continuous access evaluation — aligned to NIST SP 800-207 Zero Trust principles where relevant.

  5. Identity Governance & Joiner-Mover-Leaver

    HRIS-driven identity flows (Workday, SAP SuccessFactors, Oracle HCM, BambooHR) that automate provisioning, access reviews and deprovisioning — with attestation and audit-ready reporting.

  6. Privileged Identity & Access Management (PIM / PAM)

    Just-in-time elevation, approval workflows, credential vaulting and session recording with BeyondTrust, CyberArk, Delinea and Entra Privileged Identity Management — standing privilege becomes the exception, not the default.

  7. External Identity, B2B & CIAM

    Guest access, partner federation, cross-tenant trust and customer identity management (CIAM) — enabling secure collaboration and customer-facing sign-in without shadow accounts or unmanaged credentials.

  8. RBAC, Entitlement Management & Access Reviews

    Role-Based Access Control models, entitlement packages, access reviews and separation-of-duties enforcement — mapped to job families, regulatory obligations and application ownership.

Where workplace programmes break down

  • Leaver access lingers after departure

    Leaver revocation depends on manual tickets, so orphan accounts, SaaS entitlements and shared credentials remain active well after departure.

  • MFA coverage is inconsistent

    MFA is enforced on some applications but bypassed on others, and legacy authentication paths remain open, leaving well-known attack surfaces exposed.

  • Conditional access ignores device posture

    Sign-in policies check user risk in isolation, without device compliance signals from UEM, so access decisions no longer reflect endpoint state.

  • Application onboarding is ad-hoc

    New SaaS applications are federated one at a time by different teams, so entitlement models, SCIM provisioning and audit reporting differ between platforms.

Engagement approach

A multi-vendor workplace identity lifecycle covering assessment, target-state design, phased integration and ongoing identity operations.

  1. Assess

    Review identity providers, MFA coverage, application catalogue, HRIS integration, privileged access posture, conditional access policy and audit evidence.

  2. Design

    Define a target identity architecture, application onboarding pipeline, conditional access model, PIM and PAM design and joiner-mover-leaver automation.

  3. Implement

    Integrate the identity provider, onboard priority applications, deploy MFA and passwordless, wire in device compliance and automate identity governance in pilot rings.

  4. Operate & Optimise

    Support the identity estate under an agreed schedule with application onboarding, access reviews, PIM operations, MFA management and scheduled service reviews.

Deliverables & artefacts

  • Target identity architecture and federation design
  • SSO, MFA, passwordless and Conditional Access policy
  • Privileged access (PIM / PAM) operating model
  • HRIS-driven joiner-mover-leaver workflow
  • Access review and certification cadence
  • Identity threat detection and response runbook

Fix What's Broken — Remediation Sprints

Slow imaging, drifting device standards, patchy MDM/UEM enrolment, VDI performance complaints or a stalled Windows/macOS refresh? We run fixed-scope end-user-computing remediation sprints.

  • Device standards, imaging and zero-touch enrolment cleanup (Intune, Jamf, Workspace ONE)
  • VDI/DaaS performance tuning, image lifecycle and user-experience fixes
  • MDM/UEM policy hygiene, compliance baselines and app-delivery remediation
Request a remediation scope

Support & Maintenance — AMC-Backed

Keep the end-user estate running smoothly after rollout — device health, image lifecycle and vendor escalation under a Jiva AMC or managed workplace service.

  • Managed EUC / workplace operations with device-health and UX SLAs
  • MDM/UEM, VDI/DaaS and OS-patching hygiene under quarterly reviews
  • Device lifecycle, warranty, spares and vendor-TAC escalation
Explore AMC & support contracts

Workplace Identity, SSO & Conditional Access FAQs

Assessment, design, implementation, integration and lifecycle support across calling, meetings, collaboration, endpoints and identity.

Continue exploring

Modernise workplace identity

Align identity, device compliance and conditional access

Review the current identity provider, MFA coverage, conditional access model, privileged access posture and joiner-mover-leaver flows. Jiva Technologies can assess, design, integrate, remediate and support a phased workplace identity programme aligned with UEM and endpoint security.