Identity Orchestration

Identity Orchestration is the coordinated control of identity flows across several systems, identity providers and authentication mechanisms. Instead of hard-wiring each application to a single identity service, an orchestration layer defines flexible flows (journeys) that decide at runtime which steps a login goes through.

Typical scenarios are multi-stage login journeys with conditional multi-factor prompts, the combination of different identity sources after mergers, step-by-step migrations between identity providers without modifying the applications, and uniform registration and recovery processes. The term must be distinguished from identity automation: the latter automates administrative processes such as provisioning, whereas orchestration shapes the authentication and authorization flows themselves.

In heterogeneous IT landscapes with many interfaces, identity orchestration reduces integration effort and vendor dependency. At the same time, security policies can be enforced centrally – a building block of modern Identity Security architectures.