---
source_url: "https://www.strata.io/resources/whitepapers/identity-orchestration-buyers-guide/"
title: Identity Orchestration Guide for Buyers - Strata.io
mirrored_at: 2026-08-14T03:04:29.585Z
host: www.strata.io
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/www.strata.io/resources/whitepapers/identity-orchestration-buyers-guide/index"
---

> **Original source:** https://www.strata.io/resources/whitepapers/identity-orchestration-buyers-guide/

A number of challenges that are unique to multi-cloud environments must be overcome to achieve successful identity management:

Organizations using more than one cloud must contend with more fragmentation from multiple silos, which makes managing secure access to apps difficult. Organizations need to manage identities and access consistently across platforms, regardless of vendor.

Many organizations run apps on multiple cloud platforms and need to provide consistent access to users regardless of what cloud platform the app runs on. Further, each cloud has a built-in identity system that manages **‘local’ user accounts**. These local accounts must be consistent across platforms to [support SAML](https://searchsecurity.techtarget.com/definition/SAML) and OIDC-based SSO. Further, **access policies** on these cloud platforms need to be consistent as well. Without consistent policies, it’s difficult to manage access or demonstrate compliance.

### **Remote workers require secure access to on-premises apps and data.** 

Accelerated by mandates to support remote workers, enterprises must quickly adapt to a massive rise in the number of employees working remotely. VPNs can only scale so much and what’s needed is a way to extend access to on-premises apps to cloud-based users. These cloud-based users need secure [Zero-Trust architecture](https://www.strata.io/resources/whitepapers/secure-hybrid-access/) and seamless access to apps and data that reside behind the firewall.

### **App-to-Identity Integration Results in Lock-In.**

For the past 10 years, enterprises have deployed identity infrastructure to support on-premises custom web apps. These apps were integrated directly with legacy identity infrastructure. Moving these apps to the cloud means rewriting apps to work with a new identity system, taking months of developer time. Apps that are hard-wired to a single identity vendor leads to more lock-in and limited choices. As a result, organizations are locked into legacy identity platforms, preventing apps from moving to the cloud.

### **Multi-Cloud Requires a Higher Level of Scale.**

Consider managing identity and access for dozens of apps and thousands of identities, now multiplied by the number of cloud platforms in use. Factor in the rapid increase in the number of remote workers that need to access cloud-based apps and it’s simply not possible to keep up with changes using manual effort.

### **Need Gradual, Agile Migration Capabilities.**

Enterprises have significant existing on-premises IT investments used to run the business. Moving these business-critical apps requires working with the dependencies between apps and infrastructure. It’s not possible (or a good idea either) to do ‘big bang’ migrations or modernize everything all at once. What’s needed is an agile approach that supports an app-by-app and user-by-user incremental migration model that decreases risk and accelerates execution.

### **Need Zero-Trust Secure Architecture.**

With cloud deployments, networking plays a different role than on-premises as identity has become the new perimeter. As apps span multiple cloud platforms and on-premises platforms users must cross the open Internet to access them. What’s needed in this case is to assume that all networks are hostile and implement mutual authentication and encryption for all communications. Further, managing access to system-level credentials is critical.