Introduction

Some applications at the center of every large organization actually sit at the boundaries between mixed user populations — think employees, partners, contractors, vendors, and even machines. These shared services applications keep the business running through a combination of fragile custom code and mixed vendor environments.

The challenge?
These different user groups often authenticate in different ways and through different identity stores. Legacy on-prem systems like LDAP or custom authentication flows often collide with modern platforms like Okta or Entra ID. A small change in identity architecture can break critical access to the very apps that keep the engine running in an organization

Adding to this risk is the fact that service accounts and machine-to-machine connections frequently fall outside security and visibility standards. You can’t protect or report on what you can’t observe within these shared services apps..

In this short video, Sawyer Pence, Field Engineer at Strata Identity, talks about what makes shared services applications so complex — and why securing them requires a unified approach to access and policy enforcement.

He explains how to:

  • Address the friction of shared access between legacy and modern authentication systems
  • Manage human and service account access from a single control plane
  • Apply consistent MFA and role-based access policies across organizations
  • Improve visibility into which user type is accessing what, and when

The outcome: a unified access layer that supports both legacy and modern systems — keeping business-critical shared services applications online, secure, and trusted by every team that depends on them.

What you’ll learn

  • What makes shared services apps so difficult to manage across departments, partners, and environments
  • Why bridging old and new authentication methods is difficult — and what to watch out for
  • How to manage both human and service account access from one control point
  • How to apply consistent authentication and policy enforcement across multiple identity systems
  • How to improve visibility into authentication and user activity across cloud and on-prem user stores

Key Takeaways

  • Shared services apps power critical business operations across humans, partners, and machines — but as a result, they’re often the hardest to secure.
  • Managing them requires balancing legacy authentication with modern standards while keeping critical access intact.
  • Unifying control and visibility helps reduce risk and improve reliability across every connected system.

Transcript

Read transcript

What is a shared services application?

“Think about all the user personas in your enterprise. You might have workforce users, contractors, partners, subsidiaries, affiliates — all those different user personas.

When they come together to access a single application, it’s very likely that they’ll have different policies, different identity providers, and different identity systems that need to work together in that shared services application.

That’s how you know that you have a shared service application — when all those different personas are coming together in a single application, through different identity providers and identity services. That’s when you have an interesting application that falls under the shared service application definition.”

Where would I find a shared service app in my organization?

“In an organization, you’ll probably see shared service applications existing anywhere there’s a boundary between business units.

If we’re talking about Workforce, it could be interdepartmental. It could also be a B2C use case, where the customer is actually a subsidiary or a partner that needs to access your applications.

Shared service applications are all over the place — wherever different units, organizations, or companies need to share work, data, or applications.”

Why are shared service apps so challenging to manage?

“When you try to set up a proper Zero Trust environment without service accounts, you’ll encounter organizations and identity providers with inconsistent authentication and MFA experiences.

Users might not have their devices registered in a way that supports appropriate multi-factor authentication. Some organizations still rely on SMS or other less secure forms of two-factor.

They’re also fairly brittle to integrate with. To orchestrate these policies and authentication experiences across organizations usually means having to write intricate integrations that allow the application itself to orchestrate access.

As requirements change and user bases evolve, it becomes very easy to break that integration — or even just maintaining it becomes difficult.”

Why are legacy protocols especially hard in this situation?

“When you have a shared service application that can’t consume modern authentication protocols like SAML or OIDC, you might end up with an application where you have to build very bespoke security practices around MFA or passwordless access.

The only alternative you have to that is accepting that application as an audit risk.

It’s about putting that shared service application — its cybersecurity and its ability to consume authentication protocols — on the same footing as the rest of your organization.

You want that single sign-on. You want that shared service application to operate on the same footing as the rest of your enterprise.”

What do organizations often overlook when dealing with shared services apps?

“Observability and control of shared services is probably one of the largest pain points. Observability isn’t unified — there’s no single control point. It lives within the individual identity providers and directories of the different organizations coming into that shared service application.

Audit and security teams are very concerned about these applications. They’re among the most heavily controlled and audited types of apps in an enterprise.

Simplifying how users enter those applications and reducing the complexity of integration makes the entire experience more secure, more observable, and easier to audit.

It saves time, reduces operational and maintenance costs, and gives you the single sign-on and observability you need to control access to those apps.”

How can Strata Identity help my company?

“Identity Orchestration allows for a single control point — a single pane of glass — for observability into your users, sessions, tokens, assertions, and authentication patterns.

Strata gives you a place where you can take the events you might see in a SIEM and actually do something with them. You can send those events into that control plane and take action on user sessions or policies that control how a user session changes over time — not just at the moment of authentication, but in real time.

That ability to have observability and control over your users’ authentication experiences and sessions — from cradle to grave — gives the orchestrator the power to manage those sessions and identities across services.

If you’re dealing with identity fragmentation, applications that don’t support modern identity protocols, and you need to bring them under a single set of policies and authentication flows — what you need is Strata Identity’s Orchestrator.”