Overview
The organization previously relied primarily on password authentication, with MFA limited to a small number of privileged accounts. Password analysis and observed credential reuse demonstrated a need for stronger identity controls.
The initiative introduced enterprise MFA, SSO, role-based application access, privileged account separation, and repeatable identity lifecycle processes.
Technology Strategy
- Selected Okta and Duo for mature SSO and MFA capabilities.
- Duo was integrated into Windows login.
- Okta provided the application portal with role-based application assignments.
- Higher-risk AWS administrative access retained additional MFA requirements.
Deployment & Adoption
- Started with IT as a pilot group.
- Expanded department-by-department across the organization.
- Created video training, written guides, and a KnowBe4 LMS module.
- Conducted live sessions, especially with senior management.
- Prepared help desk staff with troubleshooting guidance and escalation procedures.
Identity Governance
- Application access was driven by employee type, department, and role.
- Created onboarding, transfer, and offboarding SOPs involving HR, managers, and IT.
- Performed quarterly account reviews using recurring IT tickets.
- Maintained evidence supporting NIST 800-53 control reviews.
Privileged Access
- Separated administrative identities from normal user accounts.
- Restricted admin accounts from normal productivity applications.
- Used SIEM alerts for unusual privileged-account activity.
- Protected service accounts with restricted vault access and long random credentials.
Results
- Reduced credential compromise risk through broad MFA adoption.
- Reduced account lockouts by combining stronger passwords with less frequent rotation.
- Improved onboarding consistency through repeatable access templates.
- Created an identity foundation supporting broader security program maturity.
Executive Takeaway
The value of the initiative was not simply deploying Okta and Duo. It transformed identity into a governed security capability that improved security, usability, compliance readiness, and operational consistency.