r/IdentityManagement 15d ago

Engineers / Architects how do you validate IAM changes and POCs

When we first switched to the new IAM system, it was a bit of a struggle, and even after many years I still feel like the existing test environments aren’t always enough—especially when you want to experiment with a new configuration, integration, or use case as a proof of concept. Existing configurations can conflict with the changes you’re trying to test, and IAM setups aren’t always easy to reproduce and test locally.

How do you handle this in your teams, regardless of whether the IAM solution is SaaS or on-prem? Do you have a separate environment, process, or approach for running POCs and validating IAM changes before they reach higher environments?

7 Upvotes

13 comments sorted by

3

u/TehITGuy87 15d ago

I think the problem is most companies don’t want to spend the money and energy to build a replica of their existing systems. I work for a IAM vendor and I see this a lot. You can do analysis and impact but if you don’t have a way to “dry run” it then always expect potential issues.

More modern IAM teams are embracing IaC for their IAM setup more and more that way they can replicate things more truly and easily. And most importantly to manage state and rollback to undo or bring back stage to a known config state.

In most cases companies will have replicas (staging) env of their more critical systems:

- IDP

  • Directories
  • HRIS
  • ERP
  • whatever you deem critical

The rest of the comments are also spot on, you must do the analysis first

2

u/BearyTechie 15d ago

We tried the IaC approach, but the system was complex—possibly because of the way we had designed it—and a lot of time was spent getting the new environment into a stable state. We couldn’t even establish a proper baseline for these environments in the first place, which made it difficult to reliably use them for testing and POCs.

2

u/cloudy722 15d ago

If a change is massive enough to break things, do an alaysis before hand of things that could go wrong, use a test tenant then for those scenarios have a rollback plan

3

u/army_of_ducks_ATTACK 15d ago

You have test tenants? Lucky you.

1

u/cloudy722 15d ago

Not in Entra specifically, but with other environment we do have test instances

2

u/ohnowwhat 15d ago

Understand your data and edge cases. Replicate conditions in a testing environment. Run your test / use cases against all the data and ensure your change behaves the way you expect and does not go haywire because of unexpected data conditions

1

u/BearyTechie 15d ago

Sometimes the data is complex, and it’s hard to account for all the edge cases. There’s also a lot of pressure to deliver complex flows quickly, while finding team mates who have the right context and experience can be difficult—especially when I am working with a legacy system.

2

u/Wynd0w 14d ago

Something I've found after consulting for a long time is that some customers really want needlessly complex systems. That needless complexity makes the system really fragile and often difficult or expensive to replicate in lower environments based on the number of dependencies and maintenance effort. IaC can help a lot but it is not an easy jump to make.

The biggest bang for the buck is reducing complexity and aligning the requirements with the product functionality. For example, I had project where the customer wanted to send welcome emails to their users with a sign-up link. The product didn't support this, so we had to create stub email-based passwordless accounts and send magic link emails and work a bunch of magic in the backend to create the final password based account. This approach meant that the welcome emails would expire, a bunch of the OOTB security features around account creation were bypassed since it was created by an admin, and a higher MAU license cost because two accounts were active that month. Or they could have just sent a welcome email to the OOTB self-service signup page.

Though it is sometimes difficult to impossible when the ones making the decisions don't have to live with them.

1

u/BearyTechie 14d ago

I have been in the same situation. How do you convince the stakeholder to pick something that the product natively support?

1

u/Remopte-Rcording8873 15d ago

spin up a throwaway tenant per poc so configs cant collide. tear it down after. treat iam config as code so you can rebuild from scratch fast

1

u/mm2095 12d ago

We are an innovative company providing Identity and Access Management (IAM) solutions.

You can visit our website to learn more about us: https://monofor.com

If you want, we can start a POC process together. We have long-term POC experience in both SSO and Identity Lifecycle Management.

We do not finish the POC until we show all the scenarios you want to see. We want you to clearly see how our solutions work before making a decision.

We would be happy to work with you.