Site Icon

Customer Identity and Access Management

Image link

When implementing custom or SaaS applications for your clients, managing customer identity becomes crucial. It’s not just about security and compliance—it’s about enhancing business value while providing a seamless user experience. A robust Customer Identity and Access Management (CIAM) strategy can help achieve this balance, enabling rapid access to apps while ensuring modern security standards.

Key Considerations for Customer Identity Authentication Flows

Before diving into specific implementations, here are some key factors to consider when designing customer identity authentication flows:

  • Custom Credentials: Do customers need unique credentials for your apps?
  • Multi-Factor Authentication (MFA): Is MFA required for added security?
  • Single Sign-On (SSO): Do customers need SSO between your apps and partner apps?
  • Session Duration: How long should authentication sessions remain active?
  • Authorization Constraints: Are there constraints based on geography, time, or usage?

These questions are a starting point. Designing an effective CIAM solution involves considering many other factors to ensure it meets both security needs and user expectations.

Modernizing Customer Identity for a Construction Client

Client Background

Our client, a construction company, used multiple custom apps with individual authentication systems. Additionally, they employed various SaaS apps to deliver features without developing them in-house, focusing instead on core business values.

 

Challenge

The client’s existing system was fragmented, with different apps having separate identity solutions, making it cumbersome for users and administrators.

 

Solution

  1. Adopt Azure AD B2C: We implemented Azure AD B2C as the centralized customer identity provider.

  2. Unify Identity Protocols: To create a cohesive system, all app identities were brought under a common protocol, OAuth 2.0. This didn’t mean overhauling existing systems; rather, we routed current identity systems to bypass authentication if the user was already authenticated through the centralized service. This approach preserved existing session and token management.

  3. Optimize User Experience: Given the client’s stringent compliance and security requirements, we selected a user experience flow that provided secure, client-specific credentials. Third-party logins were not allowed. We implemented conditional MFA to enhance user experience for users accessing the apps from familiar devices, locations, and usage patterns.

  4. Integrate with External Providers: For employees and partners, who needed access through Microsoft AD and Google Identity, we integrated these with Azure AD B2C using built-in configurations.

 

Outcome

By leveraging SaaS providers for much of the identity management and authentication, we minimized custom development and focused on agile, business-value-driven improvements. This enabled us to go live with a Minimum Viable Product (MVP) in just three weeks.

 

Building Customer Identity for a Social App Start-Up

Client Background

A niche start-up aimed at developing a social app for pickleball players worldwide sought a user-friendly and secure identity solution.

 

Challenge

The client wanted an authentication process that didn’t require users to remember credentials and minimized authentication requests, aligning with their goal of a frictionless user experience. Additionally, authentication methods had to vary by country to manage costs.

 

Solution

  1. Develop Cross-Platform Mobile Apps: We used Flutter to build the mobile apps, ensuring compatibility across devices.
  2. Leverage Firebase Authentication: Google Cloud Firebase was chosen for its robust and scalable authentication services. We enabled phone-based authentication for select countries and email-based authentication for others to control costs and comply with local regulations.
  3. Employee and Support Tools: Control panels for employees and support teams were built using Microsoft Power Platform, utilizing built-in Microsoft AD authentication.
  4. Deploy Scalable Micro-APIs: We hosted event-driven, scalable micro-APIs in Azure, making them accessible via API Management.
  5. Implement Token Validation: To streamline authorization for internal and external apps, we enabled access token validation policies within API Management, avoiding custom API authorization code.

Outcome

This approach allowed for a rapid market launch with enterprise-grade security and the user experience that the client envisioned.

Conclusion

These case studies highlight Altum’s expertise in CIAM, whether it’s for internal user management or customer-facing solutions. Our team excels in creating tailored identity management solutions that add value quickly and effectively. If you’re looking to modernize your existing CIAM system or build one from scratch, Altum can help you chart the right course. Let’s connect and explore how we can enhance your identity management strategy!