
Like many IT and security professionals, identity practitioners sometimes overlook customer-centric and nontechnical lessons, focusing instead on the technical aspects of our identity programs. We enjoy delving into the details of identity best practices, processes, and implementations, crafting these for our customers, and integrating them into our solution designs. While these elements are crucial, we must remember that identity programs are just as susceptible to failure as other initiatives due to misalignment with business objectives, poor communication, or low user adoption (including both IT and business users).
You need the right people on your side to be successful, and that means identifying them and understanding the information necessary to meet them where they are. What are their pain points and non-negotiables? What business cases do you need to make, and to whom? What communication strategy will ensure that the right people are informed at the right time? To garner the support your program needs, you’ll need answers to these questions.
Much has been said about executive sponsorship and stakeholder engagement, but effort should also be made to incorporate the business and IT teams themselves. Use a top-down approach to align everyone with the vision, but remember to communicate directly with and show value to all parties. The top supports you, but so does the bottom. Often, it’s the people doing the work—some who've been involved for many years as the enterprise’s systems evolved—who can help you avoid pitfalls and reveal hidden issues. If you stay entirely at the upper management and strategic level, you leave your project more vulnerable to these challenges, which can lead to headaches or even failed launches. Sometimes the long-haulers won’t mention something until a discussion prompts them. Talk to everyone you can, let them know they have a stake and a role to play, and treat them accordingly.
Engage with all your application owners, especially those responsible for Active Directory. Be as transparent as possible about what is being done. This same openness applies to local IT and support teams. If you've made acquisitions, this is even more important. It’s critical to know who is doing what on all sides, what their directory structures are, what attributes they use, and what conflicts exist. If you have to manage multiple domains in your new ecosystem, ensure you have a rational plan for merging these domains into a sensible and sustainable management strategy. Involve everyone you can find as often as possible.
Continually engage the business, as people turnover and newcomers must be onboarded to the program. Just because the previous person in that role cared doesn't mean the new one will. They may not initially care much about identity in their sphere of concern. Remember that business people must be addressed in their own terms, not in IT jargon. Ask about their pain points and explore whether the new processes can address them. Don’t lead by trying to fix things they don’t see as broken or sell them on what already works.
Be aware of who on your team interacts best with whom, and align people with those with whom they've built natural rapport. Speak up when communication issues arise and seek solutions. There will always be unpleasant surprises—bugs, last-minute changes, and overlooked details. Be ready to address these to maintain the goodwill you've built, which will reinforce itself when challenges arise.
Building a robust identity ecosystem goes beyond the technical; it requires a strong, collaborative community. We can create a cohesive and resilient identity program by engaging with all stakeholders, from top executives to IT teams on the ground, and continually addressing their needs and concerns. Remember, success in identity management hinges not only on the solutions we implement but also on the relationships we build and the communication we maintain. Foster these connections, stay adaptable, and your identity program will thrive in alignment with your business objectives.
Need help? Reach out. Idenhaus can help with every facet of your cybersecurity needs- from drafting a roadmap for your cybersecurity plans, to implementing new changes and updating old strategies. Talk to our experts today to get started with your best cybersecurity plan yet.