Modernized Systems Simplify Sign-On for Employees
Before Virginia modernized its IAM system, many of the state’s 50 agencies ran their own Active Directory instance and the LDAP protocol, a legacy approach that required servers, specific network ports and custom authentication for applications, Watson says.
“It wasn't web-friendly,” he says. “There was a lot of customization that had to be put in place for it to work.”
VITA consolidated its AD instances about 12 years ago, then standardized on Okta, a cloud-based IAM platform, more than five years ago to provide employees single sign-on across their applications.
The state rolled out SSO with email first. “People saw the benefit right away and asked about other applications they use every day — ‘This works great for email, what’s the holdup?’” Watson says. “Slowly, we got more adoption, then it snowballed from there, and now they don’t have to enter their credentials 15 times.”
Today, Okta provides SSO for roughly 70% of Virginia’s enterprise applications, including its central HR system and general ledger and payment platform. Not every application uses it. Some agencies still maintain their own authentication for local, specialized applications, Watson says.
The state has also deployed multifactor authentication through Okta Verify. “We reduced phishing incidents to almost none,” he says.
READ MORE: States automate user privileges with identity and access management.
Cloud-Native Identity Solutions Integrate the Government Enterprise
Watson says Virginia chose Okta, Microsoft AD and Entra ID — Microsoft’s cloud-native identity service — because they integrate well with a wide range of systems, including cloud platforms, so agencies don’t have to configure authentication every time they deploy new apps.
Virginia runs a hybrid, multicloud environment with Azure, AWS and Oracle Cloud as its primary cloud platforms, plus a smaller Google Cloud footprint in the Health Department.
Connecting Okta, AD and Entra ID into whichever cloud environment Virginia uses requires some work, but because they’re built on industry standards, the process goes smoothly, Watson says.
“There’s always a little bit of work involved with integrations, but it’s a very smooth connection between all of them,” he says.
Today, 70% of the state’s applications run on-premises and 30% in the cloud. Watson expects that to shift toward 60% cloud in the coming years.
The next step is fully adopting zero trust. Virginia’s identity layer handles authentication at login, but its zero-trust strategy will extend that trust continuously throughout a session, repeatedly revalidating a user instead of granting access once.
Modern security depends on layered controls throughout an agency’s systems, from user devices and network to data itself, all tied to identity rather than a single perimeter checkpoint, Watson says: “You have to have something at every stage of the process. The identity is the thing that ties all of those individual accesses together to make sure that you've got a trusted chain in place.”
