Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Sep 27 2026
Security

How States Secure the Cloud Era with Identity-First Strategies

Government IT agencies strengthen identity and access management to protect resources.

As Virginia continues to shift workloads into the cloud, the Virginia IT Agency and other state agencies don’t have to worry about an identity and access management solution during each migration. They can simply connect to a statewide system already in place.

VITA laid the groundwork for IAM years ago, first by consolidating dozens of Active Directory instances into one centralized AD environment, then synchronizing it with Microsoft Entra ID, forming a unified directory for on-premises and cloud workloads. The agency has added Okta on top to provide single sign-on across the state’s workforce, says CIO Michael Watson.

The foundation now authenticates employees for more than 1,000 Virginia enterprise applications and underpins VITA’s push toward zero trust.

“There are two major benefits: One is the user experience and providing a frictionless interaction,” says Watson, who became CIO this spring after 15 years at VITA, including serving as Virginia’s CISO since 2012. “The other part is security. The more we have to worry about remembering passwords, the more we have to enter them into different locations, the higher the exposure rate. Once we had single sign-on in place, it cut down our phishing incidents.”

As state governments expand their use of cloud platforms such as Amazon Web Services, Microsoft Azure and Google Cloud, they are rethinking how security is implemented in their hybrid on-premises and cloud environments.

Network perimeter defense still matters, but state governments are increasingly building security around identity.

Several forces have converged to put identity at the forefront, says Forrester Analyst Geoff Cairns. Zero-trust architecture, in which nothing is trusted inside or outside the network, has come into its own as a mainstream security strategy. Cloud adoption has also increased the number of connections between applications and systems that need to authenticate, beyond just employees logging in. And AI agents are emerging as an entirely new category of identity to manage.

“All these things have really put a spotlight on identity and access management as a foundational component for security,” Cairns says.

Click the banner below to explore the evolution of identity management through artificial intelligence. 

 

Modernized Systems Simplify Sign-On for Employees

Before Virginia modernized its IAM system, many of the state’s 50 agencies ran their own Active Directory instance and the LDAP protocol, a legacy approach that required servers, specific network ports and custom authentication for applications, Watson says.

“It wasn't web-friendly,” he says. “There was a lot of customization that had to be put in place for it to work.”

VITA consolidated its AD instances about 12 years ago, then standardized on Okta, a cloud-based IAM platform, more than five years ago to provide employees single sign-on across their applications.

The state rolled out SSO with email first. “People saw the benefit right away and asked about other applications they use every day — ‘This works great for email, what’s the holdup?’” Watson says. “Slowly, we got more adoption, then it snowballed from there, and now they don’t have to enter their credentials 15 times.”

Today, Okta provides SSO for roughly 70% of Virginia’s enterprise applications, including its central HR system and general ledger and payment platform. Not every application uses it. Some agencies still maintain their own authentication for local, specialized applications, Watson says.

The state has also deployed multifactor authentication through Okta Verify. “We reduced phishing incidents to almost none,” he says.

READ MORE: States automate user privileges with identity and access management.

Cloud-Native Identity Solutions Integrate the Government Enterprise

Watson says Virginia chose Okta, Microsoft AD and Entra ID — Microsoft’s cloud-native identity service — because they integrate well with a wide range of systems, including cloud platforms, so agencies don’t have to configure authentication every time they deploy new apps.

Virginia runs a hybrid, multicloud environment with Azure, AWS and Oracle Cloud as its primary cloud platforms, plus a smaller Google Cloud footprint in the Health Department.

Connecting Okta, AD and Entra ID into whichever cloud environment Virginia uses requires some work, but because they’re built on industry standards, the process goes smoothly, Watson says.

“There’s always a little bit of work involved with integrations, but it’s a very smooth connection between all of them,” he says.

Today, 70% of the state’s applications run on-premises and 30% in the cloud. Watson expects that to shift toward 60% cloud in the coming years.

The next step is fully adopting zero trust. Virginia’s identity layer handles authentication at login, but its zero-trust strategy will extend that trust continuously throughout a session, repeatedly revalidating a user instead of granting access once.

Modern security depends on layered controls throughout an agency’s systems, from user devices and network to data itself, all tied to identity rather than a single perimeter checkpoint, Watson says: “You have to have something at every stage of the process. The identity is the thing that ties all of those individual accesses together to make sure that you've got a trusted chain in place.”

Michael Watson
Once we had single sign-on in place, it cut down our phishing incidents.”

Michael Watson Virginia CIO

Sharing Services Can Expand Access to IAM Services

The Texas Department of Information Resources has built a shared service that helps state and local agencies assess their environments and implement IAM solutions.

In 2021, lawmakers appropriated $4 million to fund MFA statewide, part of a $17.4 million cybersecurity package. TDIR used the funds to create a shared SSO and MFA service for agencies. Lawmakers renewed the funding in 2023.

Public clouds and remote work during the COVID-19 pandemic upended the old model of network perimeter security, says Tony Sauerhoff, TDIR’s executive director and state CIO. “Connectivity to our data, our resources and our services is available from anywhere and everywhere,” he says.

That shift makes IAM foundational to Texas’s cybersecurity strategy, including a move toward zero trust, he says.

Texas runs a federated IT model. Each agency controls its own applications and infrastructure, says Sally Ward, deputy COO for TDIR’s Shared Technology Services department.

Large agencies have the budget and expertise to build their own systems. Smaller agencies struggle with IAM the most, she says.

The shared service, Texas Identity Access Management, offers three capabilities: SSO and MFA for government employees; authentication for businesses that transact with state agencies; and risk assessments. The state hired a third-party vendor to provide assessment and implementation services.

“Our vendor comes in and assesses the lay of the land, the applications involved and where there might be risk,” Ward says.

DIVE DEEPER: Utah advances policy-first digital first identity management. 

Identity Management Ensures Identity Security for All

TDIR’s technology, the Texas Digital Identity Solution, runs on Ping Identity’s cloud-based tools. Sixteen customers, including the Railroad Commission of Texas, use it today, representing more than 120,000 accounts. Onboarding takes 45 to 90 business days, depending on complexity.

TDIR’s Shared Technology Service operates a hybrid, multicloud environment: About 65% of applications run in its private cloud across two data centers; the rest are split across AWS, Microsoft Azure, Google Cloud and Oracle Cloud.

Implementation isn’t as simple as plugging in a tool, Ward says. It requires change management, new processes and responsibilities, not just software. TDIR provides a dashboard letting agency administrators manage access based on roles.

TDIR’s vendor works with agency IT teams to integrate IAM into their apps, says Dale Richardson, COO at TDIR. “The agencies have to integrate and modify their applications — the front- and back-end pieces,” he says.

Customers are happy. After implementing SSO, one small agency CIO recently wrote TDIR that she loved it. “She said, ‘I can’t believe it. What used to take me 10 clicks, I did in two,’” Ward says.

Fraud prevention is the top benefit, and increasing adoption is the state’s next priority, Sauerhoff says.

“We have good reason to be happy with the progress we've made,” he says. “But we're not resting on our laurels. We've got more work to do in this area.”

Photography by Jonathan Thorpe