Skip to content

72 Hours, Every Use Case, Harsh Conditions – Flawless Performance: A Defense Agency's Experience

Industry: Defense | Product: Junto Identity® | Get a Demo →

A large defense organization faced challenges with its approach to identity security, particularly for securing remote, forward-operating, and edge-deployed sites. It found that maintaining consistency, efficiency, and effectiveness for key identity security workloads degraded as remote sites faced connectivity challenges or disruptions.

Identity Security Success When Connectivity Fails

Specifically, the organization needed a way to:

  • Perform identity lifecycle management tasks (such as onboarding a new user) consistently even when connectivity between the enterprise and remote sites was unavailable.
  • Effectively authenticate users (including third-party users, non-human identities, and transient users) at all sites equally regardless of enterprise connectivity.
  • Enforce attribute-based access control equally on all identities, to all systems, under all conditions, and at all sites.
  • Federate external partner identities and provide appropriate access (Zero Trust) under all conditions.

They needed to avoid the inevitable degradation of identity security effectiveness and the bifurcation of identity data and access control between the enterprise (or HQ) and the edge (or forward operating base).

After a thorough review of available options, the organization turned to Junto Identity to address the need. Junto has proven success delivering a Zero Trust Architecture (ZTA) for identity and access management at the edge for organizations worldwide. In fact, Junto was instrumental in the development of the only approved Identity Credential and Access Management (ICAM) architecture for enterprise deployments within the U.S. Department of Defense.

Junto was born out of the demanding needs of military deployments to achieve compromise-free identity security and identity-centric Zero Trust in harsh environments, with limited and inconsistent connectivity, very fluid user-bases, and condensed implementation timelines. The result is a powerful identity security solution that easily addresses the unique needs of any organization – simply, completely, affordably, and quickly – without the need to compromise.

Delivering on Every Use Case

In a comprehensive proof-of-concept (PoC), the agency ran the Junto solution through a number of challenging use cases with varying connectivity scenarios.

Use Case The Junto Solution
Enterprise identity lifecycle management including on-boarding a new user based on an authoritative data source, modifying the user as the role changes, and terminating a user. Junto delivered all of the process orchestration and multi-step workflows the organization needed to move provisioning (joiner/mover/leaver) actions from a cumbersome and error-prone manual process to a consistent and virtually instant action.
Identity lifecycle management (provisioning) when connectivity to the enterprise identity security solution is unavailable. Junto’s deployment flexibility (in this case a physical appliance at the remote sites) and powerful synchronization capabilities, ensure that even when connectivity is not available, all joiner/mover/leaver actions occur fully with the same efficacy, automation, and consistency as when access to the enterprise is available.
Reconciliation of identity data when connectivity is restored. Junto’s synchronization capabilities automatically reconcile identity data when connectivity between the enterprise and remote site is restored. Following established policy, this ensures that permissions, attributes, and approvals do not diverge from the ideal state.
Enable multi-step provisioning approval workflows at both the enterprise and remote sites.

Junto provides the scope and depth necessary to build workflows that perfectly fit each of the organizations requirements, including enforcing all workflow policy consistently across connected and disconnected sites. This capability makes orchestration objectives easier to achieve across connectivity challenges including:

  • Multi-step approvals
  • Conditional access
  • Just-in-time provisioning
  • Time-bound access
  • Step-up authentication
  • Emergency, break-glass access.
Establish and enforce a Zero Trust access model across all resources. Junto’s powerful policy authoring and enforcement capabilities mean that access is not granted simply because a user has an account. Rather, it is tied attributes and policy. This ensures that “deny-by-default” is the rule not the exception for all users and all resources.
Provide partner federation without a directory trust. Junto enabled the organization to provide appropriate vendor and integrator access without a domain trust or permanent external accounts. Partners are granted only the access they need without exposure to the rest of the enterprise. This capability is equally effective when connectivity is degraded or non-existent.
Achieve just-in-time (JiT) provisioning for federated partners with constrained, policy-based access. Junto fully satisfied the organization’s requirement to grant federated partners access as it’s needed rather than requiring standing access and excessive permissions. The platform’s powerful policy authoring and enforcement capabilities along with the rich orchestration, synchronization, and virtual directory services empower full granularity on how access is granted and what entitlements are enabled including for JiT use cases.
Support and integrate with existing identity security technologies and practices. For the organization, Junto’s standards-based approach and microservices architecture extended existing identity security investments to the edge rather than replacing them. This model is particularly effective for multi-factor authentication (MFA). Junto follows a “bring your own MFA” strategy.

The PoC was scheduled to run over a weekend with multiple connectivity challenges introduced while running through the full set of use cases. 


"Junto delivered capabilities that we’ve never seen before, and it performed flawlessly.”

— Defense organization lead

Junto successfully delivered on all of the agency’s requirements in less than 72 hours:

  • Consistent, automated, and uncompromised identity lifecycle management tasks at the enterprise and the edge.

  • Complete, appropriate, and secure authentication for all users at all sites regardless of enterprise connectivity.

  • Enforce attribute-based access control equally on all users, to all systems, at all sites, and under all conditions.

  • Federate external partner identities and provide appropriate access under all conditions.

The Junto Solution

At most organizations, identity security solutions cover many, but not all, of their diverse and evolving enterprise’s needs. Where they’ve been forced to compromise is where they face the most risk. Junto covers them all – access control for users of all types, every identity security workload, and every deployment idiosyncrasy.

Junto:

  • Fits how organizations work.

  • Supports every use case and identity security workload. 

  • Secures every identity: employee, contractor, third-party, privileged, non-human, critical infrastructure, agentic, and whatever comes next.

  • Is easy to implement, use, and own. No difficult integrations. No endless customizations. No inconsistencies across users, systems, or use cases.

  • Makes compliance easier across every identity, every system, and every use case.

  • Is flexible enough to embrace whatever workflow, orchestration, or access model an organization may need. 

  • Can be deployed in whatever manner makes the most sense for the organization – on-premises, hosted (public, private/sovereign, and hybrid cloud), or appliance-based (physical or virtual).