Engity is a cloud-based, managed IAM (Identity and Access Management) provider, delivering Identity as a Service (IDaaS). Experience shows that this approach offers significant advantages over on-premises solutions in most cases.
Let’s take a look at the differences between on-premises IAM and cloud-based IAM, and discuss their respective pros and cons, as well as typical use cases. And while we’re on it, let us also discuss one more aspect: The choice is not only between running identity yourself and having someone run it for you. It is also a choice of whose law your identities live under.
What is On-Premise IAM or Access Management?
On-premise IAM refers to an Identity and Access Management system that is deployed and maintained within an organization’s own infrastructure, typically within their own data centers or server rooms.
Such a setup offers advantages in some areas, but also presents challenges.
- Control: With on-premise IAM, organizations have full control over their IAM infrastructure, including hardware, software, configurations, and the identity and access data processed within it. This level of control can be particularly beneficial for organizations that must comply with strict legal regulations or specific security requirements, as no sensitive information needs to be transferred to external IAM providers. In some situations, this can also reduce compliance effort, as no complicated additional supply chain needs to be considered – only hardware, operating systems and the IAM software itself remain suppliers.
- Customization: On-premise IAM solutions allow, in theory at least, for greater customization to align with an organization’s unique requirements. This flexibility enables tailored security policies, integrations with existing systems, and specific workflows. Updates and maintenance intervals can also be planned and managed independently, but this also increases the complexity of the company’s IT setup.
- Network Dependency: On-premise IAM solutions typically operate within an organization’s internal network, which can be advantageous for scenarios where the availability or reliability of external network connectivity is a concern. A direct connection to the local network often allows for faster data processing and lower latency, but this is becoming an increasingly less important argument due to the ever-expanding availability of broadband internet.
- Operating costs and cost structure: Operating an on-premises IAM solution requires continuous investment in infrastructure, maintenance, and personnel. In addition to the initial acquisition costs, ongoing expenses arise, which can be substantial depending on the complexity of the solution.
What is Cloud-based IAM (Identity as a Service - IDaaS)?
Cloud-based IAM, also referred to as Identity as a Service (IDaaS), involves using IAM capabilities provided by a third-party service provider via the cloud. The IAM infrastructure and services are hosted and maintained by the provider, accessible to organizations over the internet.
IDaaS offers a number of clear advantages, but also brings with it some aspects that should be taken into account when making the decision.
- Lower Cost of Entry: Cloud-based IAM typically operates on a subscription or pay-as-you-go model, eliminating high upfront costs for hardware and servers. This makes it more accessible to businesses of varying sizes and budget constraints.
- Scalability and Flexibility: Cloud-based IAM solutions offer scalability, enabling organizations to easily add or remove users, adjust resources, and adapt to changing needs without worrying about infrastructure limitations. This allows IDaaS solutions to quickly grow with a company’s needs. They can also integrate with other cloud services and applications seamlessly.
- Maintenance and Updates: With a cloud-based IAM solution, the service provider handles infrastructure maintenance, software updates, and security patches, which are typically deployed faster and more easily. This reduces the burden on internal IT teams, allowing organizations to focus more on their core business activities: the things they specialize in and that earn them money.
- Skills shortage and operating costs: Operating an IAM infrastructure often requires specialized expertise. With cloud-based solutions, companies don’t need authentication experts to adequately protect their infrastructure. Very few companies are fortunate enough to have these employees on staff, and these experts are also limited in the open job market, which can further complicate the setup and operation of an on-premises solution.
- Provider dependency: Using a cloud-based IAM solution entails a certain dependency on the provider, for example regarding availability, further development, and pricing. In practice, however, this is often offset by contractual agreements and high service standards. Two aspects of that dependency, though, are not covered by a service level agreement. The first is leaving: an IAM system holds every identity a company has, so the real measure of dependency is the effort it would take to migrate away. The second is jurisdiction. The laws which a provider operated under are determined by where that provider is incorporated, not by where its servers stand. We have written extensively about the challenges a typical US Provider poses not only for compliance but also for protection of information and trade secrets.
On-Premise IAM or SaaS – what to choose?
Engity offers IAM in the form of Identity as a Service, as we believe that the pros of a (purely) cloud-based solution clearly outweigh the drawbacks in most cases. Of course, given that there are advantages of on-premise IAM, that may not be true for every potential user, but for most of them.
Let’s revisit and address the aspects of both approaches mentioned above.
- Integrating and operating IAM on a proprietary infrastructure may be necessary in some industries with stringent compliance requirements. However, this approach is often less efficient because resources cannot be shared across multiple clients and costs are not distributed among several customers. Furthermore, inadequate planning can lead to scaling challenges, and overall costs are often difficult to predict in the long term. For startups and smaller companies, building and operating their own IAM infrastructure also often involves significant upfront investment.
- The argument for easier customization with an on-premises solution may be true in some cases, particularly for internal access management with specialized personnel. However, this generally does not apply to customer access management (CIAM). In these cases, it is often necessary to provide users with standardized and established workflows they are already familiar with. Furthermore, IDaaS providers offer a wide range of services and features that, in most cases, cover all relevant requirements.
- The main argument for choosing cloud-based IDaaS, however, is that most companies focus their skills and expertise on their core business, not on operating IAM infrastructures. For IDaaS providers, on the other hand, this is precisely their core business. Accordingly, they possess specialized expertise and experience in access management. Simply put: they know what they’re doing.
- The argument of better control, incidentally, is often read as a security argument, and the two are not the same thing. A substantial share of practitioners consider on-premises IAM the more secure option. However, due to the issues discussed in the previous bullet, on-premises systems often show weaknesses such as multi-factor authentication, insecure default configurations, weak password policies, unpatched vulnerabilities and a lack of the skills needed to run the system properly. Control is the ability to secure something. It is not the same as having secured it.
- Last not least, in regulated sectors the jurisdiction question has moved from mere preference to procedure. For example, since January 2025, financial entities under the Digital Operational Resilience Act (DORA) have had to keep a register of every ICT provider arrangement, assess concentration risk, embed a prescribed set of contract clauses covering data locations, portability, audit rights and termination, and maintain exit strategies that are documented and tested. Notably, DORA does not require a European provider. Yet it requires demonstrable control – which in practice favors a provider whose infrastructure and subcontracting chain are.
For all those reasons we at Engity believe that for most businesses and for virtually all CIAM needs cloud-based access management is the best choice. And to properly protect data and assets, consider a European one.
If you are looking for a suitable IDaaS provider or would like to evaluate your existing solution, please feel free to contact us.
Note: This article was first published in January 2024 and last updated and corrected in September 2026.
