The IdP: auth with real assurance controls
Passkeys are a first-factor path, not just a second factor. Password fallback, MFA via TOTP or passkey, and upstream SAML or OIDC federation are tenant-configurable. Auth policy ships with a preview-before-save step that surfaces readiness blockers and fallback paths that would stop working before anything takes effect. Emergency break-glass identities are dedicated non-personal accounts: mandatory reason, every use logged, same lockout semantics as normal sign-in.
IGA that executes downstream
Access requests run request, approval, grant, and execution against Portal-native targets directly, and against downstream systems through the connector catalog: 29 providers covering workforce platforms and HR sources. Every execution path creates an immutable provisioning plan before dispatch; completion, partial failure, and retry append evidence without changing the plan. JML templates handle joiners, movers, and leavers from HR events, manual kickoff, or scheduled effective-date.
User access audits, SOX-ready
Access reviews enforce separation of duties at the backend: a reviewer cannot certify their own access, on any request. The access graph shows every access edge, direct roles, group-derived access, IGA grants, and guest access, each with provenance and trust classification, so "who has access and why" has one answer instead of four spreadsheets. Review campaigns, decisions, and revocations are recorded as evidence as they happen, which is what an ITGC user-access-review control actually needs.
Migration from the incumbent
Migration tooling ships two modes: clean cutover from Okta or Entra, or merge into a running Portal estate. Inventory collection snapshots applications, identity providers, routing rules, policies, groups, and assignments. Compatibility assessment classifies every item into one of five categories, and cutover plans apply only what the classifier can prove importable. Okta TOTP factors transfer rather than forcing re-enrollment.