Skip to main content

Bridgepoint | Strengthening Identity Security

In a global investment environment where trust is fundamental, identity security has become a strategic imperative.

Bridgepoint, one of the world’s leading mid‑market investors, operates in a high‑stakes landscape where sensitive data, complex operations, and growing digital access demands must be balanced with speed and efficiency. As identity‑based attacks such as helpdesk impersonation continue to rise, the organisation recognised the need to modernise how user identities are verified – particularly in high‑risk support scenarios.

Watch the video to hear directly from Bridgepoint and Condatis about how modern identity is transforming their security approach.

Working in close partnership, Condatis designed and delivered a tailored Identity and Access Management solution that brings strong, passwordless identity verification into Bridegepoint’s day‑to‑day operations. By combining Microsoft Entra Verified ID, Face Check, and Microsoft Authenticator, the solution enables helpdesk teams to verify users with confidence, applying higher assurance only where risk demands it.

Crucially, this approach strengthens security without introducing unnecessary friction for legitimate users. High‑value and high‑risk accounts can be verified using advanced identity checks, while scalable, Microsoft‑native technologies ensure the wider organisation continues to operate efficiently.

The result is a more resilient identity framework. One that helps protect investor trust, reduce the risk of impersonation-driven account compromise, and support Bridgepoint’s continued growth.

Get in touch



University of London | Unified Library Access for 40,000 Students

The Client

The University of London (UoL) Federation, comprising of 17 member institutions, is the UK’s leading provider of digital and blended distance education internationally, with the federation serving over 40,000 students across 190 countries. Founded in 1836, it is one of the world’s largest and most diverse institutions. Known for its commitment to excellence in education, research, and innovation, UoL is a key player in global higher education.

Recognising the importance of efficient and secure access to library services, UoL commissioned Condatis to develop a comprehensive strategy for identity and access management (IAM). Our recommended strategy was specifically tailored to streamline the student onboarding process for their new library system and enhance the user experience across member institutions.

Our work with UoL furthers our commitment to positioning universities at the forefront of innovation, delivering an exceptional student journey, while safeguarding their complex data.

The Challenge

Accessing essential digital resources like library services should be simple, intuitive, and consistent-regardless of which member institution a student belongs to. Through our collaboration with the University of London Federation, our solution would enhance the digital experience for students by streamlining access to shared services. By creating a more unified and user-friendly interface, students would benefit from a smoother, more consistent journey when engaging with academic tools across institutions. This improved experience supports better learning outcomes and reduces complexity for both students and support teams.

University of London recognised the need to improve the user experience across all 17 institutions by enabling students to log in using their existing university credentials. The goal was to ensure a familiar, secure, and streamlined journey that required no new accounts or unfamiliar processes.

We recommended a solution based on Azure AD B2C, which can be customised to meet UoL’s branding and user journey requirements, ensuring a positive and professional experience for library users. This solution aligns with UoL’s requirements and identity strategy for the present and offering a future-ready access model that could unify and simplify the digital experience for students and staff.

Condatis was engaged to assess the existing identity architecture and develop a strategy that enables this federated access approach. The strategy has been delivered and is currently guiding the first phase of implementation.

The Solution

A Federation-First Access Model

The proposed strategy for UoL, centres around enabling uniform library access for users across all 17 participating member institutions, leveraging external identity federation, including all University of London (UoL) staff, students, UOLW (University of London Worldwide), ULIP (University of London Institute in Paris), SAS (School of Advanced Study), and students of federated member institutions (MI). This eliminates the need for separate registration and support processes based on user type. The solution is also designed to be extensible, allowing for the registration and management of public members or users from non-MI bodies through UoL-issued credentials.

Utilisation of existing Entra components

By leveraging existing Entra components, the solution is familiar to UoL’s Identity and Access Management (IAM) team. This familiarity facilitates easier adoption and management, making Entra the right choice for our client. Additionally, the presence of a user record in B2C supports usage tracking and future implementation of a ‘dormant user’ removal process if desired.

Enhanced security and compliance

The solution aligns with core identity management principles, including the application of a zero-trust security model and ensuring least privilege access. This reduces the risk of unauthorised access and ensures that users only have the necessary level of access at all times. The solution also supports regular access reviews and compliance with regulatory and data governance requirements.

Good data and system governance

Clear ownership of data and systems is established, with designated points of contact for assessing changes and managing data cleansing activities. A single team is responsible for defining and managing library access policies, ensuring consistency and accountability.

Forward Compatibility

The proposed architecture is designed for extensibility and future integration with additional systems beyond the library, establishing a flexible, federation-wide model for secure service access.

Preventing credential proliferation

The solution focuses on granting and revoking access based on roles and account status, rather than creating multiple identities for the same individual. This approach simplifies identity management and enhances security by reducing the number of credentials that need to be managed.

By implementing this comprehensive solution, UoL can achieve a streamlined, secure, and efficient library access system that meets the needs of all users while maintaining high standards of data governance and compliance.

The Benefits

Adopting best practices in identity governance through our proposed IAM solution would deliver a range of strategic and operational benefits to the University. These include improvements in user experience, cost control, operational efficiency, and enhanced security and governance.

Improved User Experience

  • A federated identity model enables students from member institutions to access library resources using their existing institutional credentials, eliminating the need for separate logins. This seamless access greatly enhances the academic experience.
  • Through Azure AD B2C, the University has also been able to customise login and registration pages, preserving consistent branding and offering a more intuitive, user-friendly interface for all library users.

Operational Efficiency

  • Automation has been key in driving efficiency – freeing up staff to focus on exceptions and strategic improvements rather than routine tasks.
  • Manual errors and training overhead have been reduced through clearly defined, repeatable processes and templates.
  • With Azure AD B2C, identity governance is centralised and streamlined, supporting both automated and manual access reviews to ensure appropriate access is maintained at all times.
  • The simplification of complex identity infrastructures – both within individual organisations and across organisational boundaries – have enhanced operational efficiency by reducing integration overhead, improving user experience, and strengthening the overall security and usability of identity services.

Enhanced Security and Governance

  • The solution is built on zero-trust principles, ensuring every access request is verified and no user or device is implicitly trusted.
  • By clearly separating internal and external identities, Azure AD B2C enhances security and compliance, isolating access points and applying tailored governance policies.

Quantified Outcomes

Independent research supports the value of this approach. According to Forrester’s Total Economic Impact™ report of Microsoft Entra (March 2023):

  • 50% increase in internal IDAM team efficiency
  • 20% reduction in security breach risk
  • 90% faster access provisioning
  • 75% of password resets handled via self-service
  • Average of 13 additional hours of user productivity per user, per year

These measurable improvements underscore the transformative impact of adopting a modern identity strategy using Microsoft Azure AD B2C.

Get in touch



futuristic-technology-background

Engineering | Entra External ID Architecture

Microsoft and Condatis partnered to assist their client, to design a modern standards-compliant single sign on (SSO) solution for all their applications, across divisions. The solutions aim was to consolidate a range of identity and access management technologies, which had been implemented independently within divisions, into a single identity platform. As this platform would be customer-facing, the client asked Condatis to design a solution using Microsoft External ID.

The Client

The client is a global leader in mining technology, combining deep customer insights, world class engineering, materials science expertise and intelligent automation to deliver innovative end-to-end mining technology solutions.

The Challenge

Following a series of acquisitions, our client found themselves with a fragmented Identity and Access Management (IAM) landscape. Each acquired company brought its own unique strategy and technology, resulting in inconsistent and siloed user access experiences. The lack of a unified IAM platform hindered productivity, security, and scalability for the newly integrated organisation.

As such, the client needed a solution that offered a range of benefits:

Unified Authentication & Federated Access

  • Single Sign-On (SSO) across OpenID Connect and SAML web applications
  • Federated login for users from their home tenants with home-realm discovery
  • Support for multiple corporate identity providers with easy runtime configuration
  • Secure self-service sign-up/sign-in with multi-factor authentication
  • Automated account management including deactivation of inactive users
  • Custom user profiles and role-based access control

User & Entity Management

  • Grouping of users by business entity or company
  • Support for parent/child company hierarchies and multi-location structures
  • Centralised control over which users and companies can access specific applications

Application Access Governance

  • Streamlined user and business entity assignment to applications
  • Self-service user requests and admin approvals for app access
  • Full visibility of app-user, user-app, and company-app relationships

Smooth Migration Path

  • Bulk migration of users from legacy systems
  • Side-by-side operation of old and new systems with data synchronisation
  • Gradual migration of individual apps to minimise disruption

Machine-to-Machine Authentication

  • Secure and scalable service-to-service communication

Robust Logging & Reporting

  • Detailed login activity logs and usage analytics
  • Vulnerability monitoring with automated threat protection
  • Integration with SecOps tools for incident and task management

Enablement for Future Growth

  • Comprehensive documentation and knowledge transfer to empower internal teams for ongoing IAM platform development

Partnering with Condatis

To address these business outcomes, the client engaged Condatis to support the strategic development and technical delivery of a cohesive identity solution using Microsoft Entra External ID.

While the client had already drafted a high-level design, Condatis was brought in to conduct a comprehensive gap analysis, reviewing the design against the detailed project requirements. This analysis identified key risks, missing functionality, and areas for improvement.

Following the gap analysis, Condatis collaborated closely with the client’s team to produce a robust low-level design (LLD) to act as a solution blueprint. This detailed blueprint covered all aspects of architecture, integration, networking, and security – ensuring a development-ready foundation aligned with best practices, tailored to client needs.

The Benefits of Entra External ID

By leveraging Microsoft Entra External ID, the client can achieve a consistent, secure, and scalable IAM experience across all business units and applications.

Based on the solution designed, the client can expect the following benefits:

Unified Experience Across All Applications

With a single, centralised platform, all users – regardless of company or location – will now benefit from a consistent identity and access experience, improving usability and reducing administrative complexity.

Enhanced Security at Scale

By building on Microsoft’s secure, globally distributed, infrastructure, the client can reduce reliance on custom-hosted identity solutions and gain built-in protection against evolving threats.

Cost Efficiency

External ID’s pricing model is based on monthly active users, making it a highly cost-effective solution compared to alternatives. Clients only pay for users who actively authenticate each month, keeping operational costs low and predictable.

Global Reach and Low Latency

With availability across multiple Azure regions, Entra ensures high availability and low-latency authentication for users worldwide – ideal for a distributed enterprise with multiple geographies.

Flexible Identity Provider Integration

Support for external IdPs – including social logins like Facebook and Google – will streamline user onboarding and improve the overall user experience.

Isolated and Secure Data Management

Using External ID in external tenants ensures clear separation of customer identities from internal users and partners, enhancing data governance and compliance.

The result is a future-ready IAM solution that can empower the client to scale securely, manage complexity with confidence, and support innovation across its global business.

Key Highlights

  • Collaborative Discovery
    Worked closely with the client’s IAM team to understand, validate, and prioritise core solution requirements.
  • Cross-Team Engagement
    Engaged with other key internal teams to capture additional infrastructure and security needs, ensuring a fully aligned solution.
  • High-Level Design Review
    Assessed the client’s existing high-level design, identifying potential gaps and providing actionable feedback to strengthen the overall strategy.
  • Expert Guidance on Microsoft Entra External ID
    Shared deep expertise on current and upcoming Entra External ID capabilities, ensuring the solution was future-ready and aligned with Microsoft’s roadmap.
  • Development-Ready Low-Level Design
    Delivered a detailed, implementation-focused low-level design (LLD) that covered architecture, integration, networks, and security-ready to take straight into development.

Throughout the engagement, Condatis acted as a trusted partner, not just a design service. We worked side by side with client stakeholders, offering practical advice, guiding decisions, and shaping a solution that could be confidently implemented. Our design was not theoretical – it was actionable, secure, and intended to scale with the client’s evolving business.

Get in touch



saudi-skyline

Travel | Decentralized Identity

The Client

Our client in the Middle East is a large progressive organisation responsible for the development of an advanced greenfield site, 33 times the size of New York City, that aims to create a futuristic community with advanced technologies, sustainable solutions and many luxury tourism and nature destinations to create a truly unique place to live and visit.  

We embarked on a visionary path with our partners at Publicis Sapient, bridging the gap between tradition and innovation in the Middle East. 

Our work on the project is set to revolutionise how a traveller engages with a destination and provides a seamless traveller experience. Identity is the core component, powered by our evolutionary product, Cenda, to create a Visitor Experience Platform for the client. 

Key Highlights

  • Visitor Experience Platform: Unified, real-time profile and preferences system linked to visitor identity, dynamically updated and accessible to travel providers. 
  • Enhanced Data Security and Privacy: Control over personal information negating the need for local data storage. 
  • Boost Spending: Personalised experiences based on visitor profiles and preferences. 
  • Cross-Brand Loyalty Scheme: Integrated rewards system encouraging engagement. 
  • Compliance and Flexibility: Adapts to varying legal requirements and promotes ecosystem-wide interoperability.

The Challenge

Fragmented identity management systems inhibit today’s travel landscape, where each touch point with travel services requires distinct and unique identity verification steps. This approach undermines the traveller’s security and ease of travel and hampers the smooth exchange of critical information among service providers, diminishing the overall travel experience.  

Online travel agencies exacerbate the issue by filtering travellers’ data from downstream vendors, such as airlines and hotels, creating inefficiencies and service provision limitations. To disrupt this model and improve service for the traveller, there needs to be a unified system that facilitates seamless data sharing across the entire travel journey.  

Additionally, organisations must adapt to changing international standards, such as eIDAS 2.0, to ensure compliance and enhance interoperability. This significant change will necessitate businesses revamping their operations, ultimately contributing to a more streamlined, integrated, and secure travel experience. 

Driven by leading experts, our client defined several challenges: 

  • Fragmented Identity Verification – Travellers repeat identity verification processes at multiple points, from their original booking to on-site services, creating friction and inefficiencies  
  • Multiple user accounts – travellers have to create a separate user account for each service provider on the journey, resulting in repeated processes, inconsistent user experiences and different device experiences 
  • Mutual Authentication through trusted communication channels – finding common ground to establish mutual trust between service providers and travellers. For example, Hotel representatives must trust that they are interacting with verified travellers, and travellers must trust that they are communicating with authorised travel representatives 
  • Inconvenient Data Sharing – The lack of a secure, fluid data-sharing mechanism between service providers compromises the travel experience and operational efficiency  
  • Security and Privacy Concerns – Traditional account-based systems pose risks of data breaches and misuse, eroding traveller trust 
  • Siloed Data and Systems: Loyalty programs, operational processes, and personalisation efforts are limited by fragmented, siloed data and lack of interoperability, hindering seamless service delivery and effective updates across service providers. 
  • Regulatory Compliance and Flexibility – Adhering to diverse regulatory frameworks for data protection and identity management is complex and burdensome. 
  • Innovation and Future Readiness – The hospitality sector’s reliance on outdated identity management practices stifles innovation and adaptation to future trends. To prepare for the future, companies should foster aligned leadership, leverage AI for customer service, adopt agile operating models, and cultivate an innovation-driven culture. Modernising technology platforms will enhance revenue, operations, and customer interactions. 

Without evolution, this fragmented ecosystem will continue to impact the mutual benefits between travellers, service providers, and destinations, causing inefficiencies and overlooking the significant opportunities for innovation and improved service provision in the travel sector. 

The Solution

We are dedicated to transforming visitors’ travel experience by seamlessly integrating Decentralized Identity technology. We aim to provide an enjoyable, stress-free, and frictionless journey.  

To do this, we leveraged our tailor-made product, Cenda to effortlessly scale and configure decentralised identity across our client’s complex identity ecosystem.  

Acting as a middleware, Cenda enables staff, customer and visitor credential verification to be built rapidly using existing ecosystem data sources, the latest decentralised methodologies, identity verification services and biometric technologies.  

In our client’s case, Cenda enabled the development of digital passports to speed up processes, enhance convenience and experience, verify guest identity, facilitate secure transactions, and ensure secure lines of communication between service providers and visitors.  

Our efforts are concentrated on encouraging adoption among visitors, application developers, and service providers in the Hospitality, Travel, and Tourism sectors by simplifying their access to and delivery of this seamless experience through a Visitor Experience Platform powered by Cenda and decentralised technology.  

The platform is strategically designed to enhance the overall visitor experience and streamline processes. It uses a rich decentralised data layer for tailored services and unlocks new revenue opportunities through an exceptional travel experience and secure direct communication channel. 

The Visitor Experience Platform offers a unified, real-time profile of preferences and a direct peer-to-peer communication system linked to a visitor’s identity. It is dynamically updated and makes it readily accessible to participating travel providers. This platform ensures that personal data is transferred transparently between users and ecosystem participants, shareable via Verifiable Credentials stored in their Microsoft Entra Verified ID capable digital wallet or preferences stored within their Decentralized Web Nodes (DWNs) personal data store.  

Through the platform, visitors can effortlessly adapt their profile and preferences at every stage of their journey while enabling service providers to access this data to create a personalised experience enhanced through direct, secure communication. 

Integrating the Visitor Experience Platform into current onboarding pathways enables travellers to enter their information once and then apply it across multiple engagements with various service providers, simplifying their initial setup process. The platform serves as an extensive data repository, continuously enriching a visitor’s profile and preferences as they interact with different services.  

Stored securely in the visitor’s digital wallet and personal data store, this digital identity affords meticulous control over which data is shared, allowing services to be customised through controlled disclosure.  

The visitor’s profile and preferences are not static but can be updated by both the visitor and service providers, ensuring the information remains current and relevant. This adaptability fosters a customised experience that evolves with the visitor’s needs and preferences. Additionally, the platform integrates a cross-service rewards system, enriching visitor engagement and retention across the client’s ecosystem. 

The visitor experience platform facilitates a secure communication channel between visitors and travel providers. Through Peer-to-Peer communication using decentralised identifiers and Decentralized Web Nodes, a secure and private connection is established, ensuring mutual authentication between visitors and service operators. This connection is safeguarded with encryption, allowing for the safe exchange of visitor information. This secure communication is paramount with the emergence of AI and digital agents. Travellers will need to ensure that either the human or the bot is, in fact, the person or provider they say they are. By ensuring the conversation is verified and authenticated on each end, platform users can bolster the trust and commerce being facilitated over this communication channel.  

The platform’s Peer-to-Peer communication capability enables service providers to interact directly with visitors, facilitating activities such as ticket issuance, identity verification, and the provision of a secure platform for personalised up-selling and cross-selling opportunities. This is achieved by leveraging the detailed profile and preferences of the visitor, ensuring that the communication is not only secure but also highly customised to each visitor’s needs and interests. 

Designed with compliance and flexibility in mind, the visitor experience platform can adapt to the varying legal requirements across jurisdictions and promotes ecosystem-wide interoperability and collaboration, supported by standardised protocols and shared infrastructure.

The Benefits

The Visitor Experience Platform goes beyond the standard service by offering personalised recommendations and rewards based on visitor consent. This feature is designed to make visitors feel special and appreciated, enhancing the overall experience and contributing to a memorable journey.  

The Visitor Experience Platform offers a secure, consent-based communication process for travel and tourism service providers. This not only ensures the safety of visitor data, but also establishes a sense of trust and confidence in the service providers, enhancing their relationship with visitors.  

Overall, the platform elevates visitor satisfaction, attracting more tourists and promoting sustainable growth. At a high level, the platform provides the following: 

  • Compliant and standards-based – the adaptability to new national and international digital standards ensures compliance and enhances platform and service interoperability. 
  • Streamlined onboarding process – one-time visitor registration, avoiding repetitive procedures with multiple service providers. 
  • Secure, consent-based visitor-to-provider communication – direct communication where consent governs the continuity of interactions. 
  • Personalised recommendations and traveller rewards – delivering recommendations based on current and dynamically updated traveller preferences. 
  • Easy onboarding for service operators of all sizes – an accessible onboarding system accommodates entities of varying sizes and technical capabilities. 
  • Direct customer interaction and upselling opportunities – a secure communication pathway for direct customer interaction, facilitating an enhanced travel experience. 
  • Deep insights and business intelligence – the platform provides insights into the visitor’s journey improving customer retention and increasing operational efficiency by reducing the administrative load, leading to positive customer feedback. 
  • Enhanced data security and visitor privacy – the technology’s decentralised nature ensures enhanced data security and privacy by reducing local data storage and giving visitors control over their personal information. 

Architectural Highlights

  • World Wide Web (W3C) and Decentralized Identity Foundation (DIF) standards-based architecture. 
  • Microsoft Entra Verified ID based Verifiable Credentials for personal data security and portability. 
  • Decentralized Web Nodes personal data store for interoperability with Web5 Decentralized Web Apps (DWAs)  for data sharing and peer-to-peer communication. 
  • Interoperable Trust Over IP Trust Registry for ecosystem Governance across the Travel and Tourism sector. 
  • Schema Registry for data interoperability throughout the ecosystem.

The combined power of our platform, Cenda, and our experience in professional consulting services paired with our client’s vision represents a transformative step in the evolution of travel and tourism.  

We have created a robust visitor experience platform leveraging digital passports that ensures seamless, secure, and personalised interactions by addressing critical challenges, such as fragmented identity verification, multiple user accounts, and inefficient data sharing. Leveraging decentralised identity technology and innovative new services, this solution enhances operational efficiency and elevates the overall travel experience, setting a new standard for the industry.  

With Cenda, travellers enjoy a streamlined journey from start to finish, service providers gain deep insights and operational benefits, and the destination stands out as a beacon of innovation and sustainability. This ground-breaking project revolutionises how travellers engage with their environment and paves the way for future advancements in hospitality and travel technology, ultimately fostering a more connected, secure, and satisfying travel ecosystem. 

Interested in a similar solution for your organisation?

Get in touch



Manufacturing | Unlocking Efficiency with Microsoft Entra ID Governance

The Client

Our client is a large multinational electronics company headquartered in Singapore. As an industry-leading innovator in household technology with a focus on performance, efficiency, and aesthetics, their products have garnered widespread acclaim and remain amongst top choice for consumers seeking cutting-edge solutions for their homes.

 The Challenge

Our client required a solution to address a number of issues within their ecosystem, most notably, to modernise the joiner, mover, and leaver (JML) processes for their staff and contingent workers. This modernised process would allow our client to speed up the onboarding of new staff and users in their system, increase security by standardising the leavers process, and boost efficiency by reducing unnecessary time spent, and automates a lot of currently manual tasks.

Some of the main issues that our client faced in their ecosystem were:

  • Slow onboarding time for users
  • Too many manual processes were inefficient uses of time
  • Our client’s in-house tool written in ASP.Net 6 is difficult to support.
  • Difficulty identifying different personas and roles
  • A one-persona-for-all approach to their users
  • Inappropriate user types being created (full users where guests would grant access required) causing ineffective usage of licences potentially increasing cost

It was important for our client that improving overall security and enhancing the end users experience was at the forefront of priority when addressing each of their business objectives.

The Solution

Through a Proof of Concept (PoC), Condatis demonstrated to our client that Microsoft Entra ID Governance could meet their objectives, and solve their business challenges, in the following ways…

  1. Perform a comprehensive scoping workshop with our client to:
  • Define 4 separate identity personas with individually corresponding access requirements
  • Define what “Basic Access” is and what this entails
  • Define the criteria for success when looking at the test plan
  1. Assist in the configuration of Workday Provisioning to Entra ID / Active Directory with a hybrid architecture
  2. Assist in the integration of test SaaS platform which supports SCIM.
  3. Implement Entra ID Governance Workflows to cover 2 joiner and 2 leaver processes
  4. Implement Access Packages to manage Mover processes
  5. Run test plan to ensure that PoC meets all success criteria for our clients requirements

The Benefits

Using Microsoft Entra ID Governance, Condatis’ PoC would enable our client to meet the proposed solution’s business objectives.

The key benefits included:

Fully automated end-to-end solution for joiners, movers, and leavers (JML): Implement a seamless process that automates the onboarding, movement, and offboarding of employees (Joiners, Movers, and Leavers) within the organisation. This includes provisioning and deprovisioning of access rights, resources, and privileges across various systems and applications.

Increased security through data quality control and reduced manual intervention: Enhance security measures by implementing robust data quality controls and minimising manual interventions in the JML processes. This ensures that access rights and permissions are accurately assigned and revoked, reducing the risk of unauthorised access or data breaches.

Enforcement of naming standards: Establish standardised naming conventions across all systems and platforms to ensure consistency and clarity in user identification and access management.

Fully scalable cloud solution supporting hybrid architecture: Develop a cloud-based solution that is flexible and scalable to accommodate the client’s current hybrid IT architecture. This ensures compatibility and seamless integration with both on-premises and cloud-based systems.

Optimisation of Entra ID P2 license capabilities: Maximise the utilisation of capabilities included in existing Entra ID P2 licenses to address JML requirements and streamline operations effectively.

Simplified solution architecture using modern capabilities and best practices: Design a solution architecture that leverages modern capabilities and incorporates industry best practices to simplify processes, enhance efficiency, and improve overall performance.

Integration with and enhancement of Microsoft Entra platform: Integrate the proposed solution seamlessly with the Microsoft Entra platform, leveraging its existing infrastructure and functionalities while enhancing its capabilities to meet specific JML needs.

 

This Proof of Concept (PoC) will serve as a foundation for building a compelling business case for the broader implementation of the final solution. The final design aims to achieve the stated objectives, elevate security measures, and enhance the overall end-user experience within our clients’ operations.

Interested in a similar solution for your organisation?

Get in touch



University College London | Seamless Identity Transformation

The Client

University College London, commonly known as UCL, is a leading public research university located in London, United Kingdom. Founded in 1826, UCL is the third oldest university in England. With a diverse and international student body, UCL offers a wide range of undergraduate and graduate programs across various disciplines, including sciences, humanities, law, engineering, and social sciences. UCL is committed to academic excellence, innovation, and social impact, and has produced numerous Nobel Prize winners, leaders in government and industry, and prominent academics and researchers.

Highlights

UCL receive around 140,000 applicants per year and need a solution to modernise their applicant user journey via implementation of Azure B2C tenancy for applicant account management.

In this case study our solutions include:

  • Seamless applicant onboarding and integration with SSO and MFA capabilities as well as introduction of social federation options (Google, Apple ID, Microsoft). Resulting in improved user experience allowing for straightforward registration and self-service password management.
  • Migration of existing applicant accounts from on-premises directory to B2C tenancy.
  • Ensuring consistent UCL experience through branding with the UCL Design system.
  • Enhanced security and compliance with centralised access management and MFA.
  • Operational efficiency with reduced reliance on on-premise services and streamlined management.
  • Scalability and readiness for future customer identity use cases.

The Challenge

UCL, a leading educational institution, faced the challenge of managing applicant accounts efficiently and securely.

Previously, applicant accounts were managed using a variety of legacy on-premises and in-house developed solutions. However, this setup did not allow for integration with UCL’s cloud-based identity platform or allow for a modern authentication experience  for applicant-facing service like the Student Information platform and Accommodation Management application.

The lack of integration hindered the migration of services to the cloud were an obstacle to the adoption of future platforms like Dynamics CRM. UCL needed a solution that would enable seamless applicant onboarding, leverage Microsoft Azure services, and provide a foundation for future customer identity use cases.

The Solution

To address the challenges, Condatis proposed implementing an Azure B2C tenancy to manage applicant accounts. The solution aimed to provide a quality applicant onboarding experience while leveraging the capabilities of the Microsoft Azure platform.

The key objectives included enabling modern authentication including MFA and single sign-on capabilities for student services, introducing social federation options (such as Google, Apple ID, and Microsoft), and establishing a foundation for future use cases in the customer identity space.

The solution Condatis proposed involved creating a registration flow for applicants, verifying applicant-provided data against student records using RESTful APIs, enabling self-service password management, managing account lifecycle, integrating with UCL’s Azure AD for access by the UCL Family (staff, students, and internal visitors), migrating existing applicant accounts from the on-premises directory to a B2C tenancy, and ensuring a consistent UCL experience through branding using the UCL Design system.

The Benefits

The implementation of the proposed solution offered several benefits to UCL:

 

Improved Applicant Experience:

  • Seamless registration process with automated data verification against Student Information System
  • Self-service password management for applicants
  • Enablement of social IDPs (Google, Microsoft, Apple) for convenient authentication

Enhanced Security and Compliance:

  • Integration with UCL’s Azure AD for centralised access management and security controls
  • Ability to enforce MFA for applicant-facing applications
  • Compliance with UCL’s data retention policy for account lifecycle management

Scalability and Future Readiness:

  • Foundation for managing the lifecycle of multiple customer types at UCL
  • Potential for extending the solution to other platforms, such as Dynamics CRM
  • Ability to accommodate increasing numbers of applicants (140K/year)

Operational Efficiency:

  • No longer dependent on on-premises services for applicant facing services
  • Streamlined management of applicant accounts through the Azure B2C tenancy
  • Consistent and intuitive account data management in third-party systems through APIs

Explore our Higher Education Hub> to learn about digital identity solutions for universities.

Interested in a similar solution for your institution?

Get in touch



Defra | Common Identity Platform

The Client

The UK Department for Environment, Food and Rural Affairs (Defra) are responsible for protecting the environment and growing a sustainable and thriving green economy for rural communities in the UK. Defra has a vast external user base that interacts with its digital services. These users vary from European and International bodies, public and private sector bodies, academics and student researchers, voluntary and third-sector organisations, and the general public.

Condatis started working with Defra in 2018 to develop a CIAM system on Microsoft Azure Active Directory to improve access to Defra’s digital services. This initial engagement later led to the further development of Defra’s identity strategy, ensuring their identity systems are fit for resilience and growth and simplifying service provisioning to thousands of users ranging from individuals, suppliers, and external partners.

Highlights

  • Condatis have helped Defra develop a common platform for customer identity that complies with Government standards and provides a single customer touchpoint.
  • Defra rebuilt its digital services post-Brexit to meet current UK requirements.
  • We extended Microsoft Azure AD B2C’s integration capabilities by integrating with external identity providers for user authentication.
  • The new CIAM system streamlines user migration to CRM.
  • Condatis developed an eventing component to track and report security and business-level events raised by the system.

The Challenge


Driven by the need to digitise their services, Defra’s identity journey was interrupted by Brexit bringing additional challenges as services previously provided by the EU had to be rebuilt for the UK whilst maintaining the identity and high-security standards.

Defra needed to reduce duplication and costs by providing individuals with a way of authenticating identity once to grant access to several services instead of prompting users to re-authenticate at each stage, providing consistency of experience.

The key identity challenges for Defra were:

  1. 80% of transactions are business related: A need to verify the individual logging in on behalf of a company such as manufacturers, wholesalers or other rural and agricultural organisations.
  2. Managing complex customer relationships: A need to make sure the employees, as well as any delegated authority, such as agents, who transact on behalf of a particular organisation, have the appropriate level of access and control to interact with Defra services.
  3. Customers having multiple accounts for different services in Defra: A need to create a single identity across all Defra services, considering all the relationships and complexity within the business.

With thousands of external users interacting with Defra’s digital services, the objective of this new implementation was to consolidate all customer details and access control attributes into Defra’s Customer Relationship Management (CRM) systems. HM Revenue and Customs (HMRC) being the sole identity provider, the CIAM system also needed to integrate with HMRC’s Secure Credential Platform.

The large scale of the challenge meant bespoke user journeys and custom policies were required, as well as migration of all legacy data and integration with multiple services. And from the end-user point of view – a single customer touchpoint with self-service capabilities to reduce the resources relating to user management.

The Solution

The solution’s essential requirements were to:

  • Retain existing business logic provided by Defra for registering and maintaining users, specifically managing the grouping of users into Organisations.
  • Support delegation of rights between users.

The crux of Defra’s Customer Identity and Access Management (CIAM) transformation was introducing Microsoft’s Azure AD B2C product as the orchestration engine central to every user registration or authentication journey.

Azure AD B2C’s integration capabilities allowed us to manage integration with external identity providers for user authentication. We also integrated Defra’s Registration Application as an OpenID Connect (OIDC) claims provider to apply the complex business rules around registering users and organisations.

Condatis introduced an abstraction layer to add identity providers and external data sources, extending the solution’s reach and simplifying user migration into the CRM.

Our team also developed an eventing component capable of receiving business-level events raised by the CIAM solution, generating telemetry records, audit records and security events. The solution also included session tracking to improve user sign-in experience, enabling SSO across onboarded relying party applications. This allows users to sign into any available service using their single Defra credential, browse another service and gain access without being challenged to re-authenticate.

We extended this same principle to support Multi-Factor Authentication (MFA) requirements, allowing a service to mandate the level of authentication assurance required for specific user authentication, but trusting the level previously attained within the session to provide security of MFA with the simplicity of SSO.

The solution also involves integration with their chosen Identity Provider (IdP). It considers the authentication assurance level attained on the external IdP so that the user is not prompted to perform the MFA step twice. Securing specific operations allows an onboarded application to mandate MFA for a given authentication request, regardless of whether the user previously completed MFA within the user session.

The Benefits

Using Azure AD B2C to manage customer identity simplifies user access for Defra’s customers and improves the overall digital experience for customers and suppliers alike.

Key benefits:

  • A single account: Defra customers will only need one account to access any digital services supported by that account. They will be able to move between different services, including different regions.
  • Centralised data: This allows Defra to safely keep track of all its customers in one place, offering users a degree of self-management.
  • Improved efficiency: The system will simplify processes for their helpdesk team by giving them a single data source to access customer details, making it easier to assist with customer enquiries.
  • Standardization: Using Azure AD B2C provides a standards-based interface for any application or service to use when onboarding the CIAM.
  • SSO: allows users to sign into any available service using their single Defra credential, browse another service and gain access without being challenged to re-authenticate.
  • MFA: allowing a service to mandate the level of authentication assurance required for specific user authentication but trusting the level previously attained within the session.
  • Scalability: The newly developed CIAM system is more scalable, secure, and resilient, handling growing user numbers and consuming services.

More News

https://condatis.com//news/defra-digital-identity/

Interested in a similar solution for your organisation?

Get in touch



Technology | Verifiable Workplace Credentials

To continue streamlining the way we operate here at Condatis, we are implementing Microsoft Entra Verified ID in our daily work processes. Verifiable credentials help us further secure the way visitors access our office, increase staff onboarding efficiency, and simplify our on-site health and safety procedures.

By using verifiable credentials, we’re able to fully trust records of physical and digital access, ensuring our sites are secure and safely accessible for colleagues and visitors. Let’s understand our use of Entra Verified ID further.

The challenge

The opportunities associated with digital transformation are huge. For companies to innovate their services, digital transformation is essential.  But of course, with any type of digital advancement comes the potential for risk – the risk of data governance challenges in particular. Let’s consider the following challenge-associated scenarios:

  • An organisation’s users are distributed and mobility between physical sites is required.
  • There is a diverse existing legacy technology ecosystem or a need for verifiable data from trusted partners.
  • There is a need for preserving data security, privacy, and transparency for users and organisations.
  • Securing on-site physical access
  • New hybrid work policies for tracking remote and office-based employees
  • Relying on paper documents for onboarding and difficulty accessing a staff directory to manage training records or employee data managing data silos

The solution: build trusted digital relationships

Microsoft Azure AD Verifiable Credentials allows us to empower new and existing staff with the ability to hold their data on their digital wallet and share their credentials in a way that is trusted and convenient to them.

We’ve rolled out verifiable workplace credentials as part of our business process across our:

  • HR function, to simplify the ways we onboard new staff and manage their training credentials during their employment at Condatis.
  • Front of House function, to streamline how we invite external visitors to our offices.
  • Health & Safety measures, to ensure the safety and wellbeing of those on-site, especially if an on-site emergency arises.

Chris Tate, CEO of Condatis said:

“This is an exciting time for Condatis. Some of our team work remotely, and some work in the office. It’s important for us to know who’s on-site, and be able to keep them safe in the event of an emergency. We’re so proud to be early adopters of Microsoft Verifiable Credentials ourselves and proud of the results we’ve driven for our clients. Verifiable Credentials helps us empower our own people to control their data, enabling us to protect their privacy and put the power back in their hands.”

Jess Igoe, Chief People Officer said:

“The new system streamlines how we onboard new employees and how we manage their credentials during their employment at Condatis. Training and continuous development is a major part of our business and impacts how we allocate teams to fit customer projects. In circumstances where our team are required to prove security clearance, such as enhanced disclosure documentation, the system simplifies the way we can provide evidence. With Verifiable Credentials, we can also trace Microsoft certified training records in addition to others like Fire Safety, First Aid and Mental Health First Aid.”

The technology: Condatis Credential Gateway

Condatis mobile credentialsCredential issuance and verification simplified

We have developed a gateway to enhance Microsoft’s Entra Verified ID solutions. The Condatis Credential Gateway © (CCG) is a decentralized identity service that provides us and our clients with a platform to simplify credential issuance and verification.

providing verifiable credential capabilities in a common standards-based approach to support easy integration with any verifiable credential or Identity Verification service provider without being bound to a provider, or limited to a single use case.

In an integrated identity strategy, verifiable credentials combined with CCG offer a solution where communications protocols need to be merged, converging data for a streamlined identity journey. By issuing personal identification data to a mobile device loaded with secure wallets, users can share, hold, and control their data on the go. When requested this data can be shared and cryptographically verified to ensure it hasn’t been changed since it was issued, without needing to link back to the original issuer of the credential.

The Condatis Credential Gateway simplifies the introduction and implementation of Verifiable Credentials within organisations, enabling them to be integrated into identity journeys using existing data sources or external services. Through standards-based API’s credential data can be extracted from existing systems, credentials issued, and the verification process managed.

The Condatis Credential Gateway can chain identity journey steps together, using Azure AD and external Identity Verification or Biometric capture services, to generate a verifiable credential.

Digital Opportunities: Reducing Costs & Risks. Improving security and efficiency.

Our clients and partners use our Credential Gateway to explore solutions to Staff and Student Passporting challenges and discover new digital opportunities, such as:

  • Connecting people and organisations: identifying staff and students as they move between physical sites to dramatically improve administrative efficiency and flexibility.
  • Improving privacy & transparency: by placing users at the centre of the management and control of their data using digital wallet consent models.
  • Quality of service: by recording attributes related to people to improve appraisals, employment onboarding and skills development.
  • Mitigating and managing risk: within regulated environments, immutable tracking of who and what has happened during a process.
  • Adapting technology diversity: allowing improved identity management without wholesale system change, such as Sellafield as one of 13 independent estate sites in the UK and the 223 NHS trusts within England.
  • Building trusted digital relationships: between organisations without the need to build direct links, for example combating qualification fraud or checking compliance to sector requirements.

Key Takeaways

  • CCG dramatically improves data privacy and transparency by placing the user at the centre of control.
  • Verifiable Credentials and the CCG enable organisational cost savings by streamlining organisational administration.
  • The CCG can be used as pure play decentralized identity solution or integrated as part of a hybrid solution to solve complex identity challenges.
  • CCG offers organisations stability and identity expertise in a maturing technology.
  • CCG offers standards-based APIs, such as OIDC, that can be used to orchestrate identity journeys and issue and verify verifiable credentials.
  • Organisations can integrate the CGG by either building their own applications, connecting to existing systems, such as Azure AD, or working with Condatis’ to build customised applications.
  • The CCG is designed to be expandable allowing the chaining of identity services, such as identity verification or biometric capture, and the addition of new technologies as they become available to the market, such as personal identity hubs.

 

John Yau, Chief Information Officer said:
“The examples we have deployed within Condatis demonstrate practical use cases operating within the same organisation. But the principles are similar to the wider scenarios where multiple parties are involved. Verifiable credentials are digitally signed using cryptographic methods, creating an immutable chain of trust leading to the issuer of the credential. This means you can count on the provenance and integrity of the digital credential. i.e. you can’t argue with it! That’s a lot harder to do with a paper document or email.

The use of open standards provides a basis from which to build scalable and extensible decentralised identity ecosystems. The decentralised nature means no personal data has to be held in database silos, so risk of data breach is eliminated. There are huge benefits from the user’s viewpoint.

They can control what data is presented to the verifier, on a “need to know” basis. This ‘data minimalization’ is safer where there are privacy concerns, as there is less scope for personal information leakage. Wallet technology on mobile phone devices offers a convenient user experience, with the added benefit of using biometric binding for authentication.”

 

Customer Success: Delivered in partnership with Microsoft

Enhancing student experiences with Microsoft Entra Verified ID

Condatis and Microsoft engaged in a Proof of Value project with the Royal Melbourne Institute of Technology. The Proof of Value (PoV) focused on using Entra Verified ID to facilitate smoother student onboarding and use cases to enhance the student experience. (Read the full case study…)

 

Optimising staff movement for Sellafield Ltd – a verifiable credentials case study

This verifiable credentials case study covers Condatis and Sellafield’s work to optimise staff movement with distributed ledger technology to expand Sellafield’s employee identity management capabilities. (Read the full case study…)

Microsoft Case Study | With high levels of security and trust, the NHS rapidly meets clinical demands using verified credentials

The National Health Service (NHS) in the UK is using verified credentials to support swift staff movement between NHS organizations, allowing staff to store their own verified records for employment, clearance, and other attributes on their smartphones. (Read the full case study…)

 

Transform your business with Condatis and Microsoft. Find out how you can use our Credential Gateway to transform your business with verified credentials.

Get in touch



Privacy Preference Center

Condatis
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.