CYBERSECURITY & IDENTITY

Zero-Trust Identity Platform for Enterprise SSO

Deployed a centralized identity broker supporting SAML 2.0, OIDC, and FIDO2 WebAuthn across 40+ SaaS applications, reducing account takeover incidents by 96%.

96% Fewer ATO Incidents40+ App IntegrationsPasswordless Auth
Key Takeaways
- Phasing out passwords in favor of FIDO2 hardware keys and WebAuthn eliminated credential stuffing across 5,000 enterprise employees.
- Real-time contextual risk engine evaluates device posture and network telemetry before granting application sessions.
- Centralizing 40+ enterprise SaaS apps behind a hardened Keycloak cluster reduced helpdesk password tickets from 200+ to 11 per week.

The Challenge

A 5,000-employee enterprise managed credentials across 40 disparate SaaS tools with no unified directory. Credential reuse resulted in 48 confirmed account takeover (ATO) incidents annually, while IT helpdesks spent 200+ hours monthly resolving manual password reset requests.

Architecture & Technical Approach

  • Identity Broker Cluster: Deployed a hardened, multi-region Keycloak cluster extended with custom Java SPIs for adaptive risk scoring.
  • FIDO2 WebAuthn Deployment: Rolled out YubiKey 5 hardware keys and platform biometrics (Touch ID, Windows Hello) for passwordless authentication.
  • Continuous Risk Scoring Engine: Evaluates device MDM compliance, geographic velocity, and network reputation on every session handshake.

Quantitative Benchmarks & Results

Security IndicatorLegacy Fragmented AuthZero-Trust WebAuthn SSOImprovement
Annual Account Takeover Incidents48 Cases2 Cases95.8% Incident Drop
Weekly Password Reset Tickets200+ Tickets11 Tickets94.5% Helpdesk Reduction
Employee Authentication Time14.0 Seconds3.1 Seconds4.5x Faster Login
Centralized SSO Coverage0% (Fragmented)100% (40+ Apps)Complete Visibility

Production Reliability & Lessons Learned

Deploying LDAP-to-OIDC translation proxies allowed legacy internal tools to benefit from modern WebAuthn MFA without modifying legacy application code.