Proven outcomes

State Emergency Management PIV-I Modernization

Modernizing PIV-I authentication with Okta and Microsoft Entra coexistence for emergency management staff, partner agencies, courts, public safety organizations, and jurisdiction users.

Presented as an anonymized client outcome based on Tecnics identity work in a public-sector emergency management environment. Specific customer names, dates, and implementation details are generalized unless approved for public reference use.

Identity expertise

Client Profile

Industry

State & Local Government.

Organization Type

Large state emergency management organization supporting internal staff, partner agencies, public safety organizations, courts and judicial stakeholders, state law enforcement partners, counties, jurisdictions, contractors, and external collaborators.

Scale Snapshot

Approximately 600 internal staff, roughly 45,000 non-agency partner users, and more than 250 counties and jurisdictions participating in emergency management and public-sector collaboration workflows.

Focus Areas

PIV-I authentication, passwordless access, Okta as centralized identity provider, Microsoft Entra federation, Okta and Entra coexistence, just-in-time provisioning, partner agency identity, lifecycle automation, and governance-ready operating models.

Identity expertise

Business Challenge

The organization had already issued PIV-I cards to internal staff, but the credentials were underused. Staff continued to rely on multiple passwords for workstation and application access, creating user friction, operational inefficiency, security risk, and identity assurance concerns.

Underutilized PIV-I Credentials

Internal users had strong credentials available, but daily authentication patterns still depended on passwords across devices and applications.

Okta and Entra Boundary Decisions

The organization needed a practical coexistence model where Microsoft Entra remained the source of truth for internal staff while Okta served as the centralized identity provider for application access and broader public-sector collaboration.

Large Partner User Population

Non-agency partner users were not part of the Entra domain and did not initially use PIV-I cards. The program needed to support an Okta-mastered population at scale while preserving a path toward stronger authentication over time.

Public Safety and Judicial Collaboration

Emergency management workflows required access for counties, jurisdictions, public safety organizations, state law enforcement partners, judges, courts, and other agencies that needed secure collaboration without a one-size-fits-all identity model.

Provisioning and Deprovisioning Risk

Internal and partner populations required different lifecycle patterns. Internal users needed Entra-to-Okta just-in-time provisioning, while non-agency users required pre-provisioning through bulk import, API-based processes, or other Okta-mastered workflows.

Identity expertise

Tecnics Role

Tecnics helped define an identity modernization approach that aligned PIV-I authentication, Okta, Microsoft Entra, internal staff access, partner agency identity, and long-term public-sector passwordless goals.

Assess

Review current authentication patterns, PIV-I readiness, Okta and Entra architecture, source-of-truth decisions, workstation access needs, application access flows, partner user populations, and lifecycle processes.

Design

Define a coexistence model where internal staff authenticate with PIV-I card and PIN, Microsoft Entra remains the staff source of truth, Okta centralizes application access, and partner agency users remain Okta-mastered until stronger authentication can be introduced.

Implement

Support federation, JIT provisioning patterns, Okta application access, PIV-I authentication flows, partner user onboarding patterns, and operating procedures for internal and non-agency populations.

Operationalize

Create runbooks for provisioning, deprovisioning, access troubleshooting, partner user handling, authentication exceptions, platform ownership, and future expansion of PIV-I or phishing-resistant authentication to partner communities.

Identity expertise

Target Identity Model

The modernization model separated internal staff and partner agency users while creating a path toward consistent, phishing-resistant access over time.

Internal Staff

Internal staff authenticate using PIV-I card and PIN. Microsoft Entra remains the source of truth, and Entra-to-Okta integration supports just-in-time provisioning and passwordless SSO for workstation and application access.

Partner Agency Users

Non-agency users authenticate directly to Okta. They are Okta-mastered, provisioned in advance through bulk import or API-based processes, and managed outside Entra until the organization is ready to extend PIV-I or other phishing-resistant authentication patterns.

Platform Coexistence

Okta acts as the centralized identity provider for application access while Microsoft Entra supports the internal workforce directory, federation, and Microsoft ecosystem integration. Clear platform boundaries reduce confusion and make operations easier to support.

Long-Term Authentication Roadmap

The program establishes a foundation for gradually expanding PIV-I or other phishing-resistant authentication methods across partner agencies, courts, public safety groups, counties, and jurisdictions.

Identity expertise

Outcome Snapshot

Reduced Password Friction

Internal staff move toward PIV-I card and PIN authentication for workstation and application access instead of managing multiple passwords.

Stronger Identity Assurance

Phishing-resistant authentication, centralized identity provider patterns, and clearer platform boundaries align the program with Zero Trust and federal identity assurance expectations.

Clearer Okta and Entra Coexistence

The organization gains a practical model for where Okta leads, where Entra remains authoritative, how federation should work, and how lifecycle processes should operate.

Scalable Partner Identity

Okta-mastered partner identity supports large external populations without forcing every non-agency user into the internal Entra environment.

Better Lifecycle Operations

JIT provisioning, bulk/API provisioning patterns, deprovisioning runbooks, and operational ownership reduce manual identity administration and improve audit readiness.

Start a conversation

Planning PIV-I, Okta, and Entra Coexistence?

Tecnics can help design and operationalize identity architectures that support PIV-I authentication, Okta, Microsoft Entra, partner agencies, public safety users, courts, counties, jurisdictions, and long-term passwordless goals.