Industry
State & Local Government.
Proven outcomes
Modernizing PIV-I authentication with Okta and Microsoft Entra coexistence for emergency management staff, partner agencies, courts, public safety organizations, and jurisdiction users.
Presented as an anonymized client outcome based on Tecnics identity work in a public-sector emergency management environment. Specific customer names, dates, and implementation details are generalized unless approved for public reference use.
Identity expertise
State & Local Government.
Large state emergency management organization supporting internal staff, partner agencies, public safety organizations, courts and judicial stakeholders, state law enforcement partners, counties, jurisdictions, contractors, and external collaborators.
Approximately 600 internal staff, roughly 45,000 non-agency partner users, and more than 250 counties and jurisdictions participating in emergency management and public-sector collaboration workflows.
PIV-I authentication, passwordless access, Okta as centralized identity provider, Microsoft Entra federation, Okta and Entra coexistence, just-in-time provisioning, partner agency identity, lifecycle automation, and governance-ready operating models.
Identity expertise
The organization had already issued PIV-I cards to internal staff, but the credentials were underused. Staff continued to rely on multiple passwords for workstation and application access, creating user friction, operational inefficiency, security risk, and identity assurance concerns.
Internal users had strong credentials available, but daily authentication patterns still depended on passwords across devices and applications.
The organization needed a practical coexistence model where Microsoft Entra remained the source of truth for internal staff while Okta served as the centralized identity provider for application access and broader public-sector collaboration.
Non-agency partner users were not part of the Entra domain and did not initially use PIV-I cards. The program needed to support an Okta-mastered population at scale while preserving a path toward stronger authentication over time.
Emergency management workflows required access for counties, jurisdictions, public safety organizations, state law enforcement partners, judges, courts, and other agencies that needed secure collaboration without a one-size-fits-all identity model.
Internal and partner populations required different lifecycle patterns. Internal users needed Entra-to-Okta just-in-time provisioning, while non-agency users required pre-provisioning through bulk import, API-based processes, or other Okta-mastered workflows.
Identity expertise
Tecnics helped define an identity modernization approach that aligned PIV-I authentication, Okta, Microsoft Entra, internal staff access, partner agency identity, and long-term public-sector passwordless goals.
Review current authentication patterns, PIV-I readiness, Okta and Entra architecture, source-of-truth decisions, workstation access needs, application access flows, partner user populations, and lifecycle processes.
Define a coexistence model where internal staff authenticate with PIV-I card and PIN, Microsoft Entra remains the staff source of truth, Okta centralizes application access, and partner agency users remain Okta-mastered until stronger authentication can be introduced.
Support federation, JIT provisioning patterns, Okta application access, PIV-I authentication flows, partner user onboarding patterns, and operating procedures for internal and non-agency populations.
Create runbooks for provisioning, deprovisioning, access troubleshooting, partner user handling, authentication exceptions, platform ownership, and future expansion of PIV-I or phishing-resistant authentication to partner communities.
Identity expertise
The modernization model separated internal staff and partner agency users while creating a path toward consistent, phishing-resistant access over time.
Internal staff authenticate using PIV-I card and PIN. Microsoft Entra remains the source of truth, and Entra-to-Okta integration supports just-in-time provisioning and passwordless SSO for workstation and application access.
Non-agency users authenticate directly to Okta. They are Okta-mastered, provisioned in advance through bulk import or API-based processes, and managed outside Entra until the organization is ready to extend PIV-I or other phishing-resistant authentication patterns.
Okta acts as the centralized identity provider for application access while Microsoft Entra supports the internal workforce directory, federation, and Microsoft ecosystem integration. Clear platform boundaries reduce confusion and make operations easier to support.
The program establishes a foundation for gradually expanding PIV-I or other phishing-resistant authentication methods across partner agencies, courts, public safety groups, counties, and jurisdictions.
Identity expertise
Internal staff move toward PIV-I card and PIN authentication for workstation and application access instead of managing multiple passwords.
Phishing-resistant authentication, centralized identity provider patterns, and clearer platform boundaries align the program with Zero Trust and federal identity assurance expectations.
The organization gains a practical model for where Okta leads, where Entra remains authoritative, how federation should work, and how lifecycle processes should operate.
Okta-mastered partner identity supports large external populations without forcing every non-agency user into the internal Entra environment.
JIT provisioning, bulk/API provisioning patterns, deprovisioning runbooks, and operational ownership reduce manual identity administration and improve audit readiness.
Identity expertise
Start a conversation
Tecnics can help design and operationalize identity architectures that support PIV-I authentication, Okta, Microsoft Entra, partner agencies, public safety users, courts, counties, jurisdictions, and long-term passwordless goals.