Conozca a nuestros expertos en IT & Cybersecurity Meetings en Marbella | 17–19 de noviembre de 2026

A Managed Service Model that Scales with Growth: Mondi Modernizes Its Identity Architecture with
iC Consult and Establishes Service Layers as Its Long-term Operating Model

Gestión de Accesos, Servicios gestionados IAM
Service Layers Platform

Vienna-based Mondi AG, one of the leading global players in the paper and packaging industry, faced the challenge of transforming its grown identity structure into a future-proof access management architecture. Together with iC Consult, the company consolidated its Microsoft and SAP identities into a single central user identity, introduced single sign-on with multi-factor authentication for around 80 applications, and established secure self-service onboarding for new applications. iC Consult ensures the scalable and compliant operation of the solution as part of highly available managed services based on the Service Layers platform.

Content

Customer & Project Overview

Customer Profile

Industry: Paper & Packaging

Headquarters: Vienna, Austria

Employees> 24.000

Number Identities: ~ 24.000

About the Customer

Mondi is one of the leading companies in the international paper and packaging industry and contributes to a better world with sustainable products. The group employs 24,000 people in more than 30 countries and pursues an integrated business model along the entire value chain. Mondi offers innovative solutions for consumer and industrial applications. Sustainability is a core part of the strategy, with clear targets through 2030 and a strong focus on circular solutions and climate protection.

Project Description

Establishing a central access management platform with strong multi-factor authentication across all relevant access scenarios, complemented by convenient single sign-on. Setup of a self-service portal that lets application owners integrate new applications quickly and easily.

Products & Services

System integration by iC Consult; operated as part of Service Layers’ Managed Services

Results

Migration of around 80 applications within 12 months to a new central SSO and MFA platform

Introduction of a company-wide identity provider with rule-based MFA enforcement across all web, cloud, and infrastructure access

Seamless migration of MFA and VPN services with no impact on end users

Introduction of a self-service portal with predefined security templates for standardized integration of new applications by application owners

Build-out of a multi-regional, dynamically scalable cloud setup with guaranteed availability of over 99.95% worldwide on the Service Layers platform

Operation of the entire IAM platform as a highly available, scalable managed service by Service Layers – including monitoring, logging, DevOps, and infrastructure as code

Background

When Mondi decided to put its Identity and Access Management strategy to the test, the company did not do so because of any acute weakness. Mondi already had an established access management solution that was reliably in use. However, the underlying identity model – with separate Microsoft and SAP accounts for many employees – was increasingly proving to be a limitation. Historically, two separate account worlds existed, which had run stably and functionally for many years. But as demands around cloud usage, user-friendliness, and security grew, this model increasingly reached its limits.

Managing multiple identities per person in parallel made consistent governance more difficult, increased complexity, and stood in the way of a comprehensive security strategy. The strategic decision was therefore clear: going forward, there should be exactly one central identity per person – secured by consistently enforced multi-factor authentication.

This step marked a genuine paradigm shift: to cleanly merge the Microsoft and SAP identities and manage them centrally, Mondi opted for a fundamental modernization of its architecture.

Solution

Two Sub-projects, One Shared Goal

The program was structured into two closely interlinked sub-projects. The first step was to establish a centralized identity lifecycle management system. The second – far more visible to users and business units – was the modernization of access management with single sign-on and MFA enforcement across all web, cloud, and infrastructure access.

The decision focused on the consistent enforcement of multi-factor authentication across all relevant access scenarios – Web SSO, VPN access, and interactive Windows logins. Mondi therefore chose an established access management platform that offers identity provider (SSO), MFA, and Windows client functionality, both natively and through integration. “The key factor was the high level of flexibility,” explains Markus Hörth, Infrastructure and Security Architect at Mondi. “There was practically no problem that couldn’t be solved with built-in features or targeted extensions.”

For the implementation, Mondi sought a partner with in-depth identity expertise and found one in iC Consult. “We held a series of reference calls with comparable companies – and they very quickly showed us that iC Consult was the right partner here,” says Markus Hörth.

80 Applications, Three Stages, and a Tight Timeline

This ambitious project kicked off in 2021 with a bold goal: within one year, the existing application landscape was to be fully migrated to the new access management platform. In total, this involved around 80 applications, each of which was to be set up in the identity solution as a development, test, and production environment.

Alongside the technical migration, coordinating the numerous application owners proved to be a particular challenge: “Onboarding the applications is not a process that can be automated,” states Markus Hörth. “There is a lot to clarify, align, and schedule – and to raise awareness of security issues on the application side.” Sebastian Mennicke, IAM Lead Consultant at iC Consult, adds, “Zero trust is a complex topic. By working as one joint team, we were able to migrate even Mondi’s critical applications to the new architecture efficiently and securely.”

Given the significant organizational effort that tied up many internal resources, iC Consult took on large parts of the technical implementation: to structure the process, a standardized onboarding approach was established, with results prioritized in a central backlog and implemented step by step. In the vast majority of cases, apps could be connected via standard interfaces; only a small number of integrations required individual customization.

To make onboarding even more efficient, iC Consult also developed a migration tool that automatically analyzed and transferred existing configurations. Even after the first migrations, it became clear that a purely manual approach would not have been feasible within the timeframe. “Automating the configuration transfer massively accelerated the process – and the deadline was now within reach,” explains Sebastian Mennicke.

“The collaboration was marked by a high degree of transparency. That built trust and enabled us to move forward quickly even on complex topics.”

Markus Hörth, Infrastructure and Security Architect at Mondi

From Project to Platform: Self-service Instead of a Ticket Flood

After completing the migration and decommissioning the legacy system on schedule, the project’s focus shifted. Instead of integrating existing services, app owners’ requests increasingly centered on onboarding new greenfield applications – applications that had never previously been part of the old environment.

 

For Mondi, this was a clear sign of the high level of internal acceptance of the new solution. At the same time, the company wanted to avoid becoming dependent on external support in the long term or creating new security risks through individual one-off solutions.

 

The answer to this was the introduction of a self-service portal for application owners. Using predefined templates, app owners can now integrate new applications into the SSO and MFA ecosystem largely with one click – without ticket processes or waiting times. The templates thereby implement the defined security requirements in a binding way and ensure that every new application automatically meets the required security level. In this way, Mondi significantly accelerates the onboarding of new applications, reduces coordination efforts, and strengthens governance at the same time. Security and efficiency are no longer at odds but are systematically linked.

Managed Service as a Strategic Decision

Mondi had already made a key strategic decision at the start of the project: the solution would not be operated in-house, but rather obtained as a managed service from iC Consult via the Service Layers platform.

For this purpose, the platform is operated as a highly available, multi-regional setup in the cloud – including monitoring, logging, a DevOps environment, and infrastructure as code. The system operates with redundancy across multiple regions and can be scaled flexibly as needed. “It was clear to us: we want maximum security, compliance, and future readiness – and a partner who truly lives operations,” says Markus Hörth. “The managed service approach from Service Layers is an enormous relief for our internal team, ensures continuous operations, and makes sure the platform always stays up to date.”

From iC Consult’s perspective, this exact combination is decisive. The solution combines the flexibility and maturity of established on-premise products with the advantages of modern cloud architectures. At the same time, it offers a high degree of transparency, which makes it possible – especially during troubleshooting – to quickly identify where action is needed. Combined with DevOps-based cloud operations and flexible integration capabilities, this creates significant added value – both in ongoing operations and in the platform’s further development.

Outlook

A Scalable Foundation for the Future

Today, Mondi has a modern Identity and Access Management platform that goes far beyond the original project goal. All identities are consistently managed, security policies are enforced centrally, and new applications can be integrated quickly and in a controlled way. “What convinced me most were the flexibility of the solution, the professional implementation by iC Consult, and the consistent, well-thought-out platform that Service Layers provides as a managed service,” Markus Hörth sums up. “Today we’re able to implement requirements that would hardly have been feasible before – and at a very high level of security.”