A global chemical company with tens of thousands of employees worldwide was managing around 200,000 internal and external identities within a landscape that had grown over the years and become increasingly hard to navigate. Together with iC Consult, the company modernized its access management, built a central identity platform, and introduced the first Zero Trust standards for cloud access.
Content
Customer & Project Overview
Customer Profile
Industry: Chemicals
Headquarters: Europe
Number Identities: > 200,000
The company is one of the leading players in the international chemical industry. With plants and offices in numerous countries, it supplies customers across various industries and end markets with a broad portfolio of chemical products and solutions.
Modernization of company-wide access management with single sign-on and multi-factor authentication, buildout of a central identity governance platform to replace the previous system landscape, and introduction of the first Zero Trust standards for cloud access.
Microsoft Entra ID (Azure AD), Windows Hello for Business, One Identity Manager; operated as a managed service by iC Consult
Results
Unified digital identity as the target model for up to 200,000 internal and external users
More convenient login experience for employees in day-to-day work and increased visibility into access management processes
Automated provisioning of new cloud applications via SCIM instead of manual upkeep
Step by step replacement of the previous identity governance system during ongoing operations, without disrupting day-to-day business
Infrastructure available around the clock through on-call support across time zones
Internal team increasingly enabled to handle support independently through targeted training
Foundation for differentiated authentication and identity assurance levels (AAL/IAL) across cloud and on-premises systems
Continuous operation and further development of the solution through iC Consult as a managed service partner
Background
At a chemical company with around 200,000 internal and external identities, decades of growth had produced a wide range of different systems. Internal identities were managed through an established system alongside an additional, custom-built solution, while external identities ran on a separate platform. Both approaches worked well for a long time but eventually became a bottleneck: the source systems became harder to keep in sync, and changes still had to be reliably provisioned into the SAP systems.
The login process itself created friction too. The internal team could not sustainably run the access management infrastructure, including on-call support, on its own, and signing in was far from convenient for employees. At the same time, security could not be compromised: high standards had to apply even without a physical smart card on hand, and an existing certificate-based login needed to keep working.
On top of that, the new solution had to support both growing cloud adoption and the numerous on-premises systems still in use. Both worlds had to run side by side.
Solution
More Secure and More Convenient: The New Access Management
The first step was to give employees one identity to work with, instead of juggling separate accounts for local and cloud systems. iC Consult connected the existing on-premises directories to the cloud using Azure AD Connect and Azure AD Federation Services, so employees now have a single identity that works both locally and in the cloud. New cloud applications pull their access data automatically through SCIM provisioning ever since, whether someone joins, changes departments, or leaves the company.
On this foundation, iC Consult then redesigned the login itself: biometric authentication, PIN, and physical smart cards, complemented by Windows Hello for Business as a virtual smart card for Windows and Microsoft 365. For situations without a hardware token at hand, for example on the road, alternative MFA methods such as one-time passwords or an authenticator app kept every login equally secure. Microsoft Rights Management adds an additional layer of protection for company data on mobile devices.
The effect showed up quickly in daily work: employees now sign in noticeably more conveniently, and access management processes are far more transparent to everyone involved. To keep it that way, iC Consult runs the on-call support across time zones that the internal team could not have delivered alone, while training the team to take on more of the installation and support work themselves.
One Identity Instead of Many: Building the New Platform
While access management takes care of everyday login, a second initiative had to solve what was really holding things back: bringing two disconnected identity worlds together into one. The answer is a new, central identity governance platform based on One Identity Manager, gradually replacing the previous system for around 200,000 internal and external identities and turning two previously separate worlds into a single digital identity.
Rather than one large step, the rollout happens in stages, each one starting where the benefit shows up fastest. The current focus is on account management for SAP systems, onboarding of new applications, requesting Azure AD roles, and integration with ServiceNow. iC Consult not only supports this ongoing development but also operates the platform as a managed service.
The Next Step: Zero Trust for Cloud Access
As cloud adoption grows, knowing who is logging in is no longer enough; it also matters how reliably that identity was verified in the first place. That is exactly what the third initiative addresses: together with iC Consult, the company is embedding Zero Trust principles into cloud access, among other things by harmonizing federated authentication, building out identity governance specifically for cloud resources, and introducing authentication and identity assurance levels. This makes it possible to control, with much more precision, how strongly an identity is verified and how secure a given login really is, across both cloud and existing on-premises systems.
For the people responsible within the company, this was never just about technology: only a login that is secure and frictionless at the same time lets employees around the world work productively, without compromising the security standards a global corporation must meet.
Outlook
A Foundation for What's Next
This modernization is not a single project, but part of a multi-year program that continues step by step. The Zero Trust initiative moves through further stages of maturity through 2026, and identity governance for externally facing services, such as customer portals, is already on the agenda too. With iC Consult as its managed service partner, the company has built a reliable foundation for what comes next.