Skip to content

How to Optimize Digital Identity Management for Your Business in 2024

Managing digital identity in a company is not just about choosing a good password. It encompasses all the mechanisms that…

Professionnelle en blazer marine gérant l'identité numérique de son entreprise sur un poste de travail à double écran en open space
5 min

Managing digital identity in a company goes beyond just choosing a good password. It encompasses all the mechanisms that allow you to know who accesses what, when, and with what level of trust. In 2024, this management must integrate new constraints: European identity wallets, non-human identities linked to APIs and AI agents, and a gradual abandonment of traditional passwords. Here’s how to structure this transition without suffering through it.

Non-human identities: the blind spot of most IAM policies

Have you ever counted the number of active service accounts in your information system? In most companies, non-human identities (service accounts, API keys, cloud workloads, bots) far exceed the number of user accounts.

The problem is real. These identities often operate with static secrets, rarely renewed, sometimes shared between teams. A service account created for a pilot project three years ago is still running, with broad access rights, without an identified owner.

Each non-human identity must be linked to a human owner. This is the first principle to apply. The second is to limit rights to the strict minimum, and then store secrets in a dedicated vault with automated rotation. The NIS2 and DORA regulatory frameworks address this issue indirectly, through access control and risk management related to IT service providers.

If you are starting an inventory, begin with the API keys exposed in production environments. These are the most critical and often the least documented. To find information on identitools.fr regarding tools suitable for this approach, the topic is addressed from an operational perspective.

IT director analyzing a digital identity management system on a tablet in a corporate server room

Phishing-resistant authentication: passkeys and FIDO2 in practice

Classic multi-factor authentication (SMS, temporary code apps) remains vulnerable to certain interception or social engineering attacks. An attacker controlling a session proxy can capture the code in real-time.

Passkeys and the FIDO2/WebAuthn protocol eliminate this attack vector. The principle: authentication relies on a cryptographic key tied to the user’s device. Nothing is transmitted to the server that can be intercepted or replayed.

In practical terms, an employee authenticates using a fingerprint or facial recognition on their device. The server verifies a cryptographic signature, not a shared secret. No password to remember, no code to copy.

Deploying passkeys in phases

The transition to passwordless does not happen in a day. Start with the most exposed populations: system administrators, teams with access to sensitive data, high-privilege accounts.

  • Identify FIDO2 compatible applications in your current software inventory. Major cloud providers and web browsers already support this protocol.
  • Plan for a coexistence period where the old system (password + classic MFA) remains available as a fallback, while users adopt passkeys.
  • Document access recovery procedures in case of device loss, as a lost device without a fallback procedure locks the user out.

The security gain is real, but deployment requires diligence in supporting the teams.

European Digital Identity Wallet (EUDI Wallet): what changes for businesses

The eIDAS 2.0 regulation introduces the EUDI Wallet, an interoperable digital identity wallet at the European level. This is not a distant project.

Starting in December 2027, private actors subject to strong authentication requirements will have to accept the EUDI Wallet in the relevant regulatory cases. Affected sectors include banking, insurance, energy, telecommunications, transport, health, and education, as well as certain very large platforms.

Multidisciplinary team in a strategic meeting around a touchscreen presenting a digital identity governance scheme in a company

What this implies right now

Waiting until 2027 to take an interest would be a mistake. Authentication, KYC (Know Your Customer) processes, and electronic signature journeys must be audited now. The question to ask your technical teams is simple: can our systems accept interoperable identity proofs with selective attribute disclosure?

Selective disclosure means that a user can prove they are of legal age without revealing their full date of birth, or confirm their address without exposing their name. This is a change in logic for the usual forms and databases, which often collect more than necessary.

  • Audit your customer onboarding journeys to identify those requiring regulatory identity verification.
  • Check if your electronic signature and KYC providers plan for EUDI Wallet compatibility in their roadmap.
  • Anticipate the redesign of data collection forms to adopt the minimization principle imposed by the wallet.

IAM Governance: structuring responsibilities before purchasing tools

Many companies acquire an IAM (Identity and Access Management) solution before defining who decides what. The result: the tool is deployed, but no one validates access requests, rights reviews are postponed, and orphan accounts accumulate.

Governance always precedes tooling. Three questions structure this governance: who owns each application? Who validates access? How often are rights reviewed?

An application owner is the business person (not just IT) who knows which profiles need access to what. Without this role clearly assigned, access requests end up being validated by default, without real verification.

Rights review: a frequency suited to risk

Not all applications deserve the same frequency of control. An internal management tool can be reviewed biannually. Access to customer or financial data deserves a quarterly review, or even monthly for high-privilege accounts.

The maturity of an IAM policy is measured less by the number of features of the tool than by the regularity with which unnecessary rights are actually revoked. A well-maintained spreadsheet is better than a sophisticated platform that no one updates.

Digital identity in the enterprise is no longer a topic reserved for the IT department. With the arrival of the EUDI Wallet, the proliferation of non-human identities, and the shift to passkeys, every business unit is concerned. The starting point remains the same: knowing precisely who accesses what, and ensuring that this answer is up to date.

How to Optimize Digital Identity Management for Your Business in 2024