IAM: On-Premises or SaaS? A Comparison of Operating Models

A Comparison for IT Decision-Makers

Last week, I met with the IT director of a medium-sized city government. 4,500 employees, 120 specialized systems, a five-person IT team. He said something we hear time and again in projects: “We know we need an IAM. We just don’t know if we can afford it.” He wasn’t referring to the money. He was referring to the people needed to keep such a system running.

This article is the first in a multi-part series for anyone facing exactly this decision.

1. Two Worlds: A Direct Comparison of On-Premises vs. SaaS

Imagine you’re building a house. With an on-premises solution, you buy the lot, plan the construction, hire contractors, and then handle every repair yourself—from a leaky faucet to a new roof. With SaaS, you move into a professionally managed building: you can use everything right away, the property management company handles maintenance and upgrades, and you focus on your core business. Yes, you aren’t building equity, but you also aren’t tying up capital or an entire team in building systems.

On-Premises: Full Control, Full Effort

Organizations that run IAM on their own infrastructure retain maximum control over data, configuration, and architecture. For certain scenarios, this is the right approach: for example, in highly regulated industries such as the financial sector, which must operate completely isolated from the Internet.

The downside is often glossed over in decision-making documents. Hardware, licenses, network, and data center capacities must be procured and financed before even the first identity can be created. Every release update and every security patch is the organization’s own responsibility. And then there are the connectors: interfaces to HR systems, directory services, cloud platforms, and line-of-business applications must be developed, tested, and maintained in-house. The complexity grows with every integration, and with it, the risk that something will be overlooked.

SaaS: Get Started Faster, Reduce the Burden Long-Term

An IAM solution delivered as Software as a Service shifts the operational burden to the provider. The organization uses a professionally managed platform and focuses on the business aspects: What roles do we need? What approval processes apply? Which systems need to be integrated?

At first glance, the math is simple: no upfront investment in infrastructure, predictable monthly costs, automatic updates from the provider, and scalability without the need to purchase hardware. Monitoring, backup, and disaster recovery are included in the service. Professional security management in accordance with ISO/IEC 27001 is part of the service offering.

That sounds straightforward, but it’s not quite that simple. Relying on a single provider requires trust and contractual safeguards. Ongoing subscription costs add up over the years. Not every SaaS provider allows for deep, customer-specific customization. A stable internet connection is a prerequisite, and the issue of data location must be clarified, especially for regulated industries.

When it comes to IAM in particular, a good SaaS provider not only handles the operation of the platform but also maintains the connectors, implements release updates, and adapts to new interface versions of the target systems. In our projects, we see time and again that it is precisely these tasks that tie up the most personnel resources when managed in-house—not the major architectural decisions, but the ongoing day-to-day maintenance.

Digital Sovereignty at IAM Factory

2. What On-Premises Operations Really Require

In theory, any organization can operate an IAM system on its own. In practice, however, this fails surprisingly often—not because of a lack of will, but because of a lack of the necessary prerequisites. Operating the system in-house requires a number of success factors that simply aren’t present in many organizations.

The staffing problem: Specialists who are hard to find

IAM is not a side job. Its operation requires specialists who are well-versed in identity modeling, connector development, role management, workflow design, privileged access management, and compliance requirements. These are not generic IT administrators. These are specialists with a rare skill set at the intersection of IT security, directory services, HR processes, and application integration.

The job market simply can’t keep up. According to a 2025 Bitkom study, the German IT job market has approximately 109,000 unfilled IT positions. Although this represents a cyclical decline from the 149,000 recorded in 2023, 79 percent of companies expect the shortage to worsen further. In the field of cybersecurity, according to a PwC Strategy& study (2025), nine out of ten organizations report massive recruitment problems, and in the public sector, according to the dbb Monitor 2026, there is a shortage of around 600,000 employees needed to perform tasks efficiently.

Even if suitable candidates were available, organizations in the public sector, healthcare, and higher education—which operate under rigid pay scales (TVöD, TV-L, AVR)—are competing against the private sector. An experienced IAM specialist earns significantly more than the E12 upper limit in those sectors. You know the result: positions remain unfilled for months or years, existing staff are overburdened, and the IAM project makes no progress.

How SaaS Is Changing Things Here

The provider supplies the IAM expertise. The internal IT department defines the business processes but does not operate the technical platform. Instead of three to five dedicated IAM specialists, one or two business contacts are sufficient, and the issue of compensation shifts to the service provider, who can recruit on the open market and deploy specialists across multiple clients.

When five people have to handle everything

In many medium-sized hospitals, city governments, or universities, the entire IT department consists of just a handful of employees. These teams are already struggling to maintain the day-to-day operations of the network, workstations, servers, and line-of-business applications. If the IT department doesn’t even have the capacity to handle printer support, who is supposed to operate an IAM system with dozens of connectors?

With SaaS, the provider handles the day-to-day IAM operations: monitoring, patching, backups, connector maintenance, and release updates. This takes the burden off the internal team, allowing it to focus on business-specific management—tasks that can only be performed internally.

The Identity Lifecycle: Where Most Errors Occur

An often-overlooked aspect: When an employee leaves the organization or changes roles, their access rights must be promptly and correctly adjusted or revoked across dozens of systems—from email accounts and VPN access to industry-specific business processes. When managed in-house, this requires manual coordination between HR, IT operations, and line departments. Errors lead to so-called “orphan accounts”: abandoned accounts that continue to grant access and pose a permanent security risk.

Added to this is the challenge of identity correlation. If the same person exists in multiple systems (HR system, Active Directory, cloud directory, SAP), the platform must reliably recognize that they are one and the same person. Otherwise, duplicates or conflicting permissions will result.

Do you know how many orphaned accounts exist in your system?

A professional SaaS platform automates the entire identity lifecycle end-to-end. Proven correlation rules prevent duplicates, and automated deactivation processes bridge the gap between HR notifications and the actual revocation of access rights. When managed in-house, this is often done using spreadsheets and email—a process that is error-prone, time-consuming, and hardly audit-proof.

What happens if the IAM expert resigns?

We know of an organization where a single employee built and maintained the entire IAM system for seven years. When he left, it took the team four months just to understand the documentation. It took nine months to find a replacement. In the meantime, no new connectors were integrated, no interfaces were updated, and no security patches were applied.

This is not an isolated case. An IAM system is not a one-time project. It evolves, grows, and changes over the years. If you operate it yourself, you’ll need succession planning, documentation, and knowledge transfer. With a SaaS provider, operational continuity is institutionally embedded: with teams rather than individuals, defined processes, and contractually guaranteed service levels.

Compliance: The regulatory landscape isn’t getting any easier

NIS2, BSI IT-Grundschutz, GDPR, industry-specific requirements such as the Patient Data Protection Act, or the OZG 2.0 requirements for digital administrative services, including open standards. An in-house IAM system must independently implement, document, and demonstrate compliance with all of these requirements during audits.

Regular access certifications are particularly time-consuming: At least once a year, managers must review and confirm all of their employees’ access rights. Similarly, the segregation of duties must be monitored automatically to ensure that no one is assigned roles that involve conflicts of interest—such as combining invoice verification and payment approval in a single position.

How SaaS Is Changing Things Here

A professional SaaS provider holds the necessary certifications (ISO 27001, ISO 27017, ISO 27018) and integrates compliance requirements into its standard processes. Certification campaigns are orchestrated automatically, SoD conflicts are detected in real time, and complete audit trails provide the evidence in the format that auditors expect.

Digital Sovereignty at IAM Factory

3. Getting Results Faster: The MVP Approach

Many IAM projects fail not because of technical issues, but because of their duration. A typical large-scale IAM project begins with a months-long requirements analysis, followed by software selection, infrastructure setup, implementation, testing, and go-live. It takes 18 to 24 months—and sometimes significantly longer—to go from the initial idea to live operation. During this time, budgets grow, stakeholders’ patience wanes, and requirements shift.

The key lies in the opposite approach: a Minimum Viable Product (MVP) that quickly brings the most important IAM functions online and is then expanded in stages.

What does this look like in practice? A preconfigured SaaS platform provides an industry-proven framework: user types for typical roles (employees, external users, trainees, students), predefined Joiner-Mover-Leaver processes, a proven role model based on systematic role mining, standard connectors for Active Directory, LDAP, Microsoft Entra ID, SAP HCM, or HR systems, self-service functions for password resets and access requests, as well as basic compliance features such as audit logging, access certification, and segregation of duties.

Experience has shown that this preconfiguration covers the vast majority of requirements. Instead of starting from scratch, the implementation builds on a foundation that has been refined through real-world projects. Customization is limited to what is truly unique to each client: the specific organizational structure, the specific business processes, and the internal approval rules.

Proof of Concept (PoC) Instead of a Large-Scale Project

The lowest-risk way to get started is through a structured proof of concept. Within a few weeks, a real environment identical to the production environment is set up, rather than a sales-oriented demo. An HR system is connected as the source, a directory service is configured as the destination, and automated provisioning begins. The organization can verify for itself whether the solution delivers what it promises before entering into a long-term contract.

This approach reduces three key risks simultaneously: financial risk through manageable initial costs, technical risk through validation within the organization’s own system environment, and organizational risk through rapid, visible results that win over stakeholders.

4. Why now, and why specifically for these industries?

Three sectors are under particular pressure to professionalize their identity management.

Under NIS2 and KRITIS requirements, healthcare organizations are legally required to demonstrably raise their IT security to a professional level. Centralized IAM is not an optional add-on in this context, but a mandatory requirement.

Higher education institutions manage a unique level of complexity: thousands of students, rotating faculty members, and a heterogeneous IT landscape comprising campus management, directory services, and federated authentication (Shibboleth, DFN-AAI). Added to this is the requirement that faculty and researchers be able to access resources at other institutions using their home institution’s credentials.

Under the OZG 2.0, local governments must provide digital citizen services and, to that end, establish a secure, legally compliant identity management system for thousands of employees, external contractors, and elected officials.

All three sectors have one thing in common: IT teams are small, salary ranges are capped by collective bargaining agreements, and the workload is high. If you’re thinking, “That doesn’t apply to us,” take a moment to consider how many of your IT employees will be retiring in the next five years. It is precisely in this scenario that IAM as a managed service delivers the greatest value.

The question is no longer whether an organization needs a professional IAM solution, as regulatory requirements and the threat landscape leave no room for doubt. The question is what the path to achieving this looks like and whether an organization has to go it alone.

This article is the first of four parts. The next ones will explore the topic further—including topics such as a cruise ship and a lunar mission. After all, how collaboration works during day-to-day operations and why IAM projects require a different planning approach than traditional IT projects each deserve their own closer look.

Would you like to find out what an IAM rollout might look like in your organization? Schedule a free consultation using the contact form —30 minutes, no slide-heavy presentation, just a concrete assessment of your situation.

Demo Request

Experience IAM Factory in Action

During a one-on-one presentation, we’ll show you
how our modular Software as a Service solution works in practice.

Experience modern identity and access management in action and get answers to your questions.

Loading...