Blog
AI and Fortified ID IAM: Robot-Enhanced Security for Your Organization
6/17/2026
With artificial intelligence (AI), organizations can make well-informed decisions based on the analysis of vast amounts of data, without human intervention. These decisions can also be automatically improved through machine learning. In this article, I present an example of how AI combined with Identity and Access Management (IAM) can add value in the field of cybersecurity.Background on IAM and Its Role in OrganizationsIdentity and Access Management (IAM) is a crucial aspect of cybersecurity th
BankID for access to company resources
6/17/2026
ChallengeThe company needs to give its employees and consultants access to the organization's systems and digital resources (e.g. Windows computer, Windows server, files, websites) so that they can perform their work even if they work from home or in another location outside the office. A person who works from home or outside the office today authenticates with a username and password to access the digital resources. The systems and digital resources are exposed via the Citrix Workspace software
BankID, SITHS and Freja eID for conditional access to resources in Azure
6/17/2026
ChallengeThe organization needs to protect sensitive resources (applications, files, documents) from unauthorized access. The sensitive resources are stored in Azure. Authorized users are stored in Entra ID (formerly Azure AD). For security reasons (to avoid that hackers can crack passwords and access the sensitive resources), the organization protects access based on conditional access policies, so-called Conditional Access policies. These policies require that the user be identified via multi-
BankID, SITHS and Freja eID for conditional access to resources in Azure
6/17/2026
ChallengeThe organization needs to protect sensitive resources (applications, files, documents) from unauthorized access. The sensitive resources are stored in Azure. Authorized users are stored in Entra ID (formerly Azure AD). For security reasons (to avoid that hackers can crack passwords and access the sensitive resources), the organization protects access based on conditional access policies, so-called Conditional Access policies. These policies require that the user be identified via multi-
Customer IAM (CIAM) for the public sector - self-registration, authorization management and enhanced authentication
6/17/2026
ChallengeA public organization (authority) needs to give external users access to some of the organization's systems and digital resources. The external users must be able to access and register certain information at regular intervals. The organization wants the user to be able to request access himself via a self-service process. An authorized person at the organization must then approve the request and grant authorization to the relevant systems. For security reasons, the organization require
Verified Identity for Issuing Diplomas to Digital Wallets
6/17/2026
ChallengeAlumni (former students) of a university should be able to receive a digital diploma. This diploma can be used for various purposes, such as: • Job applications • Availing discounts on further education and study materials • Free subscription to the university's magazine • Entry to alumni dinnersThe digital diploma should be stored in a digital wallet controlled by the student. The university will issue these digital diplomas, and users must verify their identity using a DIGG-approved e
EU Digital Identity Wallet: What Does It Mean for the Swedish Public Sector?
6/17/2026
With the latest update of the EU regulation on electronic identification and trusted services (eIDAS), the EU Digital Identity Wallet (EUDI) is introduced. This identity wallet aims to scale up the use of digital identities within and between member states while giving users greater control over the data shared with various services.Infrastructure and TechnologyThe EU Digital Identity Wallet is based on decentralized identity and Verifiable Credentials. The system consists of three parties:Issue
Flexible and secure login to SAP
6/17/2026
By integrating SAP with Fortified ID Integrity as a central login service, the organization can create a cohesive and secure identity architecture. Fortified ID acts as an external IdP that connects existing directory services with SAP's cloud services via standardized protocols such as SAML, OIDC, ADFS, etc.
Fortified ID Integrity, an IdP ready for level of trust 4
6/17/2026
ChallengeFor services with very high security requirements, the level of trust that must be applied for secure authentication with a high level of trust in the identity is defined. To respond to trust level 4, the entire chain from identity, authentication method, underlying infrastructure and Identity Provider (IdP) must meet stringent requirements for implementation and functionality. The Swedish trust level 4 (LOA 4) corresponds to the eIDAS level High. For Sweden, DIGG has added another requ
Fortified ID is ready for the future – Post-Quantum Cryptography (PQC) with modern architecture
6/17/2026
With the advancement of quantum computers, traditional cryptographic algorithms face a new challenge.
How to Create Added Value with Future Identity and Access Management?
6/17/2026
The importance of Identity and Access Management (IAM) has rapidly evolved in recent years and is continually developing. Initially, IAM was primarily a support for network functions (e.g., multi-factor authentication for VPN/firewalls). However, it has now become a central function in organizations. The vast number of applications, systems, computers, phones, cloud services, and on-premises services, combined with the need to ensure that the right users have access to the right information at t
Log in to Azure B2C with Swedish eID
6/17/2026
ChallengeA Swedish organization in the public sector uses Azure B2C to expose the applications aimed at citizens. The organization wants to offer citizens to use a selection of e-identifications to ensure that all citizens can log in and at the same time maintain a high level of security. The organization wishes to expose the private e-identifications approved by DIGG at trust level 2-4.SolutionWith Fortified ID Integrity, different e-identifications can be used as an authentication method again
Log in to Google Workspace with Freja OrgID, BankID, SITHS, or EFOS
6/17/2026
UtmaningA Swedish organization needs to provide its employees and consultants access to Google Workspace for email and file sharing. The organization also uses Google as the primary system for storing user identities.The users within the organization include: • Healthcare professionals • Case officers • Administrators • External consultantsTo prevent hacker attacks and protect digital information and identities in Google, the organization wants to use a more secure authentication method than pas
Log in to ServiceNow with Siths, EFOS, Freja or BankID
6/17/2026
ChallengeA Swedish municipality needs to give its employees and consultants access to the municipality's system for digital workflows, ServiceNow. The municipality's users consist of various professions, including: • Nursing staff • Case manager • Administrators • External consultants To minimize administration, the municipality wishes to use existing user accounts in the municipality's user directory, Active Directory, for authentication. For security reasons, to avoid hackers being able to c
Login for civilians using methods from social services, such as Google, Microsoft, LinkedIn and Facebook.
6/17/2026
ChallengeA Swedish organization in the private sector, e-commerce, wants to simplify the process of login and new registration in order to attract more new customers with flexibility. The organization wants to offer individuals to use a selection of social media for login and registration, so that the individual does not have to register manually and obtain another password.SolutionWith Fortified ID Integrity, accounts with a number of social services can be used as an authentication method agai
On-premise MFA for the university ADFS connection to SWAMID
6/17/2026
ChallengeA university uses Microsoft Active Directory Federation Services (ADFS) as a federation service. ADFS at the university is affiliated to SWAMID, a federation for universities and colleges. SUNET (Swedish University Computer Network) is responsible for the federation's regulations. Today, employees and students authenticate with username and password, alternatively Windows Single Sign-On to ADFS. Some services within SWAMID require logging in at a higher trust level, which requires an ad
Password Reset in Google with Swedish e-ID for Students and School Staff
6/17/2026
ChallengeA Swedish school uses Google for Education to manage accounts, allowing both students and school staff to log into their Chromebooks and access the necessary systems and services. Users need to enter their password stored in their Google account to log in. After holidays or at the start of a new term, it is common for users to forget their current password.The school wants school staff to be able to reset their passwords completely independently, without the involvement of a service des
Privacy first service credentials for employees, partners and consultants
6/17/2026
Med IDombud från Fortified ID kan organisationen utfärda en egen tjänstelegitimation som är kopplad till roll eller funktion i stället för att utgå från privatpersonens identitet i varje steg.
Remote access to university internal network with enhanced login
6/17/2026
ChallengeA university needs to give its employees and students access to the university's internal network, so that they can carry out their work even if they work from home or in another place outside the university. Today, employees and students authenticate themselves with usernames and passwords to access the university's internal network. For security reasons, to avoid hackers being able to crack passwords and access the organization's digital information, the organization wants to use a mo
Reset password with Norwegian e-ID
6/17/2026
ChallengeA Norwegian authority uses Microsoft Active Directory (AD) to manage accounts, so that the user (the user) can log in to their computers and grant permissions to the systems and services the user must have access to. To log in to their computer, the user needs to enter their password, which is stored on the account in AD. After holidays and vacations, it is common for the user to forget the current password. The authority wants the user to be able to reset their password all by themselv
Reset passwords with e-Legitimation, for employees at Swedish municipalities
6/17/2026
ChallengeA Swedish municipality uses Microsoft Active Directory (AD) to manage accounts, so that employees can log on to their computers and obtain the permissions required for the systems and services the user must have access to. To log in to their computer, the user needs to enter their password, which is stored on the account in AD. It is common for the user to forget the current password after, for example, time off and holidays. The municipality wants the user to be able to reset their pas
Safe way back when users lose access to their Entra account
6/17/2026
Help users back into their Microsoft Entra account with a guided self-service flow, less manual management, and better control over temporary access.
SCIM - System for Cross-domain Identity Management
6/17/2026
How can FortifiedID address SCIM-related challenges? FortifiedID provides an identity platform with advanced features for managing user identities and permissions.
Simple and flexible management of customer identities (CIAM)
6/17/2026
ChallengeA company, with both private and business customers, publishes a number of applications to give them an overview of subscriptions and invoices, as well as give customers the opportunity to buy more services from the company.In order to be able to log into the application easily, but at the same time securely, the company wishes to have a central authentication solution, regardless of customer type. The authentication solution must deliver:For private customers: • Login for private perso
SITHS eID for Active Directory Federation Services (ADFS)
6/17/2026
ChallengeThe Swedish healthcare system has high demands for security in order to access a patient's information, such as a journal. The requirements are designed based on the law that exists to protect a patient's personal data, PDL (Patient Data Act). To protect digital access to systems that process patient data, authentication with SITHS is required. SITHS functions as a service credential where a user is tied to an organization, almost all employees in Sweden's regions and many employees in
Teachers and school staff - login to digital nationwide exams with approved e-identification
6/17/2026
ChallengeMany municipalities and independent schools, so-called school principals, are today connected to the School Federation for flexible authentication against the various applications and services that both teachers, students and other school staff need to use for their daily activities. The integration with Skolfederation requires the principal to have software for authentication, a so-called Identity Provider, IdP. There are many different providers of an IdP on the market, for example Mi
Teachers Updating Student Information in Google via Delegated Administration
6/17/2026
ChallengeAt the start of each term, a school with many students faces a hectic period of registering and updating student information in the school’s systems. The school uses Google Workspace for Education as its primary database for student identities and accounts.The IT department cannot keep up with updating all student information, necessitating a simple, delegated process where class teachers can update specific student details. In this case, the class teacher should be able to add the stud