On guard. On premises. In control.

Identity governance for mission-critical environments

Defense organizations protect information and systems critical to national security that cannot fall into the wrong hands. Therefore, knowing exactly who (and what) has access to critical systems is a non-negotiable operational necessity. But identity governance across air-gapped, highly regulated environments with the strictest security requirements can feel like mission impossible. MidPoint provides a flexible, open source identity governance and administration (IGA) platform deployable entirely within infrastructure you own – giving defense organizations complete control over their identity landscape and where their data resides.

  • Protect sensitive data with granular access control, least-privilege enforcement, and a full audit trail for every access decision.

  • Deploy entirely on-premises, in a private cloud, or fully air-gapped – with no dependency on external connectivity.

  • Connect existing systems like directories and legacy applications into a unified governance framework without replacing your existing infrastructure.

  • Prevent identity sprawl by gaining a complete overview of all human and non-human identities, so excessive or orphaned access gets found before it becomes a vulnerability.

Stay compliant, stay secure

Make identity part of your security perimeter

An identity with excessive access can expose paths to critical systems containing highly confidential information, creating severe security liabilities and compliance headaches. Enforce granular access controls, least privilege, and segregation of duties through policy-based governance. Access is granted through roles and approval workflows, and reviewed on a recurring certification cycle, so people and systems hold only what their responsibilities require. Every access decision and change is logged, giving security teams the audit trail to investigate each activity and the evidence to meet regulatory requirements.

Built for offline environments

Connect every system without disruption

In many defense environments, isolation isn’t a limitation to work around, but the security measure itself. MidPoint is open source and deployable entirely within infrastructure you choose, whether on premises, in a private cloud, or fully air-gapped, with no external connection required for core identity governance. The source is yours to audit, and the infrastructure is yours to control. Your identity data stay securely inside whatever boundary you define, supporting digital sovereignty.

Connect what you already have

Modernize identity governance without replacing your infrastructure

Modernizing identity governance doesn’t mean an infrastructure replacement project. New platforms need to work alongside the directories, legacy systems, and specialized applications that remain mission-critical. MidPoint connects these systems into one governance framework – correlating and synchronizing identity data, and managing provisioning, deprovisioning, roles, and policy consistently across every connected system, however old or specialized.

Take control of identity sprawl

Know every identity and what it can do

Identity in a defense organization extends well beyond employees. Contractors, partners, service accounts, applications, and other machine identities can all hold access to sensitive resources. Gain a consolidated view of every identity, account, role, and entitlement across connected systems, so excessive, conflicting, orphaned, or otherwise unnecessary access can be found and resolved before it becomes a vulnerability. Automated lifecycle processes then keep access aligned with changing responsibilities: provisioning new access when needed and removing it when someone changes roles or leaves, therefore reducing the risk of forgotten accounts and permissions that outlive their purpose.

Trusted identity security

Why defense organizations choose midPoint

Zero trust

Apply zero trust principles with continuous identity governance, least-privilege access, strong policy enforcement, and regular access reviews.

Continuous compliance

Leverage certifications, segregation of duties controls, and full audit trails that run continuously, so you’re ready for audits at any point, without much preparation.

Automated identity lifecycle

From onboarding to offboarding, every provisioning, role change, access request, and deprovisioning event is handled automatically, resulting in increased efficiency.

Flexible integration

Connect HR systems, directories, legacy applications, operational technology environments, and cloud services using open source connectors.

Test changes before production

Preview the impact with simulations before anything goes live. See exactly which identities would be affected, catch conflicts before they reach production, and switch to live execution only when you’re confident the outcome is correct.

Flexible deployment

Deploy on premises, in a private cloud, or in hybrid environments to meet operational and security requirements.

Freedom of open source

Align your identity security with the NIS2 directive’s recognition of open source as a strong driver of transparency, interoperability, and resilience. Benefit from the flexibility, community, and innovation only open source can deliver, backed by full professional support.

No license fees

Save on costs by eliminating expensive licensing fees and avoiding vendor lock-in. With midPoint’s open source model, you only pay for a subscription – achieving a far better cost-to-value ratio.

Stay ahead

Unlock the full potential of midPoint with Product Support

Get the most out of your investment into identity security with an active Product Support subscription, which is an essential part of maintaining stability and peak performance across your critical identity infrastructure.

Rely on proven functional integrity

Stay secure and supported by engaging Evolveum to handle product bugs and failures and provide fixes in regular maintenance releases or temporary workarounds.

Ditch license fees and invest only in a subscription

Cover all identities, including employees, suppliers, temporary accounts, and machine identities, under one predictable plan – no license fees, no hidden costs.

Level up your skills with structured training

Get free access to certain self-paced training with your active subscription – and gain even more free self-paced courses the longer you stay subscribed. What’s more, benefit from a steep discount for Evolveum’s guided online training.

Report documentation issues for priority fixes

Report bugs in documentation and let Evolveum prioritize fixes – delivering clearer, more accurate guidance where it matters most.

Get the most out of Connector Services

Rely on Evolveum to resolve bugs in the AD, CSV, DBTable, and LDAP connectors included in the subscription. Extend Connector Services to support or improve existing connectors or request the development of new connectors for a fee, helping you keep your integrations reliable, efficient, and up to date.

Upgrade to a Platform Subscription

Take your subscription further with the Platform Subscription to sponsor new feature development, directly influence the midPoint roadmap, and request product documentation improvements to meet your specific needs.

Drive Identity Innovation

Resources to guide your journey

Discover a selection of resources tailored to the needs of the defense organizations .

Regulatory compliance with midPoint

Watch our videos to understand how midPoint supports regulatory compliance at scale.

Case studies and other materials

Visit our Resource Library for insights, case studies, and materials that illustrate midPoint’s impact on solving identity management challenges.

Learn why open source is the way

Find out more about the benefits midPoint can bring when compared to typical closed source identity management and governance software.

make the most of midPoint

Get started

Discover how midPoint helps defense organizations protect sensitive data, enforce least-privilege access, govern human and non-human identities, and secure existing infrastructure – even in fully air-gapped environments.

Contact us