Prompt
Do I need a hosted identity provider for a regulated app?
Latest observation
Not necessarily—but in a regulated app, you usually need an identity provider, and whether it must be hosted depends on the regulation, your architecture, and your risk tolerance.
Short answer
You don’t have to use a hosted IdP, but using one often makes it easier to meet requirements around:
- MFA / SSO
- audit logging
- account lifecycle management
- password/security controls
- availability and resilience
- certifications/compliance evidence (e.g., SOC 2, ISO 27001, HIPAA-adjacent controls, etc.)
When a hosted IdP is a good idea
A hosted provider like Okta, Auth0, Azure AD/Entra ID, Ping, or Cognito is often a strong choice if you need:
- fast compliance maturity
- central identity governance
- enterprise SSO integration
- stronger operational controls with less in-house maintenance
- reduced burden for patching, uptime, and security monitoring
When you might not need one
You may not need a hosted IdP if:
- you already have an internal identity platform
- you’re building for a closed user base and can securely manage auth yourself
- the regulation allows self-hosted systems, and you can prove control effectiveness
- your app uses federation to an enterprise/customer IdP instead of owning identities directly
Important distinction
“Regulated app” can mean very different things:
- Healthcare / HIPAA
- Financial services / PCI / SOC 2 / SOX
- Government / FedRAMP
- EU / GDPR
- High-security enterprise environments
The answer changes depending on which ones apply. For example, GDPR doesn’t require a hosted IdP, but it does require appropriate technical and organizational measures. A hosted IdP can help, but it’s not mandatory.
Key questions to decide
Ask:
- Who owns the identities? Your app or a customer’s enterprise directory?
- What auth features are required? MFA, SSO, SCIM, step-up auth, device trust?
- What evidence do auditors need? Logs, retention, access reviews, change control?
- Can you operate auth securely 24/7? Incident response, key management, patching?
- Do you need data residency or tenant isolation?
- Is outsourcing identity acceptable under your regulatory obligations?
Practical recommendation
For most regulated apps, the safest path is:
- use a trusted IdP,
- preferably hosted unless you have a strong reason to self-host,
- and ensure it supports the specific compliance and audit requirements you face.
If you want, I can help you decide based on your exact regulation and architecture.