MSSP IAM — MANAGED IDENTITY SERVICES

Entrusting identity security to a specialised partner

Identity and access are a pillar of your security posture. Running them requires a stable, available, trained team, engaged on outcomes — not only on hours.

The Ariovis managed service (MSSP IAM) goes beyond IAM operations: Ariovis takes operational responsibility for all or part of your IAM, IGA, Access Management, CIAM and PAM platforms, with formal service commitments and dedicated governance.

Consulting, IAM operations and MSSP IAM: three different postures

Understanding the difference between staff augmentation, IAM operations and a managed service helps pick the right model for the right maturity step.

Staff augmentation

  • Skills made available
  • Steering owned by client
  • Effort-based commitment
  • Useful during projects or ad-hoc reinforcement

IAM Operations (L2/L3)

  • Ariovis owns support
  • Incident SLAs (response, restoration)
  • Continuous improvement
  • Client remains platform owner

IAM Managed Services

  • Ariovis owns operational responsibility
  • Outcome-based commitments
  • Dedicated governance
  • Monitoring, reporting, security, platform lifecycle

These three models are complementary and often succeed one another. Managed IAM services are contracted with clear scope, commitments and reversibility.

Two engagement models

Full managed service

Ariovis operates the platform, owns service commitments, operational security, monitoring, patching, recurring evolutions and continuous improvement. The client retains strategy, compliance and structuring decisions.

Partial managed service

Ariovis operates a defined scope — for instance the IGA layer, Access, PAM, CIAM or the monitoring tier. The rest of the setup remains driven by the client’s internal teams.

Exact scope, included components, shared responsibilities and thresholds are formalised in a service assurance plan. These models are illustrative.

What an Ariovis MSSP IAM covers

A managed IAM service is not just ‘keeping the service running’. It combines operations, operational security, governance and continuous improvement.

Operations

  • Functional and technical support
  • Incident handling
  • Corrective and evolutive maintenance
  • Flow and connector monitoring

Operational security

  • Vendor vulnerability tracking
  • Critical patch application
  • Technical access review
  • Secret rotation (if in scope)

Platform lifecycle

  • Version upgrades
  • New requirements handling
  • Application onboarding
  • Decommissioning of legacy components

Service governance

  • Recurring committees
  • Service reporting
  • Risk tracking
  • Capacity review

Continuous improvement

  • Structured backlog
  • Automations
  • Runbooks
  • Lessons learned

Contractual framework

  • Formal scope
  • SLAs
  • Reversibility
  • Confidentiality
  • Security

Service commitments: example MSSP IAM framework

In MSSP mode, commitments cover incidents but also availability, restoration and eradication. The matrix below illustrates values already proposed.

Depending on the contract, Ariovis can commit to acknowledgement (response), restoration (restoration time) and an eradication path. Values are contracted per criticality and scope.

These values illustrate a framework already proposed. Final commitments depend on service hours, scope, access availability and shared responsibilities.
Service commitments: example MSSP IAM framework
PriorityGTIGTREradicationPost-mortem
P1
Critical incident
2 hours8 hours10 business days3 business days after restoration
P2
Major incident
4 hours24 hours20 business daysOn request
Response time
Maximum time for Ariovis to effectively intervene beyond automatic ticket acknowledgement.
Restoration time
Maximum time to restore an acceptable state — through fix, workaround or vendor escalation.
Eradication
Indicative contractual timeframe to durably remove the incident’s cause after restoration.
Post-mortem
Structured analysis delivered after a major (P1) incident, within a maximum of 3 business days after restoration.

Typical post-mortem content

  • Origin and timeline
  • Operational impact
  • Workaround applied
  • Validated corrective action
  • Non-recurrence measures
  • Problem record when relevant
  • SLA compliance follow-up

Service availability and staffed coverage

Ariovis portal 24/7

The Ariovis support platform remains accessible 24/7 to raise and follow requests, independently from staffed coverage.

Standard managed coverage

Ariovis has already proposed a 9 a.m.–6 p.m. dedicated team model. Different coverage can be defined contractually.

Extended coverage and monitoring

On-call, smarthands, 24/7 monitoring and crisis cells are contracted based on criticality, geography and stakes.

In MSSP IAM mode, staffed coverage is a major contractual variable. It is calibrated to the accepted risk level, not standardised.

A clear responsibility chain

In managed services, the responsibility chain must be even clearer than in operations alone: the client must know who decides, who executes and who reports, at each step.

Service management

  • Ariovis service manager
  • Service committee
  • Commitment tracking
  • Managerial escalation

L1/L2 support

  • Single entry point
  • Qualification
  • Restoration
  • Runbooks

L3 / build expertise

  • Advanced analysis
  • Complex fixes
  • Pre-production
  • Go-live

Vendor

  • Vendor ticket opening and tracking
  • Escalation management
  • Consolidated communication
In MSSP mode, Ariovis is the single point of contact for operations. The client does not orchestrate several suppliers to keep the platform alive day to day.

Ariovis’ operational responsibility in MSSP IAM does not replace vendor, hosting or client-retained responsibilities, which are explicitly defined in the contract.

Monitoring, detection and reporting

A managed IAM service without real monitoring is not one. Ariovis sets up functional and technical monitoring tailored to IAM components.

  • IAM component availability
  • Job and batch success
  • Connector errors
  • Queue depth
  • Abnormally long jobs
  • Unusual volumes
  • Orphan accounts
  • Reconciliation gaps
  • Recertification campaigns
  • Certificate and secret expiry (in scope)
  • Vendor vulnerability watch
  • Automatic alerts to the support platform
Depending on scope, monitoring alerts automatically feed the Ariovis support platform so anomalies are qualified before end users report them.

Managed service KPIs

Availability & incidents

  • Application availability
  • Number of incidents
  • Response / restoration compliance
  • P1 and P2 counts
  • Reopenings
  • Post-mortems delivered

IAM platform

  • Sync success
  • Provisioning / de-provisioning
  • Errors per connector
  • Reconciliation gaps
  • Orphan accounts
  • Data quality

Operational security

  • Critical vulnerabilities handled
  • Applied patches
  • Application delay
  • Technical access reviews

Value

  • Use cases added
  • Applications onboarded
  • Automations delivered
  • Recommendations implemented

The grid is calibrated per platform and per contract. No historical performance data is presented here.

A managed service without proactivity is just a call centre

MSSP IAM commits Ariovis to reduce incident surface and improve the platform, not only to answer tickets.

  • Recurring incident analysis
  • Systematic root cause investigation
  • Removal of manual operations
  • Fragile connector review
  • Job optimisation
  • Version preparation
  • Vulnerability analysis
  • Architecture recommendations
  • Backlog review
  • Progressive application onboarding
  • Data cleanup
  • Control automation
  • Continuous documentation improvement
  • Coaching of internal administrators
A serious MSSP IAM is judged by the reduction of operational noise, not only by ticket-acknowledgement SLAs.
Restoration after a major incident must be followed by an eradication action and a non-recurrence check.

Dedicated managed service governance

A serious managed service has its own governance, distinct from project steering. Depending on the contract, Ariovis mobilises several committees and roles.

Steering

  • Ariovis service manager
  • Client focal point
  • Service committee
  • Strategic committee (per contract)

Security

  • Vulnerability tracking
  • Technical access review
  • Security incident handling
  • Client CISO interface

Operations

  • Support manager
  • Operations team
  • On-call (per contract)
  • Monitoring

Improvement

  • Backlog committee
  • Platform roadmap
  • Automation
  • Lessons learned
Indicative service committee: monthly or quarterly, with Ariovis service manager, client focal point and relevant stakeholders. Agenda: SLAs, incidents, security, changes, versions, risks, capacity, recommendations, backlog, satisfaction.

Committee frequency is tuned to service criticality and contractual scope. Cadence above is illustrative.

Entry transition and reversibility

A serious managed service is judged as much on how it starts as on how it can end. Entry transition and reversibility are contracted, not left informal.

  • Initial state audit
  • Access inventory
  • Documentation review
  • Flow mapping
  • Risk identification
  • Documented transition plan
  • Hypercare phase
  • Formal handover
  • Operations documentation
  • Continuity procedures
  • Client-side reversibility plan
  • Skills transfer at end of contract

Technologies operated under managed services

IGA / IAG

  • Netwrix Identity Manager
  • Existing environments on SailPoint, One Identity, Saviynt or equivalents (taken over case by case)

Access Management

  • Ping Identity
  • Entra ID
  • Keycloak
  • Axiomatics (authorisation)

PAM & secrets

  • Netwrix Privilege Secure
  • Keeper
  • Existing CyberArk environments (taken over case by case)

Additional scope

  • SCIM, LDAP, JDBC, API connectors
  • SAML / OIDC federation
  • Monitoring and logging
  • SIEM / SOC interfaces

Ariovis remains vendor-agnostic. Managed services can operate an existing environment without changing tools. No third-party logo is listed as an official partner without contractual validation.

Anonymized references

Examples of managed IAM engagements representative of our practice.

Public sector

Long-term IGA outsourcing

Long-term operation of an IGA platform including support, maintenance and evolutions, with dedicated governance.

Software & HR services

Stabilise then manage

Takeover of a service under pressure: hypercare, stabilisation, then transition to managed services with formal commitments.

International organisation

MSSP around Entra ID and Keycloak

Managed service combining Access Management, legacy component decommissioning and identity ecosystem steering.

Transport & construction

PAM managed service

Continuous handling of a PAM programme: application onboarding, access review, continuous improvement, vendor escalation.

Anonymized references. No client is named without written authorization.

A managed service delivered by several locations

Ariovis MSSP IAM relies on four locations with complementary roles. Day-to-day managed service delivery is particularly carried by the Brussels team.

Paris

Service management, governance and client relationship.

Châtillon — Hauts-de-Seine

Consulting, technical expertise and complex escalations.

Bordeaux — Nouvelle-Aquitaine

Technical and consulting expertise, evolutions.

Brussels

Team particularly focused on managed services and operations for Benelux, Switzerland and Germany.

A single contract can mobilise several sites — for instance Paris for governance, Bordeaux for expertise and Brussels for managed operations.

Going further

IAM managed services extend our integrator craft and our IAM operations offering: once the platform is ready, Ariovis can carry operational responsibility. See our integrator approach, our IAM operations offering and our locations map for a complete view.

Frequently asked questions about IAM managed services

What is an MSSP IAM?

An MSSP IAM is a provider that takes contractual, operational responsibility for all or part of an identity and access platform. It runs the platform, secures it day to day, and reports to the client against service commitments.

How does a managed service differ from staff augmentation?

Staff augmentation provides skills steered by the client with an effort-based commitment. A managed service commits the provider to outcomes, a scope, SLAs and dedicated governance.

How do IAM operations differ from IAM managed services?

IAM operations cover support, maintenance and continuous improvement with incident SLAs. Managed services go further: Ariovis owns operational responsibility, including operational security, platform lifecycle and dedicated governance.

Can Ariovis manage only part of the IAM platform?

Yes. Ariovis can operate a defined scope — IGA, Access, PAM, CIAM, or monitoring only. The rest remains driven by the client.

How are service commitments formalised?

Commitments are formalised in a service assurance plan defining scope, hours, SLAs, responsibilities, processes, governance and reversibility.

Is the service 24/7?

The Ariovis portal is available 24/7. Staffed coverage (9 a.m.–6 p.m., extended, on-call, 24/7 monitoring) is a contractual variable, calibrated to the accepted risk level.

How is operational security handled?

Ariovis tracks vendor vulnerabilities, applies critical patches, reviews technical access and coordinates with the client’s security team. Security incidents follow a dedicated process.

Is reversibility contracted?

Yes. Reversibility is structural: operations documentation, procedures, skills transfer at end of contract, access reset. It is described from contract signing.

Are evolutions also managed?

Yes. Managed services include continuous improvement and can carry recurring evolutions (new connectors, new use cases, application onboarding). Structural evolutions can be handled as projects.

Can we start with IAM operations and move to a managed service?

Yes. It is a common path: Ariovis takes over support, stabilises the service, then, if the client wishes, the relationship evolves toward a managed service with broader commitments.

Does Ariovis also handle technical monitoring?

Yes, within the agreed scope. Monitoring covers availability, jobs, connectors, data quality and security indicators. Alerts can automatically feed the support portal.

How is a major incident handled?

It follows a major-incident procedure: immediate mobilisation, crisis cell, workaround, restoration, client communication, then post-mortem within 3 business days maximum, with an eradication action.

Who deals with the vendor?

In managed services, Ariovis drives vendor escalation: ticket opening, evidence submission, follow-up until fix, consolidated client communication.

Is Ariovis vendor-agnostic?

Yes. We operate Netwrix Identity Manager, Ping Identity, Entra ID, Keycloak, Axiomatics, Netwrix Privilege Secure, Keeper and existing CyberArk environments, among others. Managed services can operate an existing environment without changing tools.

Where is the team that runs the service?

The Ariovis Brussels team is particularly focused on managed services and operations, in close coordination with Paris, Châtillon (Hauts-de-Seine) and Bordeaux (Nouvelle-Aquitaine). A single contract can mobilise several sites.

Which countries does Ariovis serve with IAM managed services?

Ariovis operates mainly in France and across Benelux, Switzerland and Germany, with a dedicated Brussels team for the zone.

Outsource all or part of your IAM operations?

A first, no-commitment conversation helps qualify your context, platform criticality and the most suitable managed model (partial or full).