What it is and What it could be
Right now, the world’s split into 2 - one half has got cash to throw at the most expensive solution, hoping it would be the best there is; and the other half never seems to have enough cash lying around that can be spent on a security solution.
But there’s one thing that unites both these classes, it is their pre-existing infrastructure. Okay maybe there are 2 things. Both classes fail to realize that the set-up that they’ve already got - the website; presumably built on Drupal - the best CMS there is when it comes to security - and the associated database - can in itself become the source for Identity Verification or in other words, Drupal becomes your Identity Provider (IdP).
Unmasking Cloud IdPs
When faced with the daunting task of setting up a centralized Identity Management System, most people turn to providers like Azure AD, Okta and Ping Identity to name a few. While there’s nothing inherently wrong with choosing these products - they exist for a reason, they have a great product that has stood strong for tens of years. But what the average consumer of these services do not realize, is how quickly the costs can add up.
Maybe you’re someone who is into finance, maybe not, but there’s this concept of NDR - Net Dollar Retention - which literally means how much a customer is paying year over year. Any NDR over 100% is a sign of growth and expansion of business. There are many ways to achieve a 100%+ NDR, you cross-sell or you up-sell, but the easiest way might just be to simply jack up the prices. That is what the leaders tend to do - and they can get away with it, just because there’s nowhere for the users to go, there isn’t a better alternative out there. Well, until now.
Why On-Prem Drupal IdP
IdPs like Okta and Azure are feature-rich no doubt, but they’re often priced for large organizations. miniOrange provides a powerful, scalable alternative that doesn’t break your bank; and the added benefit - it sits right in your Drupal Ecosystem!
Let’s talk numbers:
Cloud SaaS Solutions: $5 to $15 per user per month - That’s anywhere between $6000 to $18000/year for 100 users. Even if we consider a non-linear pricing model, a 50% reduction would still mean an annual cost of anywhere between $3000 and $9000.
On-Prem Drupal as IdP: $450/year for 100 users. That's over 90% savings, without compromising on security or features. It's got all things you’d expect out of a full-fledged cloud IdP -
- Adaptive Authentication? Check!
- Protocol Agnostic - If you’re a SAML junkie or an OAuth groupie, it can do both! Check, and Check!
- Auditing, Logging and Session Monitoring? We got that too!
- In-built MFA support? Yep, it’s got that as well
There’s a pretty significant trade off while choosing between a cloud or an on-premise solution - especially when it comes to authentication & user security. One often-overlooked but critical factor in this decision is data residency.
With the rampant expansion of the AI landscape, where the ethics of AI crawlers are questionable, you should ask yourself is your cloud hosted data really private?
Why not shift to a solution that is completely within your control? A solution that can work without any external connectivity, a solution that gives you your very own inhouse IdP without the pesky setup, a solution that makes financial and technological sense.
When it comes to creating an IdP within Drupal, there are solutions including the likes of us where everything is deployed completely on-premise, within your own infrastructure - with no risk of user data exposure or a leak. The entire identity flow stays inside your environment, giving you complete control over your security setup - nothing ever leaves your system.
Put your money where it matters
This level of control is not just a bonus, it's elementary - almost mandatory, especially if you're aiming for SOC2 compliance, or operating in an environment where data sovereignty is a legal or internal mandate.
And if you need even more convincing, here’s the kicker - by going for these solutions - you're just not improving security; you're saving a ton to what you'd otherwise be spending on external identity services. The money you save just doesn't disappear, it can be redirected to something more meaningful, like adding advanced capabilities such as a PAM solution, or maybe even back into your team - because who doesn’t like a fatter wallet? Sometimes the best investment you can do is just giving your employees a well-deserved raise.
The bottom line?
You don't have to overspend to get a reliable and secure IAM solution, without - now you have the power, you can do it all - we believe in you!
Leave a Comment