Back to Blog // deployment

Hybrid and On-Premise Identity Without Lock-In

Not every workload belongs in the cloud. Here is how Veripass runs the same federation, policy, and audit model across cloud, on-premise, and hybrid deployments.

March 25, 2025 · Veripass
Hybrid and On-Premise Identity Without Lock-In

A lot of identity platforms quietly assume the answer is always “cloud.” For many organizations it is — but not for all of them, and rarely for all of their workloads. Data residency rules, regulatory boundaries, and existing on-premise systems mean the realistic answer is often “some of each.” Veripass is built so that choice does not cost you a different identity model.

One model, three deployment surfaces

The core idea is that the deployment topology is a property of where Veripass runs, not of how it works. Cloud, on-premise, and hybrid deployments share the same federation, authorization, and audit model. What changes is the surface; what stays constant is the architecture.

  • Cloud — the default for teams that want to operate the platform without running infrastructure.
  • On-premise — for organizations whose data residency or regulatory posture requires identity to stay inside their own environment.
  • Hybrid — a mix, where some workloads stay on-premise and the rest run in the cloud, all under one model.

Because these are the same platform in different topologies, an organization can start in one and move toward another without re-platforming its identity layer.

Why hybrid is the common reality

Pure cloud and pure on-premise are the simple cases. Most real organizations live in between, and usually for good reasons:

  • A regulated subset of data must remain on-premise, while everything else is better off in the cloud.
  • A migration is underway and on-premise systems will coexist with cloud ones for a long transition.
  • Different organizations within a federated estate have different residency requirements.

Hybrid identity exists to serve that reality instead of fighting it. With Veripass, the regulated workload stays on-premise and the rest runs in the cloud, but federation, policy evaluation, and audit behave identically across both. There is no second-class deployment.

Lock-in is the thing to avoid

The phrase “without lock-in” is the point of the whole exercise. Lock-in happens when the way you authenticate, authorize, and audit is welded to a single vendor’s hosting model, so that moving workloads means rebuilding identity.

Veripass avoids that in two ways. First, it keeps your directories authoritative: federation with Microsoft Entra ID and Google Workspace over OIDC, with SAML and OIDC for authentication and SCIM for provisioning, means your system of record stays where it already is. Second, it keeps the platform itself portable across cloud, on-premise, and hybrid, so the deployment decision is reversible.

The combination matters. Authoritative directories mean you are not trapped at the identity-source layer; portable deployment means you are not trapped at the hosting layer.

What stays the same everywhere

Whichever surface you run on, the controls do not change:

  • Federated authentication over SAML/OIDC, provisioning over SCIM, and API keys for machine identities.
  • Context-aware, policy-based authorization with composable claims, capabilities, roles, and access profiles.
  • Step-up MFA and biometric verification when a request warrants higher assurance.
  • An immutable audit trail for every meaningful action.

That consistency is what makes hybrid and on-premise viable rather than a compromise. You choose where identity runs based on your regulatory and operational needs, and you keep exactly the same federation, governance, and audit guarantees wherever you put it.

Keep reading

Migrating from Active Directory and LDAP Without Downtime

Migrating from Active Directory and LDAP Without Downtime

Replacing a directory is daunting because identity is load-bearing. Here is how Veripass lets you migrate from Active Directory and LDAP through federation and provisioning, without a hard cutover.

Architecture Overview: Federating Identities at Scale

Architecture Overview: Federating Identities at Scale

How Veripass federates identities across many applications and organizations from a single multi-tenant control plane, without forcing every team onto one directory.

Audit Trails That Survive an Audit

Audit Trails That Survive an Audit

An audit trail is only useful if it holds up when someone actually audits it. Here is what makes Veripass audit records immutable, attributable, and reconstructable.