We are the future of access for the Department of the Air Force
Every sign-in flows through one identity provider, so access can be granted, reviewed and revoked in one place. Applications keep their own authorization model — DAF ICAM standardizes authentication, group claims and the identity lifecycle, not what your application does with them.
DAF ICAM overview video — placeholder.
O U R M I S S I O N
We deliver the Department of the Air Force (DAF) Identity, Credential, and Access Management (ICAM) solution for all DAF applications operating on NIPRNet. We provide secure, compliant, and seamless access that supports critical Department of War (DoW) Zero Trust mandates, ensuring the right people have the right access, at the right time, for the right reason.
O U R C A P A B I L I T Y
DAF ICAM is a centrally funded enterprise identity management platform, providing proven, secure, and DoW-compliant capabilities to modernize your applications and reduce your team's workload. To learn more about ICAM fundamentals, the process and policy, visit our Knowledge Hub. If you have already registered your application, visit our Enablement Center to follow your integration pathway and access key tools and resources.
What is ICAM?
ICAM is a foundational security framework of policies, processes and technologies. Think of it as the digital equivalent of a facility's security guard, a keycard and door locks, all working together to manage and secure digital identities and control user access to critical resources.
The who
Identity Management
Establishing and managing a unique digital representation for each individual or device, creating a single authoritative source of truth for the entire identity lifecycle from creation to deletion.
How you prove it
Credential Management
Using an object or piece of information to verify an identity: something you know (a password), something you have (a CAC or PIV card), or something you are (a fingerprint), often secured with multi-factor authentication.
What you can do
Access Management
Determining which specific resources a user may use once their identity is authenticated, by enforcing least privilege — the minimum access necessary to do the job.
What is DAF ICAM?
DAF ICAM addresses the user pillar of the Zero Trust architecture while strengthening overall security posture. It provides enterprise services that give consistent, real-time access to user and resource data, so applications can create and enforce accurate rulesets for access. By verifying an individual's identity and confirming their credentials, DAF ICAM ensures users are granted access only to the information and systems they are explicitly authorized to use.
- Automated account provisioning and management
- Authentication and authorization services
- Automated processing for system access requests
- Auditing capabilities to enable access controls
The Department of the Air Force's only approved ICAM solution for NIPRNet.
What will DAF ICAM solve for you?
Identity silos
Each application or system has managed its own set of user accounts and passwords. Users had to remember numerous credentials, while administrators worked tirelessly to manage accounts across hundreds of systems.
Our solution
Users log in once with Single Sign-On to reach all their applications, which removes password fatigue and reduces administrative burden and duplicative effort.
Operational inefficiency
Onboarding new personnel or offboarding departing members was a manual process prone to error. Access requests took weeks to fulfil, while lingering accounts for separated personnel posed a security risk.
Our solution
The entire identity lifecycle is automated, so personnel are mission ready faster and the risk from orphaned accounts is removed by revoking access immediately on separation.
Lack of visibility
It was extremely difficult to answer a simple but critical question: who has access to what? Without a unified view, auditing, compliance checks and incident response were slow and ineffective.
Our solution
Real-time audit trails of all access turn incident response into rapid, data-driven action and streamline compliance.
Inconsistent policy
Without a central authority, enforcing uniform security policies such as password complexity or multi-factor authentication was nearly impossible, leaving gaps an adversary could exploit.
Our solution
Strong, consistent security is enforced centrally, providing the continuous verification a Zero Trust architecture needs and strengthening the DAF's cybersecurity posture.
How DAF ICAM works
Two components are foundational to securing an enterprise: the Identity Provider and Identity Governance and Administration. They work together but serve distinct functions, and DAF ICAM provides both as enterprise services, taking the security and management burden off application owners.
Identity Provider (IdP) — the authentication gateway, powered by Okta
An IdP's primary job is authentication: verifying a user is who they claim to be. Built on Okta, the DAF ICAM IdP is the DAF's central hub for confirming identities and enabling secure access to over 3,000 DAF applications.
Identity Governance and Administration (IGA) — the access manager, powered by SailPoint
An IGA's primary job is managing and enforcing access policy, so users hold the appropriate level of access at all times. Built on SailPoint, DAF ICAM IGA automates the identity lifecycle, closes security gaps, removes administrative burden and gives auditors centralized records of all access rights.
DAF ICAM replaces outdated, fragmented login systems with a secure, centralized, resilient, and data-centric solution. It acts as the authoritative foundation for managing digital identities and controlling access to DAF applications and systems, forming a critical pillar of the DAF's Zero Trust architecture. This ensures a consistent, secure, and seamless experience for all users while strengthening the overall cybersecurity posture of the Department.
Core values
Identity Provider
Centralized authentication and SSO
Validates a user's identity by CAC and enables one login across thousands of DAF applications.
Identity Provider
Attribute-based access control
Enforces least privilege through dynamic policy based on attributes such as rank, security clearance and training credentials.
Identity Provider
Enterprise security integration
Applies Zero Trust through continuous verification, strong encryption and centralized logging, over OIDC, SAML and OAuth 2.0.
Identity Provider
Authoritative attribute delivery
Supplies consistent user attributes such as rank and organization from trusted DAF and DoW sources, removing redundant verification systems.
Identity Governance and Administration
Seamless lifecycle management
Orchestrates the joiner, mover, leaver journey: provisioning for new users, real-time updates on role change, and instant revocation on departure.
Identity Governance and Administration
Digital access workflow automation
Turns manual DD Form 2875 processes into digital workflows, cutting overhead and accelerating onboarding.
Identity Governance and Administration
Comprehensive audit intelligence
Provides a definitive who-has-access-to-what record with immutable audit trails, for security operators and compliance programs such as FIAR.
Identity Governance and Administration
Development and compliance accelerator
Applications inherit enterprise-grade security capabilities that satisfy DoW requirements, reducing development overhead and attack surface.
Key differences
| Aspect | Identity Provider (Okta) | Identity Governance and Administration (SailPoint) |
|---|---|---|
| Primary focus | Authentication — are you who you say you are? | Authorization and governance — what are you allowed to do? |
| Core function | Single Sign-On and federation | Access requests, lifecycle management and policy enforcement |
| Key event | User login | A user joins, moves or leaves the organization |
| Lifecycle management | Basic provisioning | The full joiner, mover, leaver lifecycle |
| Access reviews | Not a standard feature | Periodic certification of who holds what |
| DAF ICAM platform | Okta | SailPoint |
Why does DAF ICAM matter?
Security is fundamental to DAF ICAM: it ensures only authorized personnel can reach DAF systems and data. DAF ICAM establishes the definitive framework for managing digital identities, authentication credentials and access privileges protecting our most mission-critical resources — a centralized identity platform with a governance framework that delivers automated, enterprise-wide authorization services, supporting rapid and secure access to mission and business information.
DAF ICAM compliance
The compliance framework protects sensitive information, supports mission assurance and maintains the trust DAF operations require. By integrating, application owners inherit a compliance posture that includes:
- Pre-validated security controls that simplify your Authority to Operate, so your application meets DoW, DAF and Zero Trust security mandates.
- Regulatory adherence: controls aligned with the NIST cybersecurity frameworks, including SP 800-39, 800-53 and 800-171.
- Audit support: the capabilities and documentation needed for Financial Improvement and Audit Readiness (FIAR).
- Risk management: identity and access practices that meet federal risk management standards.
- Documentation and reporting: the records and reports that demonstrate compliance with applicable regulations.
Zero Trust architecture
The DAF's Zero Trust cybersecurity strategy is the first step toward full compliance and a strengthened security posture. Zero Trust assumes every resource request comes from an untrusted source: access is granted per request, only once confidence in both user and device is established through identity verification and connection context, and it is revalidated frequently. DAF ICAM addresses the user pillar of the Zero Trust model, providing the authoritative identity services a Zero Trust architecture is built on.
How that is enforced
Access control frameworks
Zero Trust model
Continuously verifies every user and device with adaptive trust levels: never trust, always verify.
Access control frameworks
Attribute-based access control (ABAC)
Makes authorization decisions by evaluating user attributes, environmental factors and dynamic policy.
Access control frameworks
Role-based access control (RBAC)
Streamlines permissions by defining access levels against organizational roles.
Access control frameworks
Principle of least privilege
Users receive only the minimum access their specific role and mission require.
Authentication methods
Multi-factor authentication
Requires multiple verification steps — CAC or PIV, Okta FastPass — before access is granted.
Authentication methods
Data encryption and tokenization
Safeguards sensitive information both stored in databases and transmitted across networks.
Governance processes
Regular audits and reviews
Systematic assessment of user permissions and compliance status to identify vulnerabilities.
Governance processes
Entitlement management
Tracks the issue, update and revocation of user privileges across their lifecycle.
Governance processes
Policy enforcement points
Automated systems that request and enforce authorization decisions in real time.
Enablement pathways
Enabling your NIPRNet application with DAF ICAM is a straightforward process. After you register, our team will determine the best integration path for your application.
Accelerated Enablement
A streamlined, self-service journey using our Application Onboarding (AOB) tool. For applications using standard protocols like OIDC or SAML, integration can be completed in as little as two weeks.
Assisted Enablement
For applications with more complex requirements, our team provides hands-on guidance to ensure a smooth manual integration, which can be completed in as little as five weeks.
All DAF applications operating on SIPRNet must implement the Department of War Enterprise ICAM (DoW E-ICAM) solution. See the DoW E-ICAM website for more details.
N E E D H E L P ?
Launch and Learn Sessions
Gain an understanding of the DAF ICAM solution, its benefits and integration process, and have your questions answered at a DAF ICAM Launch & Learn session. Attending a Launch & Learn session is required to begin enablement.
DoW ICAM Huddle
Build your knowledge of ICAM fundamentals, learn about the ICAM implementation framework, and understand the future of system access at a DoW ICAM Huddle session. All sessions are held in Eastern Time.
Still not sure? AFLCMC.HNID.DAFICAMEnablement@us.af.mil or start the questionnaire.