We are the future of access for the Department of the Air Force

Every sign-in flows through one identity provider, so access can be granted, reviewed and revoked in one place. Applications keep their own authorization model — DAF ICAM standardizes authentication, group claims and the identity lifecycle, not what your application does with them.

DAF ICAM overview video — placeholder.

O U R  M I S S I O N

We deliver the Department of the Air Force (DAF) Identity, Credential, and Access Management (ICAM) solution for all DAF applications operating on NIPRNet. We provide secure, compliant, and seamless access that supports critical Department of War (DoW) Zero Trust mandates, ensuring the right people have the right access, at the right time, for the right reason.

O U R  C A P A B I L I T Y

DAF ICAM is a centrally funded enterprise identity management platform, providing proven, secure, and DoW-compliant capabilities to modernize your applications and reduce your team's workload. To learn more about ICAM fundamentals, the process and policy, visit our Knowledge Hub. If you have already registered your application, visit our Enablement Center to follow your integration pathway and access key tools and resources.

What is ICAM?

ICAM is a foundational security framework of policies, processes and technologies. Think of it as the digital equivalent of a facility's security guard, a keycard and door locks, all working together to manage and secure digital identities and control user access to critical resources.

The who

Identity Management

Establishing and managing a unique digital representation for each individual or device, creating a single authoritative source of truth for the entire identity lifecycle from creation to deletion.

How you prove it

Credential Management

Using an object or piece of information to verify an identity: something you know (a password), something you have (a CAC or PIV card), or something you are (a fingerprint), often secured with multi-factor authentication.

What you can do

Access Management

Determining which specific resources a user may use once their identity is authenticated, by enforcing least privilege — the minimum access necessary to do the job.

What is DAF ICAM?

DAF ICAM addresses the user pillar of the Zero Trust architecture while strengthening overall security posture. It provides enterprise services that give consistent, real-time access to user and resource data, so applications can create and enforce accurate rulesets for access. By verifying an individual's identity and confirming their credentials, DAF ICAM ensures users are granted access only to the information and systems they are explicitly authorized to use.

  • Automated account provisioning and management
  • Authentication and authorization services
  • Automated processing for system access requests
  • Auditing capabilities to enable access controls

The Department of the Air Force's only approved ICAM solution for NIPRNet.

What will DAF ICAM solve for you?

Identity silos

Each application or system has managed its own set of user accounts and passwords. Users had to remember numerous credentials, while administrators worked tirelessly to manage accounts across hundreds of systems.

Our solution

Users log in once with Single Sign-On to reach all their applications, which removes password fatigue and reduces administrative burden and duplicative effort.

Operational inefficiency

Onboarding new personnel or offboarding departing members was a manual process prone to error. Access requests took weeks to fulfil, while lingering accounts for separated personnel posed a security risk.

Our solution

The entire identity lifecycle is automated, so personnel are mission ready faster and the risk from orphaned accounts is removed by revoking access immediately on separation.

Lack of visibility

It was extremely difficult to answer a simple but critical question: who has access to what? Without a unified view, auditing, compliance checks and incident response were slow and ineffective.

Our solution

Real-time audit trails of all access turn incident response into rapid, data-driven action and streamline compliance.

Inconsistent policy

Without a central authority, enforcing uniform security policies such as password complexity or multi-factor authentication was nearly impossible, leaving gaps an adversary could exploit.

Our solution

Strong, consistent security is enforced centrally, providing the continuous verification a Zero Trust architecture needs and strengthening the DAF's cybersecurity posture.

How DAF ICAM works

Two components are foundational to securing an enterprise: the Identity Provider and Identity Governance and Administration. They work together but serve distinct functions, and DAF ICAM provides both as enterprise services, taking the security and management burden off application owners.

Identity Provider (IdP) — the authentication gateway, powered by Okta

An IdP's primary job is authentication: verifying a user is who they claim to be. Built on Okta, the DAF ICAM IdP is the DAF's central hub for confirming identities and enabling secure access to over 3,000 DAF applications.

Identity Governance and Administration (IGA) — the access manager, powered by SailPoint

An IGA's primary job is managing and enforcing access policy, so users hold the appropriate level of access at all times. Built on SailPoint, DAF ICAM IGA automates the identity lifecycle, closes security gaps, removes administrative burden and gives auditors centralized records of all access rights.

DAF ICAM replaces outdated, fragmented login systems with a secure, centralized, resilient, and data-centric solution. It acts as the authoritative foundation for managing digital identities and controlling access to DAF applications and systems, forming a critical pillar of the DAF's Zero Trust architecture. This ensures a consistent, secure, and seamless experience for all users while strengthening the overall cybersecurity posture of the Department.

Core values

Identity Provider

Centralized authentication and SSO

Validates a user's identity by CAC and enables one login across thousands of DAF applications.

Identity Provider

Attribute-based access control

Enforces least privilege through dynamic policy based on attributes such as rank, security clearance and training credentials.

Identity Provider

Enterprise security integration

Applies Zero Trust through continuous verification, strong encryption and centralized logging, over OIDC, SAML and OAuth 2.0.

Identity Provider

Authoritative attribute delivery

Supplies consistent user attributes such as rank and organization from trusted DAF and DoW sources, removing redundant verification systems.

Identity Governance and Administration

Seamless lifecycle management

Orchestrates the joiner, mover, leaver journey: provisioning for new users, real-time updates on role change, and instant revocation on departure.

Identity Governance and Administration

Digital access workflow automation

Turns manual DD Form 2875 processes into digital workflows, cutting overhead and accelerating onboarding.

Identity Governance and Administration

Comprehensive audit intelligence

Provides a definitive who-has-access-to-what record with immutable audit trails, for security operators and compliance programs such as FIAR.

Identity Governance and Administration

Development and compliance accelerator

Applications inherit enterprise-grade security capabilities that satisfy DoW requirements, reducing development overhead and attack surface.

Key differences

Key differences between the Identity Provider and Identity Governance and Administration
Aspect Identity Provider (Okta) Identity Governance and Administration (SailPoint)
Primary focus Authentication — are you who you say you are? Authorization and governance — what are you allowed to do?
Core function Single Sign-On and federation Access requests, lifecycle management and policy enforcement
Key event User login A user joins, moves or leaves the organization
Lifecycle management Basic provisioning The full joiner, mover, leaver lifecycle
Access reviews Not a standard feature Periodic certification of who holds what
DAF ICAM platform Okta SailPoint

Why does DAF ICAM matter?

Security is fundamental to DAF ICAM: it ensures only authorized personnel can reach DAF systems and data. DAF ICAM establishes the definitive framework for managing digital identities, authentication credentials and access privileges protecting our most mission-critical resources — a centralized identity platform with a governance framework that delivers automated, enterprise-wide authorization services, supporting rapid and secure access to mission and business information.

DAF ICAM compliance

The compliance framework protects sensitive information, supports mission assurance and maintains the trust DAF operations require. By integrating, application owners inherit a compliance posture that includes:

  • Pre-validated security controls that simplify your Authority to Operate, so your application meets DoW, DAF and Zero Trust security mandates.
  • Regulatory adherence: controls aligned with the NIST cybersecurity frameworks, including SP 800-39, 800-53 and 800-171.
  • Audit support: the capabilities and documentation needed for Financial Improvement and Audit Readiness (FIAR).
  • Risk management: identity and access practices that meet federal risk management standards.
  • Documentation and reporting: the records and reports that demonstrate compliance with applicable regulations.

Zero Trust architecture

The DAF's Zero Trust cybersecurity strategy is the first step toward full compliance and a strengthened security posture. Zero Trust assumes every resource request comes from an untrusted source: access is granted per request, only once confidence in both user and device is established through identity verification and connection context, and it is revalidated frequently. DAF ICAM addresses the user pillar of the Zero Trust model, providing the authoritative identity services a Zero Trust architecture is built on.

How that is enforced

Access control frameworks

Zero Trust model

Continuously verifies every user and device with adaptive trust levels: never trust, always verify.

Access control frameworks

Attribute-based access control (ABAC)

Makes authorization decisions by evaluating user attributes, environmental factors and dynamic policy.

Access control frameworks

Role-based access control (RBAC)

Streamlines permissions by defining access levels against organizational roles.

Access control frameworks

Principle of least privilege

Users receive only the minimum access their specific role and mission require.

Authentication methods

Multi-factor authentication

Requires multiple verification steps — CAC or PIV, Okta FastPass — before access is granted.

Authentication methods

Data encryption and tokenization

Safeguards sensitive information both stored in databases and transmitted across networks.

Governance processes

Regular audits and reviews

Systematic assessment of user permissions and compliance status to identify vulnerabilities.

Governance processes

Entitlement management

Tracks the issue, update and revocation of user privileges across their lifecycle.

Governance processes

Policy enforcement points

Automated systems that request and enforce authorization decisions in real time.

Enablement pathways

Enabling your NIPRNet application with DAF ICAM is a straightforward process. After you register, our team will determine the best integration path for your application.

Accelerated Enablement

A streamlined, self-service journey using our Application Onboarding (AOB) tool. For applications using standard protocols like OIDC or SAML, integration can be completed in as little as two weeks.

Assisted Enablement

For applications with more complex requirements, our team provides hands-on guidance to ensure a smooth manual integration, which can be completed in as little as five weeks.

All DAF applications operating on SIPRNet must implement the Department of War Enterprise ICAM (DoW E-ICAM) solution. See the DoW E-ICAM website for more details.

N E E D  H E L P ?

Launch and Learn Sessions

Gain an understanding of the DAF ICAM solution, its benefits and integration process, and have your questions answered at a DAF ICAM Launch & Learn session. Attending a Launch & Learn session is required to begin enablement.

DoW ICAM Huddle

Build your knowledge of ICAM fundamentals, learn about the ICAM implementation framework, and understand the future of system access at a DoW ICAM Huddle session. All sessions are held in Eastern Time.

Still not sure? AFLCMC.HNID.DAFICAMEnablement@us.af.mil or start the questionnaire.