How can we assist you?

Two routes, depending on what you need. The DAF ICAM Service Desk handles Okta sign-in and Okta Verify multi-factor resets, and technical support for Okta or SailPoint applications that are already integrated. Enablement inquiries — the program, the enablement process, or general information — go to the enablement team. The knowledge base below answers most enablement questions without a ticket.

DAF ICAM Assistant

An AI tool providing on-demand support and guidance for your DAF ICAM enablement journey. Access is requested through a form and approved within two business days.

Request access to the Assistant (opens in a new tab)

Knowledge base

My application is listed as discovered — what does that mean?

Okta told us the application exists but nobody has claimed it. Register it and the registry will route it into enablement.

I registered but have not heard anything

Check the program status page for your application's current state. Accelerated applications move straight to provisioning; assisted applications are scheduled for a discovery session.

My sign-in works but my roles are wrong

Group and claim mapping is an IdP-track issue. Confirm the claims you requested at registration, then raise it with your enablement engineer.

Access certification is asking me to review users I do not own

Certification campaigns follow the entitlement owner recorded in SailPoint. Ask your IGA analyst to correct the owner on the source.

Do I still need a DD Form 2875?

The paper SAAR is replaced by the digital workflow for applications on DAF ICAM. Existing paper processes must migrate on the published compliance timeline.

My application is on SIPRNet

SIPRNet applications implement DoW E-ICAM, not DAF ICAM. Register with that program instead.

Can I change my enablement path?

Yes. The program team can override the routing decision with a recorded justification; overrides are audited.

How do I add a redirect URI after enablement?

Managed applications can request the change through your enablement engineer; it is applied in Okta and recorded against the application.

Common problems and how to resolve them

Symptoms, resolutions and self-checks
SymptomResolutionSelf-check
Single sign-on returns "invalid redirect_uri" The URI the application sent does not match one registered in Okta. Compare it exactly, including scheme, port and trailing slash, and request the correction. Ask the assistant, or your enablement engineer, for the redirect URIs recorded against your application.
Users reach the application but see no data Authentication succeeded and authorization failed. Confirm the group claim your application expects and that the user holds the entitlement in SailPoint. Confirm the group claim recorded for your application with your enablement engineer.
Sign-out leaves the user signed in The application is clearing its own session only. Implement the single-logout endpoint published in the AOB guide.
Aggregation shows no entitlements The IGA source is connected but the entitlement schema is empty. Your IGA analyst re-runs aggregation after the schema is mapped.
Service account cannot obtain a token Machine-to-machine access uses a separate client with its own scopes; it is not covered by the interactive sign-on configuration.

Contact the program

Enablement inquiries

AFLCMC.HNID.DAFICAMEnablement@us.af.mil

AFLCMC/HNID DAF ICAM Enablement. Questions about the program, the enablement process, registration or general information. Include your application name; we answer as promptly as possible.

DAF ICAM Service Desk

Submit a service desk ticket

Okta sign-in and Okta Verify multi-factor resets, and technical support for Okta or SailPoint applications after integration. SailPoint tickets follow the submission instructions.

EITaaS Service Desk

1-888-996-1629

Telephone line for the service desk issues above.

A1 Service Desk

1-800-525-0102, Option 6

myFSS issues, which the DAF ICAM Service Desk does not handle.

Enhancement requests

Submit an enhancement request

Changes to configurations, entitlements or approvers, and new functionality on an Okta or SailPoint enabled application, where you need help from the DAF ICAM team.

Launch and Learn

Session schedule

Required orientation, with live question and answer.

DoW ICAM Huddle

Session schedule

Monthly community session on ICAM fundamentals and implementation.

Enablement Center

SharePoint

Pathway tools and resources for applications already registered.

Content last reviewed 17 September 2026. Next review due 16 December 2026.