Air Force Space Force

Department of the Air Force

Identity, Credential, and Access Management for air, space and cyber

DAF ICAM delivers secure, compliant, and seamless access for all DAF applications operating on NIPRNet, supporting Department of War (DoW) Zero Trust mandates — the right people have the right access, at the right time, for the right reason.

Register your application How enablement works

Takes about five minutes. You can save and come back.

An Airman in hearing protection works the flight line at RAF Lakenheath.
Air
A Guardian monitors a workstation in the Combined Space Operations Center.
Space
Cyber operators watch network defence displays at Port San Antonio.
Cyber
Airmen and Guardians salute in formation at a retreat ceremony.
Airmen & Guardians

Photographs: U.S. Air Force and U.S. Space Force. Works of the U.S. Government, in the public domain. Credits are listed in docs/hero-photo-credits.md.

  • 1,000 Applications in the registry Registered and discovered
  • 174 Enabled and live on DAF ICAM Cumulative
  • 22 Enabled this month Current month
  • 13.6% Provisioning automated Of applications in scope

Figures are live from the registry and refresh on this page. See the full program status.

T H E  T H R E E  T R A C K S

Three tracks, one onboarding

Every application follows the same registration, then moves through the tracks it needs. The registry reports progress on each one separately, so an application waiting on governance is never counted as blocked on authentication.

Okta

Identity Provider

Single Sign-On and multi-factor authentication over SAML or OIDC, with authoritative user attributes aggregated from DAF sources.

SailPoint

Identity Governance

Access requests, entitlement mapping, periodic certification and least-privilege enforcement for the roles that require a System Access Request.

SCIM and connectors

Automated Provisioning

Accounts and permissions created, updated and deprovisioned automatically over SCIM, REST, LDAP or just-in-time from the assertion.

Y O U R  P A T H

From registration to live

  1. Phase 1 Discovery and inventory Okta and SailPoint inventories are reconciled and application owners are identified.
  2. Phase 2 Register and route Owners register their applications and answer the questionnaire; the registry routes each one to accelerated or assisted enablement.
  3. Phase 3 Enablement Accelerated applications configure themselves through the AOB tool; assisted applications work with an enablement engineer.
  4. Phase 4 Cutover and verification Access is verified in SailPoint, legacy authentication is retired, and the application goes live on DAF ICAM.

O U R  M I S S I O N

We deliver the Department of the Air Force (DAF) Identity, Credential, and Access Management (ICAM) solution for all DAF applications operating on NIPRNet. We provide secure, compliant, and seamless access that supports critical Department of War (DoW) Zero Trust mandates, ensuring the right people have the right access, at the right time, for the right reason.

O U R  C A P A B I L I T Y

Do you know DAF ICAM?

DAF ICAM is a centrally funded enterprise identity management platform, providing proven, secure, and DoW-compliant capabilities to modernize your applications and reduce your team's workload. To learn more about ICAM fundamentals, the process and policy, visit our Knowledge Hub. If you have already registered your application, visit our Enablement Center to follow your integration pathway and access key tools and resources.

How DAF ICAM works

DAF ICAM replaces outdated, fragmented login systems with a secure, centralized, resilient, and data-centric solution. It acts as the authoritative foundation for managing digital identities and controlling access to DAF applications and systems, forming a critical pillar of the DAF's Zero Trust architecture. This ensures a consistent, secure, and seamless experience for all users while strengthening the overall cybersecurity posture of the Department.

Identity Provider (IdP) — the authentication gateway, powered by Okta

An IdP's primary job is authentication: verifying a user is who they claim to be. Built on Okta, the DAF ICAM IdP is the DAF's central hub for confirming identities and enabling secure access to over 3,000 DAF applications.

Identity Governance and Administration (IGA) — the access manager, powered by SailPoint

An IGA's primary job is managing and enforcing access policy, so users hold the appropriate level of access at all times. Built on SailPoint, DAF ICAM IGA automates the identity lifecycle, closes security gaps, removes administrative burden and gives auditors centralized records of all access rights.

O U R  W H Y

Enhanced security

Protects sensitive data from unauthorized access and cyber threats.

Improved user experience

Enables capabilities like Single Sign-On (SSO), allowing users to log in once to access multiple applications.

Operational efficiency

Automates the process of managing access for new hires, role changes, and departures.

Regulatory compliance

Creates a clear audit trail of "who accessed what" to meet compliance standards.

Our approach

Enabling your NIPRNet application with DAF ICAM is a straightforward process. After you register, our team will determine the best integration path for your application.

Accelerated Enablement

A streamlined, self-service journey using our Application Onboarding (AOB) tool. For applications using standard protocols like OIDC or SAML, integration can be completed in as little as two weeks.

Assisted Enablement

For applications with more complex requirements, our team provides hands-on guidance to ensure a smooth manual integration, which can be completed in as little as five weeks.

All DAF applications operating on SIPRNet must implement the Department of War Enterprise ICAM (DoW E-ICAM) solution. See the DoW E-ICAM website for more details.

Who needs to register

  • Any DAF NIPRNet application that authenticates humans, including internal tools
  • Any application still issuing its own local accounts or passwords
  • Any service or machine-to-machine integration that needs scoped credentials
  • Applications already federated to a legacy identity provider

What this registry does

This registry is the DAF ICAM enablement front door. Okta remains the authoritative inventory of applications; the registry owns the program state around each one — who claimed it, which enablement path it is on, and what remains on the IdP and IGA tracks before cutover.

Register your application

C O M P L I A N C E  T I M E L I N E

DoW and DAF policies state that DAF ICAM is the single, DoW-authorized ICAM solution for all DAF systems, applications and services on NIPRNet, and all DAF NIPRNet applications must be onboarded to meet Zero Trust requirements. Failure to comply risks loss of application access, accreditation challenges, and mission disruption.

  1. 1 January 2026 All existing digital DD Form 2875 processes on NIPRNet must migrate to DAF ICAM.
  2. 30 September 2026 By the end of FY 2026, all ICOFR-relevant systems must be onboarded.
  3. 1 January 2027 All existing digital DD Form 2875 processes on SIPRNet must migrate to DoW E-ICAM.
  4. 30 September 2027 All DAF systems and applications must have adopted a DoW-approved ICAM Service Provider.

Per the ICAM Implementation Memorandum, all DAF NIPRNet applications were required to register with DAF ICAM by 27 April 2026. If you have not registered, you are non-compliant and must register immediately.

DAF ICAM is more than a tool

It's a force multiplier that benefits every user, program, and mission.

A P P L I C A T I O N  O W N E R S

  • Meet security mandates and reduce risk Integrating aligns your application with DoW and DAF policy, delivers compliant out-of-the-box capabilities, and lets you inherit pre-validated security controls to simplify your ATO process.
  • Cost savings DAF ICAM is centrally funded — there are no licensing costs for your program. You eliminate the expense of building and maintaining redundant identity solutions and can reinvest those savings into your core mission.
  • Resource efficiency Your developers focus on application logic and innovation while DAF ICAM handles authentication, access control and auditing, accelerating development of your application's core features.

A I R M E N  &  G U A R D I A N S

  • Login once, access everything Single Sign-On gives you secure access to all your authorized applications with one simple login.
  • Mission ready, faster Slow paper DD Form 2875 System Authorization Access Requests are replaced with automated digital workflows that take minutes.
  • One look, one process A single, consistent way to access your authorized systems, reducing user confusion.
  • Your information is secure Comprehensive security features and automated provisioning update your access as your role changes.

N E E D  H E L P ?

Launch and Learn Sessions

Gain an understanding of the DAF ICAM solution, its benefits and integration process, and have your questions answered at a DAF ICAM Launch & Learn session. Attending a Launch & Learn session is required to begin enablement.

DoW ICAM Huddle

Build your knowledge of ICAM fundamentals, learn about the ICAM implementation framework, and understand the future of system access at a DoW ICAM Huddle session. All sessions are held in Eastern Time.

Questions owners ask

Do I have to register an application that is already in Okta?

Yes. Okta tells us the application exists; the registry tracks whether anyone owns it and where it is in enablement. Imported applications start as "discovered" until an owner claims them.

What happens after I submit?

The routing engine decides your enablement path immediately and shows you the reasons. Accelerated applications move to Okta provisioning; assisted applications are scheduled for a discovery session.

Can the routing decision be overridden?

Yes, by the program team, with a recorded justification. Overrides are audited.

Does DAF ICAM change my application's configuration without telling me?

No. The registry only writes to Okta for applications in the "managed" state, which requires the owner to opt in.

What about applications on SIPRNet?

SIPRNet applications implement DoW E-ICAM rather than DAF ICAM; register them with that program instead.

DAF ICAM enablement is here. Are you ready?

Questions? AFLCMC.HNID.DAFICAMEnablement@us.af.mil

Register your application