Workforce Identity and Access

One trusted identity. Secure access. Easier collaboration across state government.

WaTech's Workforce Identity and Access services help agencies manage who can access state systems, applications, networks, and cloud services.

These shared services provide the foundation employees use to sign in, access the tools they need, and work securely with people in other agencies and organizations.

Depending on your agency's needs, Workforce Identity and Access can provide:

  • A shared directory for employees and computers.
  • Secure sign-in to applications and services.
  • Single sign-on so employees do not have to repeatedly enter credentials.
  • Identity services that connect on-premises and cloud environments.
  • Secure collaboration between agencies with separate Microsoft 365 environments.
  • Guest access for partners, vendors, and other approved users.
  • Cloud-based domain services for applications and virtual machines.

Explore our identity services

Enterprise Active Directory (EAD) - A shared identity foundation that helps agencies securely connect employees, computers, applications, and resources across state government.

Active Directory Federation Services (ADFS) - Provides single sign-on for applications that still rely on ADFS while WaTech works toward modern Microsoft Entra ID authentication.

Microsoft Entra ID (previously Azure Active Directory/AAD) - Cloud-based identity and access management that helps agencies securely connect people to Microsoft 365, cloud applications, and other resources.

Cross-Tenant Synchronization - Helps agencies with separate Microsoft 365 environments work together by automatically sharing approved employee identities between environments.

Business-to-Business (B2B) Collaboration - Provides secure guest access so agencies can work with people outside their Microsoft 365 environment.

Azure Domain Controllers - Extends Enterprise Active Directory into Azure so agencies can use familiar domain services with cloud applications and virtual machines.

The goal is simple: Make working across agency boundaries feel easier without giving up control of identity and access.

Enterprise Active Directory (EAD)

A shared identity foundation for state government.

Enterprise Active Directory provides a common directory and identity service for participating Washington state agencies.

It helps identify employees and computers, control access to resources, and make it easier for agencies to work together while still managing their own organizations.

EAD also provides directory information such as employee names, work email addresses, phone numbers, and other business contact information.

Why use EAD?

EAD gives agencies a shared foundation instead of requiring every agency to build and maintain the same identity infrastructure on its own.

It can help agencies:

  • Give employees secure access to agency and shared state resources.
  • Find and connect with employees in other participating agencies.
  • Simplify common tasks such as finding coworkers and scheduling meetings.
  • Use shared statewide identity and authentication services.
  • Reduce duplicated infrastructure and administration.
  • Support applications that depend on Active Directory.

Back to top

Active Directory Federation Services (ADFS)

Single sign-on for applications today, with a path toward modern cloud authentication.

Active Directory Federation Services provides single sign-on for applications that use ADFS authentication.

In plain terms, single sign-on means an employee can sign in with their work account and use that trusted sign-in to access other approved applications. They do not need a separate username and password for every system.

WaTech has used ADFS to support access to applications such as HRMS, ServiceNow, Salesforce, and other on-premises and cloud applications.

Where ADFS is headed

ADFS has served state government for many years, but identity technology is changing.

Microsoft now recommends moving application authentication from ADFS to Microsoft Entra ID and provides tools and guidance specifically for migrating and eventually decommissioning ADFS environments.

WaTech is preparing for that future.

Our focus is to reduce reliance on ADFS over time and expand modern Entra ID capabilities that provide secure authentication and make it easier for agencies to work across separate Microsoft 365 environments.

That work includes growing our Cross-Tenant Synchronization offering.

What is Cross-Tenant Synchronization?

Think of each agency's Microsoft 365 environment as its own secure building.

Employees have an identity and badge that works inside their own building. But when they need to work regularly inside another agency's environment, someone may need to create and maintain another identity for them.

Cross-Tenant Synchronization helps automate that connection.

It allows approved employee identity information from one Microsoft 365 tenant to be automatically created and kept up to date in another tenant.

Microsoft describes Cross-Tenant Synchronization as a way to automatically create, update, and remove B2B collaboration users between Microsoft Entra tenants.

For example:

An employee at Agency A regularly works with Agency B.

Instead of Agency B manually creating and maintaining an account for that person, Cross-Tenant Synchronization can automatically make the employee available in Agency B's Microsoft 365 environment.

When information about that employee changes, the synchronized identity can be updated. When the employee is no longer included in the synchronization, their B2B account can be removed automatically.

Why this matters

For employees, it can mean:

  • Easier collaboration across agencies.
  • A more consistent Microsoft 365 experience.
  • Less friction when accessing approved resources in another agency.

For agency IT teams, it can mean:

  • Less manual account creation and cleanup.
  • More consistent identity management.
  • Better control over which users are shared.
  • Easier management of employee access as people join, move, or leave.

Each agency continues to control access to its own environment. Cross-Tenant Synchronization helps automate identity sharing; it does not automatically give another agency's employees unrestricted access to applications or data. Microsoft provides separate cross-tenant access controls for managing those trust and access decisions.

Our direction

WaTech is working toward an identity environment that relies more on modern Entra ID capabilities and less on legacy federation technology.

Our priorities include:

  • Expanding Cross-Tenant Synchronization for participating agencies.
  • Helping agencies move application authentication from ADFS to Entra ID where appropriate.
  • Reducing manual management of cross-agency identities.
  • Improving secure collaboration between agencies with separate Microsoft 365 tenants.
  • Maintaining appropriate agency control over access and security.

Your organization must be a member of the Enterprise Active Directory (EAD) to use this service.

Service Forms & Documents

Back to top

Microsoft Entra ID

Cloud identity for Microsoft 365 and modern applications.

Microsoft Entra ID, formerly called Azure Active Directory or Azure AD, is Microsoft's cloud-based identity and access management service.

It helps determine who a user is and what that user is allowed to access.

For participating agencies, Entra ID provides the identity foundation behind Microsoft 365 and many other cloud services.

What does Entra ID do?

Entra ID can help agencies:

  • Sign employees in to Microsoft 365 and cloud applications.
  • Manage access to applications and resources.
  • Use single sign-on with supported applications.
  • Apply security controls to user access.
  • Collaborate with users in other organizations.
  • Support identities that need access to both cloud and on-premises resources.

Entra ID is also the platform behind capabilities such as B2B collaboration and Cross-Tenant Synchronization.

For agencies using the Enterprise Shared Tenant, Entra ID capabilities are provided through the Microsoft 365 environment and applicable Microsoft licensing.

Back to top

Cross-Tenant Synchronization

Making it easier for separate agency Microsoft 365 environments to work together.

Some Washington state agencies participate in WaTech's Enterprise Shared Tenant. Others operate their own Microsoft 365 tenants.

That independence can be important, but it can also create barriers when employees need to work across agency boundaries.

Cross-Tenant Synchronization helps bridge that gap.

It automatically synchronizes approved identities from one Microsoft Entra tenant into another as B2B collaboration users. Microsoft designed the capability to improve collaboration and automate identity lifecycle management across multiple tenants.

What does that mean in plain talk?

Imagine Agency A and Agency B each have their own Microsoft 365 environment.

Agency A has an employee named Taylor who needs to regularly work with Agency B.

Without automation, Agency B may need to manually create and maintain a guest identity for Taylor.

With Cross-Tenant Synchronization, Taylor's approved identity information can be automatically synchronized from Agency A into Agency B.

Taylor continues to belong to Agency A, while Agency B decides which of its resources Taylor can access.

If Taylor's information changes, the synchronized identity can be updated automatically. If Taylor should no longer be synchronized, that identity can be removed automatically.

Benefits

Cross-Tenant Synchronization can help:

  • Make cross-agency collaboration easier.
  • Reduce manual guest account management.
  • Keep shared identity information more current.
  • Remove accounts when they are no longer needed.
  • Give agencies more consistent ways to connect separate Microsoft 365 environments.
  • Preserve each agency's control over its own applications, information, and access decisions.

WaTech is continuing to develop this capability as part of our move toward a more modern statewide identity model.

Back to top

Business-to-Business (B2B) Collaboration

Work securely with people outside your Microsoft 365 environment.

Not everyone an agency needs to work with will have an account in the same Microsoft 365 tenant.

Microsoft Entra B2B collaboration allows agencies to invite approved users from another organization to access selected applications and resources.

Those users can often continue using the credentials from their home organization instead of receiving another username and password.

When might an agency use B2B?

B2B can support collaboration with:

  • Other state agencies.
  • Contractors.
  • Vendors.
  • Business partners.
  • Other approved external organizations.

Benefits

B2B helps agencies:

  • Collaborate without creating a completely separate workforce account for every external user.
  • Allow external users to use their existing organizational credentials.
  • Control which applications and resources guests can access.
  • Remove access when it is no longer needed.

Cross-Tenant Synchronization builds on Microsoft Entra B2B by automating much of the work involved in creating, updating, and removing those cross-tenant identities.

Back to top

Azure Domain Controllers

Extend Active Directory into the cloud.

Some applications still need traditional Active Directory services even after they move to the cloud.

WaTech's Azure Domain Controller service extends Enterprise Active Directory (EAD) into Azure so agencies can use those services with cloud-hosted applications and virtual machines.

Agencies can connect approved Azure or AWS environments to the service and use EAD-based authentication without building and maintaining their own domain controller infrastructure.

Why use Azure Domain Controllers?

The service can help agencies:

  • Move applications from on-premises environments to the cloud.
  • Support applications that still require traditional Active Directory.
  • Reduce the work of operating domain controller infrastructure.
  • Use existing EAD identities with cloud-hosted systems.
  • Improve resiliency by using shared, managed infrastructure.

The service includes production and pre-production environments.

Agencies must be current EAD customers to use Azure Domain Controllers.

Pricing:

Description

Fee

Base Azure DC Root

$1,550 per month

Agency dedicated hosted DC in Azure

$550 per month

Service Forms & Documents

Back to top