The DoD Has 24 Months to Migrate Thousands of Applications to Centralized Identity Systems. Is Your Team Ready?

The mandate is active. The clock is running. Here’s what federal ICAM leaders need to know.

Compliance  |  6 min read  |  Audience: DoD & Federal Agencies

There’s a moment in every large-scale federal IT modernization program when the scope becomes undeniable. For identity teams across the Department of Defense, that moment has arrived.

The mandate to consolidate and migrate applications to centralized Identity, Credential, and Access Management (ICAM) systems isn’t new. What is new is the urgency. With a 24-month window to bring thousands of applications into compliance with DoD identity modernization directives, the challenge isn’t whether to act — it’s how to act fast enough.

The bottleneck isn’t budget. It isn’t willingness. It’s the onboarding process itself.

The average enterprise today spends between $15,000 and $75,000 to onboard a single application into an IGA system. Multiply that by hundreds — or thousands — of applications, and the math becomes impossible.

Why Application Onboarding Is the Hardest Part of ICAM Migration

Ask any identity program manager what slows down an IGA deployment and the answer is almost always the same: getting applications onboarded. Not the technology. Not the policy. The process of capturing what each application needs, configuring the right connectors, defining roles and entitlements, establishing approval chains, and mapping that information into the identity governance system — over and over again, for every application in your portfolio.

The typical onboarding cycle for a single enterprise application looks something like this:

  • An identity team member schedules a kickoff meeting with the application owner
  • The application owner — who may have never worked with an IGA system — tries to understand what information is being asked for
  • Multiple rounds of back-and-forth clarification follow over days or weeks
  • A developer manually translates that information into connector configurations
  • Testing reveals gaps; the cycle starts again
  • Final configuration is loaded into the IGA platform by a specialist with deep system knowledge

For a well-resourced team with deep SailPoint expertise, this process might take two to four weeks per application. For a team managing hundreds of applications simultaneously while also operating a production identity environment? It becomes an existential program risk.

$45,000
Average cost to onboard a single enterprise application — before the mandate, the timeline, or the scale.

What the Mandate Actually Requires

The DoD’s centralized identity systems mandate isn’t asking agencies to move a handful of high-priority applications. It’s asking for comprehensive migration — including applications that have never been formally governed, applications running on legacy infrastructure, and applications whose ownership has changed hands multiple times.

That scope demands a repeatable, scalable process. A process that doesn’t require an expert developer for every application. A process that captures the right information — system owners, classification levels, connector types, entitlement definitions, SAR 2875 approval workflows, joiner/mover/leaver rules — in a structured, consistent way that translates directly into system configuration without manual rework.

That process doesn’t exist in most organizations today. It’s built manually, from scratch, on every program.

The Information Gap at the Heart of the Problem

One of the most underappreciated challenges in application onboarding is the knowledge gap between application owners and identity teams. Application owners understand their systems deeply but have no context for what an IGA platform needs. Identity teams understand governance requirements deeply but lack the bandwidth to hand-hold every application owner through the process.

The result is a translation problem that plays out in every intake meeting, every clarification email, every rework cycle. Application owners don’t know what a “connector type” is. They can’t distinguish between IT roles and business roles without guidance. They don’t know what correlation attributes are or why they matter.

You can’t scale a migration program when every application requires an expert in the room. The knowledge has to be embedded in the process itself.

A Better Path: Structured, Automated, Scalable Onboarding

The federal agencies and DoD components that will successfully meet the 24-month migration deadline will have one thing in common: a repeatable onboarding process that doesn’t depend on individual expertise at every step.

That means:

  • A structured intake form aligned to DoD mandate requirements — capturing application name, system owners, technical POCs, mission criticality, classification levels, environments, and risk
  • Guided self-service for application owners — with built-in context, definitions, and AI-powered assistance so they can complete onboarding without constant identity team involvement
  • Automated configuration output — where the information collected translates directly into a system-ready configuration file, eliminating the manual development step
  • Workflow visibility — a real-time pipeline view showing exactly where every application stands, from submission through production deployment
  • Consistent governance — birthright roles, pre-flight eligibility checks, SAR 2875 approval chains, and joiner/mover/leaver automation applied the same way to every application, every time

The Cost of Waiting

Federal identity teams that approach this migration the same way they’ve approached previous onboarding efforts — manually, one application at a time, with developer-dependent configuration — will not meet the deadline. The math doesn’t work at scale.

More importantly, the security risk compounds with every application that remains outside the centralized governance framework. Unmanaged entitlements, stale access, ungoverned accounts — every unmigrated application is a gap in the zero trust posture that the mandate is designed to close.

The 24-month window is not a suggestion. It is the timeline within which the DoD’s identity security posture will either modernize or fall further behind.

See How Onboard.id Was Built for This Mission

Onboard.id is the first purpose-built IGA application onboarding platform designed specifically for federal ICAM teams — with DoD-mandate-aligned intake, automated SailPoint IIQ configuration generation, and an AI assistant trained on your organization’s own architecture.

Request a demo at hello@onboard.id