Scaled Identity Sharing in R82.10
R82.10 introduces TLS-based Scaled Identity Sharing, increasing scalability from 20 PEPs per PDP to 300 PEPs per PDP while simplifying Identity Awareness deployments. It also adds support for direct cross-domain identity sharing between domains managed by the same Multi-Domain Security Management Server, eliminating the need for Identity Broker in many designs.
I put together the attached whitepaper to provide:
- A concise overview of the new architecture
- Traditional versus Scaled Identity Sharing comparisons
- Cross-domain deployment guidance
- Current limitations and supported topologies
- A streamlined six-step configuration workflow
- Required Management API commands and configuration screenshots
The paper is intended as a practical deployment guide in planning large-scale Identity Awareness implementations.
If you're evaluating Identity Awareness designs with many gateways, multiple domains, or existing Identity Broker deployments, this should help simplify the planning process.
Note: This guide is intended to be used with on-premise AD and not with direct integration of Entra ID or other external IdPs. Identity and Trust supports external IdPs. I'm planning a separate whitepaper about that topic later.
If you find errors with this document, let me know.