top of page


DTM 25-003 User Attribute Federation: Building DoD ZTA CoA-Aligned ICAM Foundations
Most DoD Zero Trust programs do not stall on conditional user access because the identity provider cannot talk to the application. Under ATO pressure, with PPBE cycles already locked and mission owners protecting operational timelines, teams often connect IdPs first and clean up attribute governance later. DTM 25-003 does not support that sequence. Conditional access depends on trusted, federated, policy-usable attributes from the start.
Jul 86 min read


Enterprise ICAM Implementation for CISA ZTMM Conditional Access Requirements Under OMB M-22-09
Conditional user access is not an MFA project. To meet OMB M-22-09, it is an enterprise ICAM operating model tied to attributes, privileged access, policy enforcement, monitoring, and ATO boundaries. Agencies are trying to build that while operating under continuing resolution uncertainty, lean IT staffing, FedRAMP procurement constraints, and production systems that cannot be taken offline for identity redesign. This blog details how to get it right with the right sequencing
Jun 116 min read
bottom of page
