As cyber threats continue to evolve in both scale and sophistication, the telecommunications industry faces a unique and pressing challenge: securing the infrastructure that underpins global communication.
Messaging platforms like the TC6000 are not just applications—they are critical components of national and enterprise infrastructure. As a result, identity and access management have become central to maintaining both security and operational integrity.
At Openmind Networks, we are evolving the TC6000 platform to align with modern Zero Trust security principles, moving away from traditional, localized authentication models toward a centralized identity architecture that reflects how enterprises now operate.
Understanding the Bigger Picture: Identity, Zero Trust, and Telecoms
Zero Trust is often summarized as “never trust, always verify,” but in practice it represents a fundamental shift in how systems are secured. Instead of assuming that users or systems inside a network are trustworthy, every access request must be explicitly validated, regardless of where it originates. Identity becomes the primary control point, replacing the old notion of a secure network perimeter.
This shift is particularly important in telecoms environments. Infrastructure is inherently distributed, often spanning multiple regions, vendors, and operational domains. Engineers, partners, and third-party vendors may all require access to sensitive systems, and the consequences of a breach can be far-reaching. In this context, relying on implicit trust or fragmented authentication models is no longer viable—centralized, identity-driven security is essential.
Key Concepts and Definitions
To understand this shift, it helps to clarify a few key concepts that underpin modern identity architecture.
An Identity Provider (IdP) is a centralized system responsible for authenticating users and asserting their identity. Rather than each application maintaining its own user database, the IdP becomes the single source of truth. Platforms such as Microsoft Entra ID are widely used in this role, providing not just authentication but also advanced security controls like conditional access and risk-based policies.
A Service Provider (SP), by contrast, is an application or platform that relies on the IdP to authenticate users. The TC6000 can now operate in this role. It no longer manages credentials directly, but instead trusts the identity assertions provided by your organisation’s IdP.
This model enables Single Sign-On (SSO), where users authenticate once through the IdP and gain access to multiple systems without repeated logins. It also allows organisations to enforce Multi-Factor Authentication (MFA) centrally, requiring users to provide additional verification—such as a mobile prompt, biometric factor, or hardware key—before access is granted.
Under the hood, these interactions are powered by standard protocols. OpenID Connect (OIDC) is commonly used in modern, cloud-based environments, while Kerberos remains a cornerstone of many on-premise Active Directory deployments. Together, these standards ensure interoperability and future-proofing.
Finally, Just-in-Time (JiT) Provisioning removes the need for manual user creation by automatically generating accounts when a user first logs in, using identity information provided by the IdP.
The Problem with “Identity Islands”
Historically, many telecom platforms—including messaging systems—managed authentication locally. Each system maintained its own user database, password policies, and often its own implementation of two-factor authentication. While this approach may have been sufficient in simpler environments, it introduces significant risk at scale.
When identity is fragmented across systems, it becomes difficult to ensure consistency and control. Users who leave an organisation may retain access in one system but not another. Engineers are forced to manage multiple credentials, increasing the likelihood of password reuse or insecure storage practices. From a governance perspective, demonstrating compliance with standards such as ISO 27001 or SOC 2 becomes far more complex when identity data is distributed and difficult to audit.
These “identity islands” are fundamentally at odds with Zero Trust principles, which depend on a single, authoritative view of identity and access.
The Solution: Strategic Centralization
To address these challenges, the TC6000 now operates as a Service Provider, delegating authentication entirely to your organisation’s Identity Provider. This is not just a technical change, but a strategic one: it aligns the platform with how modern enterprises manage identity and security.
By centralizing authentication, the TC6000 inherits the full capabilities of your existing identity platform. This includes advanced authentication methods such as biometrics and passwordless login, as well as hardware-backed credentials like FIDO2 security keys. It also enables the enforcement of conditional access policies, where decisions about access can take into account factors such as user location, device posture, and real-time risk signals.
Crucially, this approach eliminates the need for custom-built authentication logic within the platform itself, reducing both complexity and potential attack surface.
Why We Delegate MFA to the Experts
A common question is whether MFA should be implemented directly within the TC6000 interface. While this might seem like an added layer of security, in practice it often has the opposite effect.
In most enterprise environments, users are already required to complete MFA when accessing corporate systems via the IdP. Introducing an additional MFA prompt at the application level creates redundancy and contributes to what is often referred to as “MFA fatigue.” When users are prompted too frequently, they become desensitized, which can ultimately weaken security.
More importantly, modern Identity Providers offer capabilities that go far beyond simple second-factor verification. Platforms like Microsoft Entra ID use advanced analytics to detect suspicious behaviour, such as login attempts from geographically distant locations within a short timeframe or the use of credentials known to have been compromised. These systems can adapt authentication requirements dynamically based on risk—something that a localized MFA implementation within a messaging platform cannot realistically replicate.
By delegating MFA to the IdP, the TC6000 benefits from these continuously evolving protections without needing to replicate them.
Streamlining Operations with Just-in-Time Provisioning
Security improvements are only effective if they do not hinder operational efficiency. In high-performance telecom environments, manual user management quickly becomes a bottleneck.
The TC6000 addresses this through Just-in-Time Provisioning, which allows user accounts to be created automatically when a user logs in for the first time via the IdP. At that point, the platform reads roles and group memberships directly from the authentication token, ensuring that permissions are always aligned with the central directory.
This approach eliminates the need for manual provisioning while also reducing the risk of configuration drift. Users are always granted the appropriate level of access based on their current role, and any changes made in the central identity system are reflected immediately.
To maintain strict security boundaries, all JiT-provisioned users are treated as external identities within the platform. They are prevented from using local credentials, ensuring that all access flows through the centralized SSO mechanism.
Moving Toward a Passwordless Future
As identity systems continue to evolve, the industry is moving steadily toward passwordless authentication. In this model, traditional passwords are replaced by more secure and user-friendly mechanisms such as biometrics or cryptographic keys.
For TC6000 deployments, we recommend disabling local password-based access for all non-emergency accounts. This enforces 100% SSO usage and ensures that the central identity system remains the single point of control.
The operational benefit of this approach is significant. When a user leaves the organisation or changes roles, access can be revoked instantly and globally by updating their status in the IdP. There is no need to track down and disable accounts across multiple systems.
Built for Hybrid and Evolving Environments
We recognise that telecom environments are rarely uniform. Some organisations operate fully in the cloud, leveraging platforms like Microsoft Entra ID and modern protocols such as OIDC and OAuth 2.0. Others maintain deep integrations with on-premise Active Directory systems using Kerberos.
The TC6000 is designed to operate seamlessly across these environments. Its protocol-agnostic architecture ensures that it can integrate with both modern and legacy identity systems, allowing organisations to evolve their security posture without disrupting operations.
Conclusion
The shift to Zero Trust is not a theoretical exercise—it is a practical necessity for securing modern telecom infrastructure. As identity becomes the primary security boundary, platforms must adapt by integrating with centralized, enterprise-grade identity systems.
By operating as a Service Provider and delegating authentication to your Identity Provider, the TC6000 achieves a higher level of security, simplifies operations, and aligns with industry best practices. It becomes not just a messaging platform, but a secure and resilient component of your broader enterprise architecture.
Ready to secure your messaging infrastructure?
Contact our team to learn more about deploying the TC6000 with centralized Identity Management.