The White House Office of Management and Budget (OMB) recently delivered a major directive to U.S. federal leadership, establishing Login.gov as the primary authentication option across all public-facing federal websites.
The policy directive introduces aggressive compliance milestones, directing agencies to inventory authenticated portals within 60 days, conduct comprehensive digital identity risk assessments within 240 days, and achieve full operational rollout within two years.
OMB's directive shifts digital identity consolidation from a distant agency aspiration into a concrete compliance mandate, forcing leaders to modernize legacy architectures while defending the public edge.
Operational hurdles
The mandate requires agencies to promote Login.gov as the default identity provider (IdP) for citizen authentication, while continuing to support approved commercial Credential Service Providers (CSPs) for specific mission requirements.
For agency CIOs, CISOs, and enterprise architects, this presents a dual challenge: complying with strict timelines while integrating a modern OpenID Connect (OIDC) and SAML identity provider across a complex infrastructure.
“F5 simplifies compliance by providing an identity brokerage and edge security architecture integrated directly into the F5 Application Delivery and Security Platform (ADSP).”
Most federal digital infrastructure is not designed for direct OIDC integration. Thousands of mission-critical applications rely on legacy authentication mechanisms (such as Kerberos, HTTP header injection, and proprietary session tokens) that cannot natively parse assertions from modern IdPs without extensive code refactoring.
At the same time, centralizing citizen traffic onto public authentication workflows creates high-value targets for AI-driven and automated attacks, such as credential stuffing, account takeover, and synthetic identity fraud, targeting agency registration endpoints before the authentication handshake even occurs.
The compliance roadmap
The OMB directive outlines four critical implementation milestones across a two-year horizon:
- Within 60 Days (Website & API discovery): Agencies must provide OMB with a validated inventory of all public-facing websites, web applications, and APIs requiring user authentication.
- Within 240 Days (Digital identity risk assessment): Agencies must evaluate authentication resilience, identity proofing workflows, and fraud vulnerabilities across all public entry points.
- Within one year (Multi-provider coexistence): Agencies must adopt General Service Administration Login.gov best practices, establish Login.gov as the default option, and maintain coexistence with approved commercial CSPs (such as ID.me or CLEAR) for specialized user populations.
- Within two years (Full operational rollout): Agencies must ensure full deployment of Login.gov across all in-scope public-facing federal systems.
Navigating these transitions with F5
F5 simplifies compliance by providing an identity brokerage and edge security architecture integrated directly into the F5 Application Delivery and Security Platform (ADSP). Instead of requiring agencies to re-architect applications manually, F5 acts as a centralized policy enforcement point and protocol bridge directly in the data path to help agencies achieve:
- Automated discovery and surface mapping (60-day milestone): F5 API security and F5 Distributed Cloud Web App Scanning can automatically discover and catalog public-facing web applications, endpoints, and shadow APIs across hybrid and multicloud environments. Paired with telemetry from F5 Insight for ADSP, agencies can generate comprehensive, audited inventories of authenticated surfaces without modifying underlying code.
- Pre-authentication fraud and bot management (240-day milestone): F5 Distributed Cloud Bot Defense applies behavioral AI telemetry at the application edge to stop automated credential stuffing, brute-force attacks, and fake registration attempts before traffic reaches Login.gov or agency servers. F5 WAAP continuously monitors traffic and inspects API authentication flows, delivering quantifiable telemetry for agency risk assessments.
- Identity brokerage and multi-IdP federation (One-year milestone): F5 BIG-IP Zero Trust Access functions as an intelligent identity federation gateway. The solution directs new users to Login.gov by default while routing specific high-assurance or legacy workflows to approved commercial CSPs, enforcing unified authorization policies across disparate upstream providers.
- Legacy protocol bridging without rearchitecting (Two-year milestone): BIG-IP Zero Trust Access terminates Login.gov OIDC and SAML assertions at the ingress proxy and translates them into Kerberos (KCD), HTTP headers, or RADIUS sessions required by legacy backends. For high-assurance, defense, and intelligence agencies, F5 VELOS and F5 rSeries chassis deliver FIPS 140-2/3 and DoDIN APL certified performance for sovereign and air-gapped deployments.
The right tools for the timeline
The OMB mandate makes one thing clear: digital identity consolidation is an immediate operational priority. Agencies that prepare early by cataloging authentication endpoints, automating edge bot protection, and implementing identity-aware protocol bridging will navigate these transitions seamlessly long before compliance deadlines arrive.
Explore how these and other F5 public sector solutions help federal agencies meet evolving compliance mandates and accelerate their infrastructure modernization efforts.
About the Author

Related Blog Posts

Securing the new control points in the AI journey
AI architecture is fundamentally different than traditional IT environments and requires a different security strategy to protect critical AI workloads.

The patch window has closed. Here is how F5 is built for what comes next.
As AI models have changed software security, the industry needs to adapt.

Best practices for optimizing AI infrastructure at scale
Optimizing AI infrastructure isn’t about chasing peak performance benchmarks. It’s about designing for stability, resiliency, security, and operational clarity

Datos Insights: Securing APIs and multicloud in financial services
New threat analysis from Datos Insights highlights actionable recommendations for API and web application security in the financial services sector

Secrets to scaling AI-ready, secure SaaS
Learn how secure SaaS scales with application delivery, security, observability, and XOps.

How AI inference changes application delivery
Learn how AI inference reshapes application delivery by redefining performance, availability, and reliability, and why traditional approaches no longer suffice.