SSO for your Hybrid Cloud

F5 Ecosystem | April 12, 2017

In our recently released State of Application Delivery report, 80% of survey respondents said they employ a hybrid cloud strategy, meaning they have applications that reside in a combination of SaaS environments, on-premises, and in IaaS. Oftentimes, the question of lifting and shifting an on-prem legacy app to the cloud gets a quick answer: too expensive; can’t afford the opportunity cost. Dedicating your software developers’ already stretched time to an application that already works doesn’t usually compete with delivering new applications demanded by the business. To help frame the decision, do the math…

C = Current Annual Cost
(server/network hardware/software maintenance and licensing, power, application maintenance)

F = Future Annual Cost
(IaaS service/feature expenses, application maintenance)

D = Cost of Developers
(inc. QA and operations time necessary to make app cloud-ready)

L = Lifetime of the Application
(in years)


So, if D + FL > CL, the easy answer is, "well, if it ain’t broke..." But what if that simple math provides a different answer? What if it tells you that it would be worth re-architecting that app to move to the cloud? Then you need to weigh that against the opportunity cost of committing your developers’ time to a new application or new features to an existing application that would gain efficiencies and savings for the business. Another thing to consider: is the application the last hold-out tenant in a data center that is otherwise ready to shut down? The point is, there are several things to weigh when making the decision to lift and shift an app to the cloud.

Our State of Application Delivery report also told us that 47% of companies now have a cloud-first strategy, however that doesn’t mean they are free of the constraints and considerations noted above. No matter where your applications reside, access to ALL your applications should be simple and easy for your users, while also protecting user identities. F5 and our partners offer several choices of solutions to best fit the architecture that you choose, or in many cases, the architecture that you have inherited.

Benefits of a great SSO solution include a greatly reduced chance of credential theft, improved user experience and satisfaction, fewer calls to your helpdesk, centralized access logs, and more. F5’s SSO solution can end users’ burden of multiple points of access, by supporting SAML and OAuth federation for your cloud apps, and Kerberos or header-based authentication for your on-prem apps that don’t support SAML federation. This SSO solution also comes with powerful centralized access management that is easily achieved with our Visual Policy Editor.

F5 partners including OktaPing Identity, Microsoft Azure AD, and VMware all offer great SSO solutions as well. F5’s BIG-IP APM augments these solutions by consuming a SAML or OAuth assertion/token from these aforementioned Identity Providers, and translates it into a Kerberos or header-based authentication to your on-prem applications. Simply put, the BIG-IP APM extends the coverage of Identity-as-a-Service (IDaaS) providers to allow your users to connect to all apps from the same user experience. And as we all know, a consistent user experience is a key component of reducing the likelihood of credential theft through phishing.

So with F5, you have flexibility. You can extend on-prem authentication into the cloud, or cloud authentication into the data center while enhancing the security of both with SSO and additional custom access policies.

Related Content:
SSO to Legacy Web Applications

The Perimeter: An Identity Crisis

Credential Theft: Easy as Shooting Phish in a Barrel

Share
Tags: 2017

About the Author

Related Blog Posts

Accelerate Kubernetes and AI workloads with F5 BIG-IP and AWS EKS
F5 Ecosystem | 11/17/2025

Accelerate Kubernetes and AI workloads with F5 BIG-IP and AWS EKS

The F5 BIG-IP Next for Kubernetes software will soon be available in AWS Marketplace to accelerate managed Kubernetes performance on AWS EKS.

The everywhere attack surface: EDR in the network is no longer optional
F5 Ecosystem | 11/12/2025

The everywhere attack surface: EDR in the network is no longer optional

All endpoints can become an attacker’s entry point. That’s why your network needs true endpoint detection and response (EDR), delivered by F5 and CrowdStrike.

F5 NGINX Gateway Fabric is a certified solution for Red Hat OpenShift
F5 Ecosystem | 11/11/2025

F5 NGINX Gateway Fabric is a certified solution for Red Hat OpenShift

F5 collaborates with Red Hat to deliver a solution that combines the high-performance app delivery of F5 NGINX with Red Hat OpenShift’s enterprise Kubernetes capabilities.

F5 accelerates and secures AI inference at scale with NVIDIA Cloud Partner reference architecture
F5 Ecosystem | 10/28/2025

F5 accelerates and secures AI inference at scale with NVIDIA Cloud Partner reference architecture

F5’s inclusion within the NVIDIA Cloud Partner (NCP) reference architecture enables secure, high-performance AI infrastructure that scales efficiently to support advanced AI workloads.

F5 Silverline Mitigates Record-Breaking DDoS Attacks
F5 Ecosystem | 08/26/2021

F5 Silverline Mitigates Record-Breaking DDoS Attacks

Malicious attacks are increasing in scale and complexity, threatening to overwhelm and breach the internal resources of businesses globally. Often, these attacks combine high-volume traffic with stealthy, low-and-slow, application-targeted attack techniques, powered by either automated botnets or human-driven tools.

Phishing Attacks Soar 220% During COVID-19 Peak as Cybercriminal Opportunism Intensifies
F5 Ecosystem | 12/08/2020

Phishing Attacks Soar 220% During COVID-19 Peak as Cybercriminal Opportunism Intensifies

David Warburton, author of the F5 Labs 2020 Phishing and Fraud Report, describes how fraudsters are adapting to the pandemic and maps out the trends ahead in this video, with summary comments.

Deliver and Secure Every App
F5 application delivery and security solutions are built to ensure that every app and API deployed anywhere is fast, available, and secure. Learn how we can partner to deliver exceptional experiences every time.
Connect With Us