Identity & Access Management Engineer · Okta Certified Consultant

Deepan Udaiyar

I design authentication and lifecycle as one model: phishing-resistant by default, with device trust proven rather than asserted.

About me

You cannot define a problem you cannot see.


Most of my work begins by making an environment legible before changing it. I'm an identity and access management engineer with ten years in IT and seven hands-on with Okta, currently owning identity architecture across a multi-organisation, multi-geo environment. I design authentication and lifecycle as one model rather than per application: phishing-resistant by default, device trust proven rather than asserted, and joiner/mover/leaver driven from an HRIS instead of a ticket queue.


A lot of the work I value most is subtraction: an Active Directory decommission with no cutover downtime, a 500-form access-request build replaced by a single metadata-driven form, five Atlassian tenants consolidated into one. The right answer is usually the simplest one that survives scrutiny; it just isn't visible while everything else is in the way.


Outside work, I'm usually in the mountains of British Columbia, and occasionally on an indoor climbing wall.

Work Experience

IT Systems & Integration Engineer
EarthDaily Analytics
Aug 2024 – Present

Designed the authentication policy architecture for a phishing-resistant MFA programme: a device-trust ladder across every sign-in surface, with tiered enrollment so no population needs a standing exception.

Led an end-to-end Active Directory decoupling and decommission in two months with no cutover downtime, using a self-service, user-paced conversion. Published the six-phase methodology publicly.

Integrated identity through acquisition: tenant consolidation with application group modelling and a native cross-tenant mailbox migration.

Standardised SSO and SCIM lifecycle provisioning across the SaaS estate, with an HRIS as the authoritative identity source driving joiner/mover/leaver.

Principal Consultant, Identity & Access Management
MU Tech Inc.
2025 – Present

Deliver identity engagements under signed statements of work and agency contracts: assessment, implementation, and ongoing managed support.

Delivered a phishing-resistant Okta baseline removing all password-only authentication paths, SCIM provisioning across five applications, and an HRIS as the authoritative profile source.

Delivered Entra ID hardening for a second client: Conditional Access baseline, PIM for privileged roles, and administrative account separation.

Contracted to ATB Financial (via Raise Recruiting): replaced a planned 500-form ServiceNow build, one form per application, with a single request form driven by a master metadata table, so onboarding an application became a metadata entry rather than a build. Automated directory group provisioning and deprovisioning from approved requests, delivered in under two months on a programme that had not shipped in over a year.

Senior Consultant, Delivery
T-Mobile, via TechDemocracy
Mar 2022 – Apr 2024

Supported and advised on a 10,000+ user enterprise Okta tenant spanning hundreds of applications, resolving cross-tenant provisioning failures, MFA issues, and SAML sign-in faults.

Advised on application assignment strategy, profile optimisation, and Entra integration; governed service principals and privileged accounts across Azure and Okta.

IT Support Specialist
Dialpad Inc.
Sep 2019 – Mar 2022

Sole owner of identity integration during the Highfive acquisition; engineered an onboarding pipeline that provisioned 50+ employees with zero manual intervention.

Integrated 10+ business applications into Okta via SAML and SCIM through a period in which headcount roughly doubled; automated Google Workspace offboarding.

Earlier Roles
2016 – 2019

Systems Support Specialist, The Peak Group of Companies (2019)

IT Support Analyst, Sleep Country Canada (2017 – 2019)

Technical Support Analyst, IBM (2016 – 2017)

Active Directory administration for enterprise clients including Scotiabank and Irving Oil, to the change-control standards of a regulated bank.

Education & Certifications

Okta Certified Consultant
Okta
2021 – 2023

Okta Certified Administrator
Okta
2021 – 2023

Okta Certified Professional
Okta
2021 – 2023

HashiCorp Terraform Associate
HashiCorp
2022 – 2024

AWS Certified Cloud Practitioner
Amazon Web Services
2022 – 2025

Computer Systems Networking Diploma
Centennial College
2013 – 2015

Skills & Expertise

The identity, authentication, and automation stack I build with.

Identity & Access Management

Okta (OIE, FastPass, Workflows, IGA), Microsoft Entra ID, Microsoft 365, Active Directory, AD Connect / DirSync, Privileged Access (PIM)

Authentication & Zero Trust

Phishing-Resistant MFA, Authentication & Enrollment Policy Design, Device Trust, WebAuthn / Passkeys, Conditional Access

Protocols & Standards

SAML 2.0, SCIM, OIDC, OAuth 2.0, SCEP

Lifecycle & Automation

Okta Workflows, Joiner/Mover/Leaver, Attribute Mapping, Cross-Tenant Migration, Python, PowerShell, Bash, Microsoft Graph API

HRIS & Lifecycle Sources

BambooHR, HiBob, HR-Driven Provisioning, Access Governance, Import Safeguards, Staged Cutover

SaaS Integration & Administration

Google Workspace, Slack, GitHub / GitLab, Atlassian, 1Password, Microsoft 365, License & Group Governance

Featured Projects

The identity work I'm proudest of.

Phishing-Resistant Authentication Programme

Designed the authentication policy architecture behind a phishing-resistant MFA programme: a device-trust ladder where sign-in friction scales inversely with attested device trust. Recovery and enrollment are treated as part of the authentication boundary rather than as support workflows, because the back doors matter more than the front door. Built a Python pipeline against the identity provider's APIs to measure and prove enrollment and device-trust posture.

Okta FastPass Phishing-Resistant MFA WebAuthn / Passkeys Device Trust Python

Active Directory Decoupling & Decommission

Led an end-to-end Active Directory decommission with no cutover downtime. Directory migrations fail at the cutover window, so this one removed the window: users converted themselves at their own pace, driven by an Okta Workflow that unassigned the directory link and issued a temporary credential. Written up and published as a public six-phase methodology.

Active Directory Okta Workflows Microsoft Entra ID Directory Migration PowerShell Microsoft Graph API

Enterprise RBAC & Access Request Redesign

Replaced a planned 500-form access-request build, one form per application, with a single request form driven by a master metadata table, so onboarding a new application became a metadata entry rather than a development task. Automated directory group provisioning and deprovisioning straight from approved requests. Delivered in under two months on a programme that had not shipped in over a year.

RBAC ServiceNow Access Governance Okta Workflows Active Directory Identity Lifecycle

Atlassian Estate Consolidation

Consolidated five Atlassian instances into a single environment, delivered single-handedly and in-house. The decision that shaped the project was recognising that the built-in cloud-to-cloud transfer tooling could handle the data movement, so the real work was the configuration the tools don't cover plus stakeholder coordination, not raw engineering effort. I ran it as per-tenant playbooks with a named stakeholder and dedicated channel for each, phased the cutovers, and version-controlled the repetitive pipeline steps, then enforced SSO and connected SCIM provisioning once the tenants were merged.

Atlassian Cloud SSO SCIM Okta Stakeholder Management Automation

M&A Identity Integration

Integrated identity through three acquisitions across two employers: merged acquisition Okta tenants with dozens of applications in under a month, ran a native cross-tenant mailbox migration that preserved directory identifiers and mail routing, and built a zero-touch onboarding pipeline that provisioned new employees with no manual intervention.

M&A Integration Okta Exchange Online Cross-Tenant Migration Microsoft 365 Identity Mapping Bash

SSO & Lifecycle Standardisation

Brought the SaaS estate onto consistent federation and lifecycle patterns: dozens of integrations with automated licence assignment, SAML group sync, and automated deprovisioning, with an HRIS as the authoritative identity source driving joiner/mover/leaver across the application estate.

SAML SCIM Okta Microsoft 365 HRIS Integration Identity Lifecycle

Let's Connect

Working on an identity or IAM transformation, or need a second opinion on an Okta or Entra design? I'm always open to a conversation.