Beyond Active Directory: NetIQ Access Manager & Okta with SharePoint 2016 | Alpachi Blog

Beyond Active Directory: Integrating NetIQ Access Manager and Okta with SharePoint for Enterprise Identity Management

A
Andre FigueroaCo-Founder & Principal Consultant
April 27, 20267 min read

Every enterprise we work with eventually runs into the same uncomfortable truth: their identity landscape is messier than their org chart suggests. An acquisition brought along a corporate LDAP directory that nobody wants to retire. A long-standing partner needs federated access. A modern business unit standardized on Okta while the rest of the company still lives in Active Directory. And somewhere in the middle of all of this sits SharePoint — the platform everyone needs to get into, and the one that historically assumed a single, tidy identity source.

The instinct in most IT shops is to force the mess to conform: replicate every user into AD, stand up sync jobs, manage shadow accounts, and hope nobody notices the seams. There's a better way. SharePoint is more flexible than it gets credit for, and with the right architecture it can welcome users from multiple identity providers without compromising the security model your governance team relies on.

The Solution at a Glance

Recently, Alpachi Consulting architected exactly that kind of solution for a client whose users were split across traditional Active Directory and a corporate LDAP directory fronted by NetIQ Access Manager (the identity platform formerly under the MicroFocus banner and now part of OpenText). The goal was simple to describe and deceptively complex to deliver: let every user — regardless of which directory they live in — sign into the same SharePoint farm with their existing credentials, and let SharePoint treat them as first-class citizens once they arrived.

The architecture pivots on SharePoint 2016 on-premises as the platform, with ADFS deployed as the federation broker at the center of the solution. NetIQ Access Manager serves as the identity provider for the corporate LDAP directory, while Okta is wired in as an additional identity provider option for business units that have already moved to it. WS-Federation passive authentication is the protocol that ties everything together, and LDAPCP is the claims provider that teaches SharePoint's people picker how to resolve users from both Active Directory and the corporate LDAP store.

In plain language, the flow looks like this: a user navigates to SharePoint, gets redirected to ADFS, and is presented with a choice of identity provider. If they pick the corporate directory, NetIQ authenticates them against LDAP and returns a signed assertion. ADFS receives that assertion, transforms the claims into the format SharePoint expects, and hands the user off. SharePoint sees a trusted claims identity, applies the right permissions, and the user lands on their site without ever knowing how many systems just collaborated on their behalf.

Why This Matters

The business value here is the kind that quietly compounds. Users authenticate with the credentials they already have — no new passwords to remember, no separate accounts to provision, no help desk tickets the first time someone forgets which login goes where. IT, in turn, is freed from the thankless work of replicating every LDAP user into Active Directory just to grant them SharePoint access. Identity stays where it belongs: in the directory that owns it.

The experience inside SharePoint is just as clean. The people picker resolves users from both Active Directory and the corporate LDAP directory, so site owners can grant permissions exactly the way they always have — by typing a name and picking the right person. Permissions, audiences, and sharing all continue to work against the standard SharePoint model, except now the underlying identities can come from anywhere the business actually keeps them.

Security teams keep the controls they care about. Because every authentication flows through ADFS, there's a single, auditable broker between SharePoint and the outside world. Adding a new identity provider — say, an Okta tenant for a newly acquired business unit — becomes a configuration exercise at the ADFS layer rather than a redesign of SharePoint itself. The platform scales to as many identity sources as the enterprise needs without the farm ever being touched again.

The Technical Elegance

What makes this approach durable is that it's built entirely on open standards. WS-Federation and SAML are doing the heavy lifting, which means the solution isn't tied to any one vendor's roadmap. The same pattern works whether the custom directory in question is eDirectory, OpenLDAP, or something more bespoke; whether the federation provider is NetIQ Access Manager, Okta, Ping, or a future replacement for any of them. ADFS becomes the universal translator between identity sources and SharePoint, and the SharePoint farm itself stays blissfully unaware of the diversity behind the curtain.

That separation of concerns is what makes the architecture worth investing in. Identity providers come and go, mergers reshuffle the directory landscape, and authentication standards evolve — but a well-designed claims architecture absorbs all of that without forcing a rebuild of the platform your business runs on.

Let's Talk About Your Identity Landscape

Every enterprise's identity story is a little different. Maybe you're absorbing a directory from a recent acquisition, opening SharePoint to a partner organization, modernizing around Okta while keeping AD in place, or simply trying to get a legacy LDAP system out of the critical path. Whatever the shape of it, there's almost always an architecture that lets your users authenticate the way they already do — without compromising security, governance, or the SharePoint experience your business depends on.

Alpachi Consulting has spent years architecting these kinds of solutions, and we'd genuinely enjoy hearing about yours. Reach out for a no-pressure conversation — bring the messy diagram, the awkward acquisition, the directory nobody wants to talk about. We'll help you think through what's possible.

Have a Complex Identity Landscape?

Whether you're dealing with a corporate acquisition, a partner directory, a legacy LDAP system, or multiple identity providers, Alpachi Consulting has the expertise to architect the right authentication solution for your SharePoint environment. We'd love to hear about your specific situation — reach out for a no-pressure conversation.