Skip to content
Insights
Request Services
← All OSS projects

Infrastructure as Code · Apache 2.0

terraform-iam-baseline

Production-ready Terraform modules for IAM baseline across Okta, Microsoft Entra ID, and AWS IAM Identity Center.

View on GitHub →HCL (Terraform)

About

Opinionated Terraform module set establishing IAM baseline configurations for the three most-deployed workforce identity platforms: Okta tenant baseline (sign-on policies, MFA factors, group structure, application catalog), Microsoft Entra ID Conditional Access baseline (named locations, risk-based policies, compliance device requirement), and AWS IAM Identity Center baseline (permission sets, account assignments, SAML integrations).

Designed as a starting point for IAM-as-code programs: forkable, parameterized, with sensible defaults derived from baseline hardening guidance (CIS, NIST 800-53, Okta + Microsoft published recommendations).

Features

  • →Okta tenant baseline — sign-on policies, MFA factors, group structure
  • →Microsoft Entra ID Conditional Access baseline — named locations, risk policies, device compliance
  • →AWS IAM Identity Center baseline — permission sets, account assignments, SAML
  • →Configurable defaults aligned with CIS + NIST baselines
  • →Per-environment overlays (dev / staging / production)
  • →CI examples (GitHub Actions, GitLab CI, Terraform Cloud)

Install

module "okta_baseline" {
  source  = "askmeidentity/iam-baseline/okta"
  version = "~> 1.0"

  tenant_domain    = "acme.okta.com"
  admin_email      = "[email protected]"
  enforce_mfa      = true
  phishing_resistant_admin = true
}

Usage

Drop the module into an existing Terraform repo, set the required variables, and apply. The module is idempotent and safe to re-apply against existing tenants.

Related resources

  • Insight: 7 deadliest IAM misconfigurations →
  • IAM Audit Checklist hub →
Last reviewed: 2026-05-26

Identity, cybersecurity, and custom software for regulated enterprises. Audit-ready operations from advisory through audit.

Americas HQ

Wilmington, DE

America/New York

India HQ

Hyderabad, TG

Asia/Kolkata

Services
  • IAM Consulting
  • IAM Technologies
  • Custom Software & AI
  • IAM Staffing
  • Request Services
  • Case Studies
Resources
  • All Resources
  • Complete Guide to IAM
  • IAM Frameworks Compared
  • IAM Certification Roadmap
  • IAM API Hub
  • IAM Explainers
  • IAM Vendor Status
  • Release Notes
  • State of Identity
  • State of PAM
  • State of IGA
  • State of CIAM
  • State of AI Agent Identity
  • IAM Salary Benchmark
  • Vendor Pricing Index
  • Year in Review 2026
  • Acquisition Tracker
  • Outage Tracker
  • Identity Incidents
  • Vulnerability Tracker
  • Cheat Sheets
  • Standards Explainers
  • Migration Playbooks
  • Audit Checklists
  • Reference Architectures
  • RFP Templates
  • IAM Anti-Patterns
  • Compliance Crosswalk
  • Market Landscape
  • Awesome IAM
  • IAM Glossary
  • Compliance Frameworks
  • Integration Guides
  • Vendor Alternatives
  • IAM by Industry
  • Salary Lookup
  • Directory
Research & media
  • IAM Compensation 2026
  • Vendor Moves Q3 2026
  • Identity Incidents Q3 2026
  • Vendor Security Posture 2026
  • Vendor Pricing 2026
  • AI Citation Tracker
  • Top 50 IAM Tools 2026
  • Podcast
  • Videos
  • Newsletter
  • Newsletter Archive
  • Embed Widgets
Free tools
  • JWT Decoder
  • JWT Signer
  • SAML Decoder
  • SAML Metadata Diff
  • OAuth Flow Visualizer
  • OIDC Debugger
  • OIDC Discovery Validator
  • PKCE Generator
  • WebAuthn Tester
  • Bearer Token Inspector
  • SCIM Validator
  • Password Entropy
  • IAM RFP Template
  • PAM Vendor Selector
  • Maturity Assessment
  • ROI Calculator
  • TCO Calculator
  • MFA Bypass Risk
  • Audit-Prep Burden
  • Quizzes
Company
  • About
  • Leadership
  • Approach
  • Why Choose Us
  • Partners
  • Press Kit
  • Press Topics
  • Global Presence
  • Locations
  • Insights
  • Now
  • Community
  • Open Roles
  • Submit Resume
  • Training
  • Contact

© 2026 askmeidentity, Inc.. Safeguard your digital frontier.

  • Privacy Policy
  • Terms of Service
  • Accessibility