- Axiad’s Andrew Sheedy has outlined new options that could improve government credential management
- Automation could ease IT burden and close machine identity security gaps
- Axiad Conductor could support credential lifecycle management and quantum-safe migration
Andrew Sheedy, director of federal at Axiad, said the federal government is starting to approve modern authentication technologies that could make it easier to balance security and convenience.
In an article published on Carahsoft.com, Sheedy wrote that credential lifecycle management is a core part of any zero trust strategy. He noted that employees and contractors often carry multiple authenticators, such as a Personal Identity Verification, or PIV, card, a common access card, or a Derived PIV Credential.
How Can New Authentication Options Ease Security Trade-Offs?
Sheedy wrote that a Fast Identity Online 2, or FIDO2, credential could offer a better user experience for cases that do not need the highest levels of assurance. He added that agencies could also issue Derived PIV Credentials to different form factors, including mobile devices and security keys.
How Should Agencies Manage & Secure Machine Identities?
Sheedy stated that machine entities on a network usually outnumber human users. He said automating machine identity management as much as possible could reduce the load on IT teams and minimize security gaps.
“When paired with good governance and in-house expertise, automation takes a lot of error out of the process for both human users and machine entities,” Sheedy wrote.
He noted that each agency is responsible for securing its own resources since no outside authority may be able to enforce compliance inside an agency’s own network.
Sheedy explained that agencies should also review the security, governance and resilience of the internal public key infrastructure, or PKI, that issues these identities. He mentioned several questions agencies should ask, including whether they have sufficient in-house expertise, whether certificate authorities are hardened against rogue administrators or insider threats, whether a disaster recovery plan exists and whether certificate lifecycle automation has been implemented.
What Is Axiad Conductor?
Sheedy said Axiad Conductor is a FedRAMP-authorized cloud-native credential management system, or CMS, and PKI-as-a-service offering that could deliver seamless coverage across an agency’s ecosystem of Derived PIV Credentials, smart cards, security keys and devices.
According to Sheedy, Conductor could integrate with existing identity providers and ecosystem components to support low-friction adoption. He added that the platform could cover “credential gap” use cases such as privileged user access, interim credentials and visitor access control badges.
Sheedy explained that Conductor also includes a customizable PKI-as-a-service offering that could modernize legacy on-premises PKI systems. He noted that this could remove the need for expensive infrastructure and hardware security modules and could automate certificate distribution through a unified service that supports smooth migration and quantum-safe algorithms.













