Three-tier enterprise architecture, designed for scale
MyID CMS is built on a proven three-tier architecture separating presentation, business logic and data. Each tier can be independently scaled, from single-server pilots to deployments managing millions of credentials across distributed data centres.
| Presentation tier | Web console and REST API on Microsoft IIS |
| Logic tier | Application components (COM+) and .NET services; credential policy engine |
| Data tier | SQL Server / Azure SQL / Amazon RDS for SQL Server. HA supported |
| HA topology | Load-balanced web and application channels; database failover clustering |
| Scalability | Proven at enterprise scale |
| Offline mode | Full operation without Internet connectivity |
Presentation Tier
Browser-based MyID Operator Client, self-service enrolment, and the MyID Core API - all served on Microsoft IIS. Role-based operator access with scope and multi-factor sign-in (including passkeys and Entra ID). Scale out by adding web servers behind a load balancer - the most common way to grow a deployment.
Logic Tier
Credential policy engine, lifecycle workflow manager, CA connector hub and HSM interface layer, running as MyID application components (COM+) and .NET Core services. Horizontally scalable across multiple application servers.
Data Tier
Microsoft SQL Server, Azure SQL, or Amazon RDS for SQL Server. High availability through database failover clustering. Optional separate audit and archive databases.
HSM Layer
Hardware Security Module integration for credential signing operations, data protection and key ceremony events. Thales Luna and Entrust nShield supported natively.
CA Connector
Native integration with Microsoft CA ADCS, DigiCert ONE, Entrust and PrimeKey EJBCA. Multiple CAs simultaneously, on a single MyID instance.
Offline Engine
Full credential lifecycle operations without Internet connectivity. Essential for classified networks and air-gapped environments.
Modern Deployable Platform
MyID CMS runs its web services on Microsoft IIS with the ASP.NET Core runtime, on current Windows Server releases. Web and application tiers communicate over DCOM/COM+, with COM+ proxies supporting split-tier topologies where the web services sit on a separate server. A standalone authentication service provides FIDO sign-in.
Advanced Key Management
Reduce dependency on your certificate authority key escrow stores by using MyID CMS to manage storage and recovery of cryptographic keys for data encryption and decryption. When integrated with MyID SecureVault, you can generate or import these keys for safe storage, empowering you to centralize and consolidate this critical data without dependency on specific CA vendors.
Built for Microsoft Entra ID
MyID CMS integrates with Microsoft Entra ID for user information, authentication, and passkey and certificate management - a two-way flow of information between your credential management system and your Entra ID tenant.
Entra ID as a Directory
Search for users in Entra ID, import them into MyID CMS and keep accounts synchronised, with customisable mappings between Entra ID and MyID user attributes.
Log in with Entra ID
Use Entra ID as an authentication provider via OpenID Connect (OIDC). Sign in to MyID with your Microsoft account - or bootstrap stronger credentials from a Temporary Access Pass (TAP).
Automatic Account Creation
Authenticate with Entra ID when collecting a self-service credential request and MyID CMS creates the account automatically - then issue a smart card, YubiKey, Windows Hello or mobile credentials, or register a passkey.
Roles from Security Groups
Assign MyID CMS roles automatically from a person's Entra ID security groups, and keep them in step as group membership changes.
Passkeys for Entra ID
Register FIDO2 passkeys for Entra ID through MyID CMS - with data validation, permissions, expiry dates and support for multiple tenants, cloud-only and hybrid - and synchronise passkeys issued elsewhere for full inventory and lifecycle management.
Certificate Sync
Notify Entra ID automatically when certificates are issued or cancelled, keeping certificate-based authentication information up to date.
REST API, integrate with anything
The MyID Core API (REST, with an OpenAPI/Swagger definition provided) exposes the full MyID Operator Client feature set. Authenticate with OAuth2 - including a server-to-server client-credentials flow for automation - with every call governed by MyID roles and scope.
Representative Operations
Event-driven integration
Beyond the Core API - MyID pushes REST Web Service Notifications on lifecycle events - device issued, cancelled or reassigned; person added, edited, deleted, enabled or disabled; request added or updated; - so you can drive PACS, SIEM and workflow systems in real time. Mobile credentials and soft certificates are provisioned through a dedicated API.
Build on the Core API
New integrations should use the MyID Core API. The older Lifecycle, Credential Web Service, Device Management and Reporting Web Service APIs are end of sale in MyID CMS 2026.1 and are superseded by the Core API.
Need the full technical specification?
Download the MyID CMS technical datasheet for full hardware requirements, supported OS versions, CA connector versions and API documentation.