Skip to main content
Home > MyID Product Family > MyID CMS Enterprise > MyID CMS Technical Features

MyID CMS
Technical Features

The technical capabilities of MyID CMS Enterprise: three-tier architecture, Certificate Authority (CA) connectors, HSM (Hardware Security Module) integration, Entra ID integration, credential types and REST API.

Architecture

Three-tier enterprise architecture, designed for scale

MyID CMS is built on a proven three-tier architecture separating presentation, business logic and data. Each tier can be independently scaled, from single-server pilots to deployments managing millions of credentials across distributed data centres.

Presentation tier Web console and REST API on Microsoft IIS
Logic tier Application components (COM+) and .NET services; credential policy engine
Data tier SQL Server / Azure SQL / Amazon RDS for SQL Server. HA supported
HA topology Load-balanced web and application channels; database failover clustering
Scalability Proven at enterprise scale
Offline mode Full operation without Internet connectivity

Presentation Tier

Browser-based MyID Operator Client, self-service enrolment, and the MyID Core API - all served on Microsoft IIS. Role-based operator access with scope and multi-factor sign-in (including passkeys and Entra ID). Scale out by adding web servers behind a load balancer - the most common way to grow a deployment.

Logic Tier

Credential policy engine, lifecycle workflow manager, CA connector hub and HSM interface layer, running as MyID application components (COM+) and .NET Core services. Horizontally scalable across multiple application servers.

Data Tier

Microsoft SQL Server, Azure SQL, or Amazon RDS for SQL Server. High availability through database failover clustering. Optional separate audit and archive databases.

HSM Layer

Hardware Security Module integration for credential signing operations, data protection and key ceremony events. Thales Luna and Entrust nShield supported natively.

CA Connector

Native integration with Microsoft CA ADCS, DigiCert ONE, Entrust and PrimeKey EJBCA. Multiple CAs simultaneously, on a single MyID instance.

Offline Engine

Full credential lifecycle operations without Internet connectivity. Essential for classified networks and air-gapped environments.

Modern Deployable Platform

MyID CMS runs its web services on Microsoft IIS with the ASP.NET Core runtime, on current Windows Server releases. Web and application tiers communicate over DCOM/COM+, with COM+ proxies supporting split-tier topologies where the web services sit on a separate server. A standalone authentication service provides FIDO sign-in.

Advanced Key Management

Reduce dependency on your certificate authority key escrow stores by using MyID CMS to manage storage and recovery of cryptographic keys for data encryption and decryption. When integrated with MyID SecureVault, you can generate or import these keys for safe storage, empowering you to centralize and consolidate this critical data without dependency on specific CA vendors.

Entra ID Integration

Built for Microsoft Entra ID

MyID CMS integrates with Microsoft Entra ID for user information, authentication, and passkey and certificate management - a two-way flow of information between your credential management system and your Entra ID tenant.

Entra ID as a Directory

Search for users in Entra ID, import them into MyID CMS and keep accounts synchronised, with customisable mappings between Entra ID and MyID user attributes.

Log in with Entra ID

Use Entra ID as an authentication provider via OpenID Connect (OIDC). Sign in to MyID with your Microsoft account - or bootstrap stronger credentials from a Temporary Access Pass (TAP).

Automatic Account Creation

Authenticate with Entra ID when collecting a self-service credential request and MyID CMS creates the account automatically - then issue a smart card, YubiKey, Windows Hello or mobile credentials, or register a passkey.

Roles from Security Groups

Assign MyID CMS roles automatically from a person's Entra ID security groups, and keep them in step as group membership changes.

Passkeys for Entra ID

Register FIDO2 passkeys for Entra ID through MyID CMS - with data validation, permissions, expiry dates and support for multiple tenants, cloud-only and hybrid - and synchronise passkeys issued elsewhere for full inventory and lifecycle management.

Certificate Sync

Notify Entra ID automatically when certificates are issued or cancelled, keeping certificate-based authentication information up to date.

API Reference

REST API, integrate with anything

The MyID Core API (REST, with an OpenAPI/Swagger definition provided) exposes the full MyID Operator Client feature set. Authenticate with OAuth2 - including a server-to-server client-credentials flow for automation - with every call governed by MyID roles and scope.

Representative Operations

  • Add or update a person and upload their photo
  • Request a device or credential and check request status
  • Import a certificate, or request key recovery for a person or to a device
  • List credential profiles; run and page reports
  • Manage directories and reassign devices
  • Event-driven integration

    Beyond the Core API - MyID pushes REST Web Service Notifications on lifecycle events - device issued, cancelled or reassigned; person added, edited, deleted, enabled or disabled; request added or updated; - so you can drive PACS, SIEM and workflow systems in real time. Mobile credentials and soft certificates are provisioned through a dedicated API.

    Build on the Core API

    New integrations should use the MyID Core API. The older Lifecycle, Credential Web Service, Device Management and Reporting Web Service APIs are end of sale in MyID CMS 2026.1 and are superseded by the Core API.

    MyID CMS

    Need the full technical specification?

    Download the MyID CMS technical datasheet for full hardware requirements, supported OS versions, CA connector versions and API documentation.