Skip to main content
Home > Solutions > Solutions by Deployment > On-Premise Full Infrastructure Control

On-Premise
Full Infrastructure Control

Deploy MyID Suite within your own infrastructure for maximum control, no cloud dependency and complete air-gap capability. The preferred deployment model for government, defence and critical infrastructure.

Key Capabilities

What this deployment model delivers

Your data centre, your rules

Every component of MyID Suite runs within your perimeter. No data leaves your network, and no external connectivity is required at any point in the credential lifecycle.

Air-gap capable

MyID® CMS and MyID MFA are proven in air-gapped defence and government deployments. The full credential lifecycle runs within your isolated environment, alongside the certificate authority CRL and OCSP services.

Standard Windows Server infrastructure

Runs on Windows Server 2022 or 2025. Uses your existing SQL Server (2022 or 2025), Azure SQL or Amazon RDS, and integrates with your Active Directory forest. No proprietary hardware or operating systems required.

Scale and resilience

Install across multiple servers with load balancing and a supported failover strategy. Scale the web and application tiers to meet demand, and configure your database and HSM for resilience.

Architecture components

Presentation Tier IIS web server, admin console, self-service portal
Logic Tier .NET runtime, policy engine, CA connector hub, HSM interface
Data Tier SQL Server 2022 or 2025, Azure SQL or Amazon RDS
HSM Layer Thales Luna, Entrust nShield. FIPS 140-2 Level 3
System requirements

Detailed platform requirements

Full server, operating system, database, HSM and client requirements for every MyID deployment are maintained in the Technical Overview, alongside the architecture and API detail.

View the Technical Overview →
Context

On-premise deployment, when data sovereignty is non-negotiable

On-premise deployment means every component of the credential management system runs within your own perimeter. No data leaves your network. For organisations with regulatory requirements that prohibit cloud processing, or operational environments with no external connectivity, on-premise is not a preference, it is a requirement. MyID CMS was designed for this model from the outset, with more than 25 years of deployment across environments from national health services to air-gapped defence and government networks.

Air-gap
Capable, zero external connectivity required
Air-gapped
Proven in defence and government deployments
FIPS 140-2 L3
HSM integration for key protection
Windows Server
Standard infrastructure, no proprietary OS
Frequently Asked Questions

Common questions

Need something specific? Contact our team →

MyID CMS on-premise runs on Windows Server 2022 or 2025, SQL Server 2022 or 2025 (or Azure SQL / Amazon RDS), and IIS, using .NET Framework 4.8 and .NET Core. Minimum 16 GB RAM and 4 cores for production. An HSM (Thales Luna or Entrust nShield) is optional but strongly recommended for production PKI deployments.

Yes. MyID can be installed across multiple servers with load balancing, and supports a failover strategy for resilience. The web and application tiers can be scaled out, and your database and HSM can be configured for high availability.

Yes. MyID on-premise integrates with Microsoft Entra ID (Azure AD) for FIDO2 provisioning, Azure AD Joined devices, and hybrid identity scenarios. The PKI and credential management stays on-premise; Entra ID handles cloud-native authentication policies.

Deployment · On-Premise

Deploy with full control and zero cloud dependency.

Our team has deployed MyID on-premise across defence, government, healthcare and financial-services environments. Book an architecture review to plan your deployment.