Just finished a global rollout. The promise was a single pane of glass for identity across our enterprise SaaS apps. Reality was a three-month firefight.
The big breaks:
* SSO to legacy on-prem apps choked on latency. Ping's proxies in one region couldn't handle the hop to our data centers in another. Timeouts became the norm.
* Just-in-time provisioning workflows failed silently when HRIS data contained null fields. No error in logs, just dead user accounts.
* The cost model exploded. We were quoted per "connection," but each environment (dev, staging, prod) for the same app counted as a separate connection. That's not how our procurement team understood it.
We stabilized it, but the ROI calculation looks terrible now. Anyone else hit these specific issues, or did we just set it up wrong?