Juniper Square builds fintech AI readiness by leveraging Okta for continuous identity governance

100%

phishing-resistant authentication from day one using Okta FastPass

260k+

identity lifecycle actions automated per month with Okta Workflows

175+

SSO applications centralized and secured for 1,300+ remote employees

1,150

hours of IT effort saved by automating access requests

"OIG reminds me to review. Without a nice interface telling me the role, the user, and when they got access, I'd have to go through my Slack history and Jira tickets. When I show auditors the evidence, it’s all accounted for.”

Shen Ming Mah,

Staff IT Systems Administrator, Juniper Square

In the financial technology sector, a single security breach can dissolve customer trust in an instant. Juniper Square — a platform that provides technology, data, and administration services for the private funds industry — understands those stakes intimately. As the company rapidly scaled to more than 1,300 fully remote employees who manage sensitive financial statements, they needed to achieve SOC 2 compliance and replace their fragmented, manual security practices.

"Before Okta, it felt impossible for my team to stay ahead while addressing existing challenges," says Shen Ming Mah, staff IT systems administrator at Juniper Square. “We knew we needed to standardize password management to keep accounts safe from phishing attempts without complicating the login experience."

At the time, the lean IT team of 12 managed a time-consuming onboarding process, manually checking off a 200-task Asana list to determine which apps a new hire needed. Going all-in on Okta, Juniper Square deployed Okta Workforce Identity to establish a unified identity security fabric as the foundation of modern enterprise security. By centralizing 175+ applications behind Universal Directory and Single Sign-On, Juniper Square instantly modernized its security posture.

“I launched Okta to be 100% phishing-resistant from day one," Mah says. "The only MFA methods I've ever allowed are YubiKey and Okta FastPass."

Automating lifecycle management and AWS infrastructure access

To scale efficiently, Juniper Square integrated Okta directly with its HR system, HiBob, to drive granular role-based access control (RBAC). Today, the team executes more than 260k flows in Okta Workflows every month to completely automate the onboarding and offboarding lifecycle.

This automation extends into Juniper Square's most critical foundational infrastructure: Amazon Web Services (AWS). Previously, a new engineer might receive basic AWS console access but couldn't see the specific development environments necessary for their job, forcing them to submit IT tickets and wait for manual approvals.

Now, Okta Workflows maps HR attributes — including business unit, department, and function — directly to AWS push groups. "Okta will add users to the appropriate groups, and those AWS push groups will confer the correct role they need in order to do their job on day one," Mah explains. Together, these automations have saved Juniper Square more than 1,150 hours of IT effort — or the equivalent of more than six months of full-time IT admin work — all within the first year.

Workflows also mitigates security risks during offboarding. For instance, Juniper Square  manages highly sensitive customer financial data. If a departing employee's account is simply deactivated, all of their shared client files would become inaccessible. Okta Workflows now automatically transfers the departing employee's files to their manager, ensuring seamless business continuity and preventing client disruptions, before locking the device.

A single pane of glass for continuous, security-driven governance

With just 12 people supporting 1,300+ employees, manual audits had become impossible. Juniper Square deployed Okta Identity Governance (OIG) and Identity Threat Protection (ITP) to provide a single pane of glass for all access, expanding governance from a compliance requirement to a proactive security function.

In addition to quarterly review cycles, Juniper Square evaluates access on an ongoing basis. Using HiBob, OIG triggers automated user access campaigns the moment an employee's business unit, department, function, or group changes.

"OIG reminds me to review. Without a nice interface telling me the role, the user, and when they got access, I'd have to go through my Slack history and Jira tickets," Mah says. "When I show auditors the evidence, it’s all accounted for.”

Moving beyond a point-in-time compliance exercise, continuous access reviews allow the IT team to easily investigate and mitigate over-privileged access in real time. By placing apps like Dialpad, Box, and AWS behind self-service OIG access requests via Slack, Juniper Square avoids unnecessary software license provisioning, removes standing privileges, and saves on costs.

The company also uses ITP to ingest continuous risk signals from their security stack —including CrowdStrike and Cloudflare — and also communicate risk scores back to Omnissa to take more informed action. If a high-risk event is detected, such as a stolen session token, Okta triggers a universal logout and alerts the IT team via Slack. By taking a broad, consolidated approach to identity security, the lean IT team saves hours of manual review time.

Preparing for an AI-powered future

Looking ahead, Juniper Square is exploring Okta Device Access to secure desktop logins, and plans to further bridge their governance and threat protection tools. This is further strengthened by transitioning to fully biometric-based FastPass use through Okta Verify, so employees will always have Okta access without any concern of password-based attacks. As their identity security fabric matures, they plan to use continuous risk signals from ITP to automatically trigger OIG recertification campaigns.

Their immediate focus, however, is on securing identity in the AI era. Recently, Juniper Square rolled out company-wide access  to a full suite of AI tools. This resulted in a massive surge of IT requests to connect various MCP servers and SaaS apps to AI agents. It also led to a "shadow AI" loophole. When employees want to do something badly enough, they tend to look for ways around security, and the Juniper Square team needed a strategy for non-human identities to scale AI securely without blocking the rest of the organization.

To safely close this gap and manage the growing ratio of non-human to human identities, Juniper Square is evaluating Okta for AI Agents to provide centralized visibility and strict access controls over what these autonomous agents can do.

"Being able to control what the AI agent account can or cannot do when it's interacting with other apps is really promising," Mah says. "Based on the foundation that I've built, I’m confident we can find a solution.”

About Customer

Juniper Square provides a cloud-based software platform and fund administration services for private market investment managers, primarily focusing on commercial real estate, private equity, and wealth management. Its software streamlines fundraising, investor reporting, and CRM, helping General Partners (GPs) manage investor relations, automate workflows, and improve the investor experience.