Global identity vendors will tell you the future is SaaS-only. Indian regulators, procurement rules and CERT-In directions tell a more nuanced story. The right question isn't 'cloud or not' — it's 'which of our identity workloads can leave our perimeter, and under whose jurisdiction?'
The forcing factors
Three requirements push identity infrastructure on-premises or into Indian sovereign environments. First, log residency: CERT-In directions require 180-day ICT log retention within India, and authentication logs are squarely in scope. Second, sector rules: RBI, SEBI and IRDAI expectations around data location and auditability make many BFSI institutions keep identity data in their own data centres as a matter of policy. Third, procurement: government and PSU tenders frequently require indigenous software and in-country deployment outright.
Against that, cloud deployment wins on speed to value and operational overhead. For unregulated mid-market companies, a cloud IAM deployment is usually the right default.
The honest decision framework
Ask four questions. Where must authentication and access logs physically live? Which regulator can audit you, and what have they flagged at peers? What latency does your core application estate tolerate for authentication round-trips? And who patches the platform at 2 a.m. — your team or your vendor's?
The answers usually land in one of three patterns: fully on-premises (government, banks, insurers with strict interpretations), hybrid (regulated core on-prem, workforce SaaS apps via cloud), or fully cloud (growth-stage companies without sectoral mandates). The platform decision that keeps all three open is choosing software that runs identically in every topology — so a regulatory change is a redeployment, not a re-procurement.