Identity and access management covers the directory of users and groups, single sign-on, multi-factor authentication, passwordless login, lifecycle provisioning, privileged access and, for customers, customer identity management. Organisations use it to decide who can reach which application and to cut off access quickly. Microsoft Entra ID and Okta are widely known non-EU reference points.
An identity provider sits in front of every other system. Its signing keys let it vouch for any user, its logs show who accessed what and when, and its outage can lock a whole organisation out. Most integrations are built on open standards such as SAML, OpenID Connect and SCIM, so the protocols are portable, but the rest is not easy to move: policies, conditional-access rules, group structures, application connections and the MFA enrolments of every user. A hosted provider also holds or controls the keys and secrets behind those enrolments.
When choosing a European option, check how signing keys and MFA secrets are generated and stored, whether you can use your own hardware security modules or run the service yourself, and where administrators and support staff operate from. Look at standards support, a documented export of users and policies, and a tested break-glass procedure for when the provider is unavailable. Confirm support for strong authentication such as FIDO2 security keys.