💡In versions 15.0 and earlier, the Identity Hub was not available.
This article covers the following topics:
What is the Board Identity Hub?
The Board Identity Hub is a centralized identity management service that Board Administrators use to manage Board Support users and their access to one or more customer Subscription Hubs.
It allows Board Support personnel to access customer environments through a centralized identity instead of maintaining a separate local account in each Subscription Hub. This access supports activities such as troubleshooting, investigation, and guided issue resolution.
The Board Identity Hub is for Board Support use only. Customers and partners cannot access it or use it to manage their users.

Before you begin
Before the Identity Hub can provision a Board Support service account, the Subscription Hub client secret defined for the Board Identity Hub must be available in the Subscription Hub Key Vault.
This configuration is completed during environment setup. Customers and Subscription Hub Administrators do not configure the client secret through the Identity Hub or Subscription Hub interfaces.
Manage Board Support users through the Identity Hub
The provisioning process depends on whether the Board Support user already exists in the target Subscription Hub:
New user provisioning. The user does not exist in the Subscription Hub and requires customer approval before provisioning.
Existing user association. The user already exists in the Subscription Hub and is associated with the Identity Hub without creating a duplicate account.
New user
A new Board Support service account must be approved by the customer before it can access the customer environment.
When Board Support associates a new service account with a Subscription Hub:
The Identity Hub creates a provisioning request.
The relevant Subscription Hub Administrator receives an approval request by email.

The service account receives an informational email confirming that provisioning has started.

The Subscription Hub Administrator reviews and approves the request through the existing email-based approval process.
The Identity Hub provisions the service account in the Subscription Hub.
The service account receives a confirmation email stating that the Subscription Hub has been associated with its Identity Hub account.
.png)
When the user authenticates through Board Authentication rather than single sign-on, the user receives an additional email requesting that they complete registration and set a password.

The service account can now access the customer environment according to the approved configuration.
After the account is associated with the Subscription Hub, it appears in the user list with Identity Hub user as its authentication type.
Approving the service account does not automatically grant access to a Subscription Hub instance. The Subscription Hub Administrator must configure instance access, roles, permissions, and scope separately.
Access remains inactive until both of the following actions are complete:
The service account is approved.
The required instance access and authorizations are configured.
Existing user
When a Board Support user already exists in a Subscription Hub and is later associated with the Identity Hub, Board updates the existing user record instead of creating a duplicate.
The following settings are preserved:
Approval status
Instance access
Roles
Permissions
Access scope
The following changes occur:
The authentication type changes to Identity Hub user.
The user becomes a Board Support service account.
The user no longer consumes a customer licence.
The Subscription Hub Administrator does not need to approve the user again, but receives an informational email explaining that the existing user is being converted into a service account.

The Subscription Hub Administrator must then:
Review the user’s existing access configuration.
Confirm the provisioning.
Verify that the assigned instance access, roles, permissions, and scope remain appropriate.
The user receives a notification confirming that provisioning is complete.
Once provisioning completes successfully:
The user authenticates through the Identity Hub.
Existing Subscription Hub authorizations remain unchanged.
Existing permissions remain available.
The service account no longer consumes a customer license.
Existing user identity updates
During provisioning, the Identity Hub may detect that an existing Subscription Hub user matches only part of the Identity Hub identity. This can occur when:
The email address matches, but the account name is different.
The account name matches, but the email address is different.
In these cases, Board updates the existing Subscription Hub account instead of creating a duplicate user.
The affected user receives a notification explaining whether the account name or email address was updated.
Subscription Hub Administrator responsibilities
The Subscription Hub Administrator retains control over Board Support access.
For a new Board Support service account, the Administrator determines:
Whether to approve the account
Which instances the account can access
Which roles and permissions to assign
The scope of access
For an existing Board Support user associated with the Identity Hub, the Administrator must review and confirm the existing access configuration.
Licensing
Board Support service accounts are typically used to access customer environments for assistance and troubleshooting.
In Board 15.1 and later, service accounts managed through the Identity Hub do not consume customer licences. Customers therefore do not need to allocate paid user licences to service accounts used for support activities.
This simplifies licence administration while preserving Board Support access to customer environments.
Known limitations
The Identity Hub does not currently support standard home realm users who use the same account name or user identifier in multiple Subscription Hubs, so each Subscription Hub must use a unique identifier so that the Identity Hub can associate the user with the correct tenant.
This limitation does not apply to users provisioned through the approved service account or multi-tenant user processes.
Identity Hub service account sessions authenticated through a Board Entra federation may expire after approximately 30 minutes, regardless of the session timeout configured for the environment. When the Identity Hub session expires, the user is also signed out of all associated Subscription Hubs. As a workaround, configure the user's authentication type in the Identity Hub as Board authentication instead of Board Entra. With Board authentication, the user signs in using a username and password and is not affected by this session expiration issue.