Fagerhult Group is a global lighting and technology company made up of 16 independently operated brands. Each brand runs its own IT and HR environment. That independence is part of the group’s operating model and commercial strength.
But independence at scale comes at a cost.
Across the group, there were 12 separate Microsoft Entra ID tenants and HR data spread across multiple systems and CSV feeds. The workforce was split between desk-based employees with M365 accounts and deskless workers without them. There was no consistent way in, and it was clear that no one had a complete view of who needed access to what, or whether that access was current.
And when Fagerhult began planning the rollout of Workvivo as a shared communications platform across all 16 brands, the identity problem could no longer sit in the background. Every employee needed access. Not just desk-based employees, every single one of the 4,000 people across the group, regardless of brand, role or how they work.
The goal was clear. Provide secure, consistent access for every employee without forcing brands to change their existing infrastructure.
The complexity was real and layered. Fagerhult wasn't dealing with just one IAM problem, it was dealing with several at once.
The group needed a way to manage identity and access consistently, without asking anyone to change how they operated.
Rather than forcing a structural change on any brand, Fagerhult deployed Connect as a shared identity and access layer sitting above its existing IT infrastructure.
The approach was deliberate: preserve everything brands already had and add the group-level capability they were missing.
One identity layer across 12 tenants
Connect integrates individually with all 12 Entra ID tenants and pulls employee data from each brand's HR sources, including CSV feeds. Every employee now has a single, secure group-level identity regardless of which brand they work for, where they are located or how they access systems.
Access for every type of worker
Desk-based employees sign in through Microsoft 365 Single Sign-On. Deskless workers authenticate directly through Connect. Both groups access Workvivo and other connected tools through the same identity layer, with the same reliability and without needing separate credentials or workarounds.
Automated joiner, mover and leaver workflows
Connect replaced the manual provisioning chain entirely. When a new employee is added through Entra ID or a connected HR source, access is provisioned automatically. When someone changes roles or moves between brands, their access updates accordingly, and when someone leaves, their access is removed across all connected systems. The process runs without manual input and without the errors that came with it.
A reliable source of truth for workforce data
7 HR data sources feeding into one platform meant data quality couldn't be an afterthought. Connect maps employee data across organisations, regions and reporting lines, giving the group IT function an accurate, always-current view of its entire workforce for the first time.
Distributed control with central visibility
Local IT teams continue to manage their own users and environments as they always have. What changed is that the group IT function now has visibility across access, governance and usage in one place. Independence is preserved. Oversight is no longer a blind spot.
With Connect live across all 16 brands, Fagerhult has a consistent, automated and scalable identity model for the first time.
For IT Teams
For HR Teams
For the Business
Fagerhult didn’t need to consolidate infrastructure to achieve consistency. By introducing a shared identity layer, the group created secure, automated access across 16 brands while preserving local autonomy. Identity became simpler, access became reliable, and the workforce became system ready from day one.