The intention of this project was to provide a consistent Single-Sign-On (SSO) between an on-premise ISAM (IBM Security Access Manager) and IBM’s Cloud Identity (CI) using SAML by utilising local user accounts for authentication. MMFA (Mobile Multi Factor Authentication) with QR Code and TOTP (Timely One Time Password) was added to provide a 2-factor authentication process. In a second step IBM’s Connections Cloud as well as several WebSphere based applications were added to extend SSO for a user. Products used: IBM Security Access Manager, IBM Cloud Identity, IBM Connections Cloud, Active Directory