The IdM needs to be split from the IdP to be a 2nd application. This is to enable security through firewall'ing the IdM from the general internet.