Topics

Customer Identity and Access Management Data and Information Protection Fraud Prevention Identity Governance and Administration Identity Threat Detection and Response Non-Human Identity Zero Trust

Research

Leadership Compass Buyer's Compass Advisory Note Whitepaper Executive View Leadership Brief Rising Star Product Value Navigator Blog

Advisory

Advisory Services Meet our Advisors Strategy Navigator Success Stories

Events

IF Impact Day 2026 AI & NHI Impact Day 2026 CIAM Impact Day 2026 EIC 2027 EIC 2026 Upcoming Events Upcoming Webinars

Videos

All latest videos European Identity and Cloud Conference 2025 cyberevolution 2024 KuppingerCole Webinars KuppingerCole Analyst Chat

Membership

About Professional Expert Corporate

Company

About us Success Stories People Jobs Newsroom Cybersecurity Council Technology Providers Contact us

Become a Member

Customer Identity and Access Management

Data and Information Protection

Fraud Prevention

Identity Governance and Administration

Identity Threat Detection and Response

Non-Human Identity

Zero Trust

See All Topics

Research

Leadership Compass

Buyer's Compass

Advisory Note

Whitepaper

Executive View

Leadership Brief

Rising Star

Product Value Navigator

Blog

[See all research\ \

\ \ May 19, 2026\ \ Identity Governance and Administration (IGA)\ \ \ This Leadership Compass Identity Governance and Administration (IGA) provides an overview of the IGA market and a compass to help you find a solution that best meets your needs. It examines solutions that provide both identity lifecycle management and access governance capabilities. Solutions have](/content/research/lc80864/identity-governance-and-administration-iga/index.html)

\ \ May 18, 2026\ \ Privileged Access Management (PAM)\ \ \ This KuppingerCole Leadership Compass provides an overview of the leading vendors in the Privileged Access Management (PAM) market, assessing their innovation, product capabilities, and market presence. PAM solutions enable organizations to control, manage, and monitor privileged access across](/content/research/lc81007/privileged-access-management-pam/index.html)

\ \ Apr 29, 2026\ \ Managed Detection and Response\ \ \ This KuppingerCole Analysts Leadership Compass provides an overview of the Managed Detection and Response (MDR) market in 2026. It examines services that detect, analyze, investigate, and respond to cyber threats across diverse environments, and evaluates the ability of vendors to deliver](/content/research/lc80871/managed-detection-and-response/index.html)

\ \ May 19, 2026\ \ Identity Governance and Administration (IGA)\ \ \ Modern access governance is strained by identity sprawl (including non-human identities), complex joiner/mover/leaver lifecycles, manual reviews at scale, and integration gaps that create blind spots. IGA platforms centralize identity/entitlement inventories, automate provisioning and](/content/research/bc81004/identity-governance-and-administration-iga/index.html)

\ \ May 18, 2026\ \ Privileged Access Management (PAM)\ \ \ Privileged access has expanded from admin accounts to high-impact actions across human, machine, application, and automated identities in dynamic hybrid/cloud environments. Key problems include action-based privilege definition, fragmented visibility, non-human identity risk, privilege sprawl, and](/content/research/bc81009/privileged-access-management-pam/index.html)

\ \ May 11, 2026\ \ Managed Detection and Response\ \ \ Escalating threats, alert overload, fragmented tooling, and scarce SOC skills drive slow detection and response. Managed Detection and Response (MDR) provides 24/7 monitoring, telemetry correlation, validated detection, and analyst-led investigation/response, augmented by automation and AI. Modern](/content/research/bc81061/managed-detection-and-response/index.html)

\ \ May 15, 2026\ \ Navigating the Agentic AI Security Landscape\ \ \ Enterprise AI deployments have passed a threshold that most security frameworks were not designed for. Agentic AI (autonomous, tool-using systems that chain actions, delegate to sub-agents, and operate continuously on behalf of users) is already in production across a growing number of](/content/research/an82020/navigating-the-agentic-ai-security-landscape/index.html)

\ \ Apr 22, 2026\ \ KuppingerCole 2nd Level Reference Architecture for CIAM\ \ \ The purpose of this document is to define the KuppingerCole Analysts 2nd Level Reference Architecture for CIAM, providing a structured and consistent model for designing, evaluating, and evolving Customer Identity and Access Management (CIAM) solutions.\ It focuses exclusively on capabilities](/content/research/an81080/kuppingercole-2nd-level-reference-architecture-for-ciam/index.html)

\ \ Mar 23, 2026\ \ Make or Buy: Bringing Structure and Transparency to Strategic Decisions\ \ \ Make or buy decisions are a recurring challenge in Identity and Access Management (IAM) and beyond. While the question appears straightforward, the underlying decision is rarely simple. Organizations must balance multiple, often conflicting dimensions such as cost, functionality, technical](/content/research/an82018/make-or-buy/index.html)

\ \ Jun 01, 2026\ \ Application Inventory - Identify What to Protect. Are You Missing Critical Assets?\ \ \ This whitepaper examines Application Inventory Management (AIM) as a critical, yet often underestimated, enabler for Identity and Access Management (IAM). It shows how incomplete or poorly maintained application inventories undermine IAM initiatives by increasing manual effort, fragmentation, and](/content/research/wp81148/application-inventory-identify-what-to-protect-are/index.html)

\ \ May 13, 2026\ \ Governing Third-Party Privileged Access: Moving Beyond VPN-Based Collaboration\ \ \ Organizations rely on third parties that require remote access to internal systems and operational platforms. Managing this privileged third-party access creates operational and security challenges, particularly when external identities fall outside established governance processes. Many](/content/research/wp81146/governing-third-party-privileged-access/index.html)

\ \ Apr 22, 2026\ \ Access Fabric: Uniting Access Control across Endpoints, Networks and Identity\ \ \ Access Fabric presents a transformative approach in enhancing enterprise security frameworks by integrating identity, network, device, and business signals into a unified, context-aware system. It describes how this new model resolves the limitations of traditional, siloed security practices,](/content/research/wp81140/access-fabric/index.html)

\ \ May 11, 2026\ \ Tuebora\ \ \ Modern IGA struggles with manual governance, siloed identity data, and rising non-human identities (bots, service accounts, AI agents). Tuebora’s roadmap targets lower IGA TCO via dual AI vs deterministic operation, natural-language configuration in Tuebora Studio, a Neo4j-based Unified Identity](/content/research/ev81301/tuebora/index.html)

\ \ Mar 20, 2026\ \ NEXIS Platform - IVIP Capabilities\ \ \ Identity Visibility and Intelligence Platforms (IVIP) unify data from IGA, PAM, AM, and ITDR to resolve fragmented access visibility and enable analytics-driven governance. The NEXIS Platform delivers IVIP plus converged IAM/GRC: role management/mining, cross-application SoD, identity graphs,](/content/research/ev81145/nexis-platform-ivip-capabilities/index.html)

\ \ Jan 18, 2026\ \ Memority\ \ \ Identity Fabrics unify disparate IAM solutions, enabling secure, scalable identity management across complex environments. Leveraging microservices, API-centric design, and Zero Trust principles, these fabrics offer seamless integration and advanced analytics. Memority’s 360° Identity Factory,](/content/research/ev81445/memority/index.html)

\ \ May 28, 2026\ \ No API Security, No AI Security\ \ \ Every AI system acts through APIs: retrieving context, invoking tools, and chaining decisions across enterprise infrastructure. Yet most organizations govern API security, generative AI defense, and non-human identity management as separate disciplines, leaving the gaps unprotected. This Leadership](/content/research/lb80920/no-api-security-no-ai-security/index.html)

\ \ May 15, 2026\ \ Crypto-Agility: Managing Cryptographic Change in the Post-Quantum Era\ \ \ Crypto-agility has become an urgent enterprise requirement as post-quantum cryptography, expanding machine identity ecosystems, and growing regulatory expectations expose the risks of treating cryptographic infrastructure as static. This Leadership Brief examines why organizations struggle to](/content/research/lb80919/crypto-agility/index.html)

\ \ May 11, 2026\ \ Model Context Protocol: The API Security Problem Nobody Is Ready For\ \ \ The Model Context Protocol (MCP) has rapidly become the connective tissue of the agentic AI ecosystem, and it is being deployed at enterprise scale without a mature authentication baseline or reliable runtime enforcement. Security has not kept pace with adoption. This Leadership Brief examines MCP](/content/research/lb80918/model-context-protocol/index.html)

\ \ May 15, 2026\ \ Rising Star TechJutsu\ \ \ Contact Center Authentication strengthens voice and agent-assisted channels by replacing vulnerable knowledge-based questions with IdP-backed MFA. TechJutsu’s CallerVerify triggers verification from ITSM, collaboration, and IVR tools using Okta/Auth0 or Microsoft Entra factors. OrgVerify adds](/content/research/rs81153/rising-star-techjutsu/index.html)

\ \ May 11, 2026\ \ Rising Star Bare.ID\ \ \ Bare.ID is a self-funded Wiesbaden IAM vendor (founded 2022) focused on EMEA mid-market needs within Identity Fabrics. Its subscription offering extends Keycloak into a comprehensive package combining Access Management, IGA, and PAM, with strong UI/UX, open-standard APIs, self-service automation,](/content/research/rs81152/rising-star-bare-id/index.html)

\ \ Nov 18, 2025\ \ Rising Star AuthZed\ \ \ AuthZed provides scalable authorization solutions leveraging SpiceDB for global, fine-grained permissions. Supported by $15.8M funding, their cloud products optimize performance and deployment flexibility. With innovative Materialize technology, AuthZed enhances rapid permission checks. Despite](/content/research/rs81131/rising-star-authzed/index.html)

\ \ Mar 18, 2026\ \ ManageEngine PAM360\ \ \ Privileged Access Management (PAM) is a priority in hybrid environments where ransomware risk, misconfigurations, and audit expectations are rising. Buyers need rapid, practical governance that fits existing identity and monitoring ecosystems, but must still verify modernization, extensibility, and](/content/research/pv81149/manageengine-pam360/index.html)

\ \ Jun 03, 2026\ \ From the Floor, Not the Stage: An Advisory View on EIC 2026\ \ \ AI was the headline at EIC 2026, but the real story was the gap between hype and the unfinished plumbing of identity. In hallway conversations and unfiltered case studies, the same theme kept surfacing: teams can’t govern agents they can’t yet govern users, apps, and access. Here’s what surfaced](/content/blog/schuetze/advisory-view-on-eic-2026/index.html)

\ \ Jun 02, 2026\ \ Your AI Agent Has a Supply Chain Problem\ \ \ Learn how MCP can quietly turn agentic AI into a Log4Shell-like dependency blind spot, and how to get ahead of it. You’ll leave with a practical checklist to inventory MCP endpoints, harden provenance and review of manifests/configs, avoid “valid token = safe code” thinking, and add runtime](/content/blog/balaganski/your-ai-agent-has-a-supply-chain-problem/index.html)

\ \ Jun 01, 2026\ \ Securing and Governing AI: Why AI Security Requires a Fabric, not a Category\ \ \ AI isn’t “just another app,” and your security stack can’t pretend it is. Prompts can be poisoned, retrieval can be manipulated, and agents can take actions across systems faster than reviews can keep up. The answer isn’t a new category, it’s a connected fabric of identity, data, policy, runtime](/content/blog/gardiner/securing-and-governing-ai/index.html)

Events

IF Impact Day 2026

AI & NHI Impact Day 2026

CIAM Impact Day 2026

EIC 2027

EIC 2026

Upcoming Events

Upcoming Webinars

[See past events\ \

Identity Fabric Impact Day 2026

Identity Fabric Impact Day is a focused, one-day, practice-oriented event for IAM professionals, security leaders, and solution providers seeking hands-on guidance on Identity Fabrics - modular, flexible, and scalable architectures that address identity and access needs across the enterprise. Identity Fabrics enable secure, seamless access for employees, customers, partners, and machines, while improving efficiency, supporting compliance, and strengthening security across hybrid and multi-cloud environments.

To the\ Event [Call for Speakers\ \

AIdentity & Non-Human Identity Impact Day 2026

Join the leading event dedicated to securing and governing non-human identities at scale and learn about AIdentity. Explore how dynamic credentials, automated governance, and Identity Fabric architectures transform how organizations secure workloads, APIs, and services across multi-cloud environments. Connect with experts shaping the future of identity automation, where governance meets agility, and ownership is non-negotiable.

To the\ Event [Call for Speakers\ \

Customer Identity & Access Management (CIAM) Impact Day 2026

This event is dedicated to transforming Customer Identity & Access Management (CIAM) into the next era of digital engagement. Explore how EUDI Wallets, verifiable credentials, decentralized identity, and passwordless authentication reshape customer experiences, trust, and digital safety. Connect with identity innovators, security leaders, and business strategists defining how organizations authenticate, protect, and understand their customers in a global, omnichannel world.

To the\ Event [Call for Speakers\ \

European Identity and Cloud Conference 2027

Join Europe’s leading event on Digital Identity, Security, Privacy, and Governance in an AI-driven world. Connect with a vibrant community and dive into the technologies shaping the future.

To the\ Event [Call for Speakers\ \

European Identity and Cloud Conference 2026

To the\ Event [Agenda Overview\ \

\ \ Sep 09, 2026\ \ Identity Fabric Impact Day 2026\ \ \ Identity Fabric Impact Day is a focused, one-day, practice-oriented event for IAM professionals, security leaders, and solution providers seeking hands-on guidance on Identity Fabrics - modular, flexible, and scalable architectures that address identity and access needs across the enterprise.](/content/events/ifid2026/index.html)

\ \ Oct 06, 2026\ \ AIdentity & Non-Human Identity Impact Day 2026\ \ \ Join the leading event dedicated to securing and governing non-human identities at scale and learn about AIdentity.\ Explore how dynamic credentials, automated governance, and Identity Fabric architectures transform how organizations secure workloads, APIs, and services across multi-cloud](/content/events/nhiid2026/index.html)

\ \ Nov 18, 2026\ \ Customer Identity & Access Management (CIAM) Impact Day 2026\ \ \ This event is dedicated to transforming Customer Identity & Access Management (CIAM) into the next era of digital engagement.\ Explore how EUDI Wallets, verifiable credentials, decentralized identity, and passwordless authentication reshape customer experiences, trust, and digital safety. Connect](/content/events/ciamid2026/index.html)

\ \ Jun 16, 2026\ \ Navigating B2B IAM: Leadership Compass Results Revealed\ \ \ As B2B ecosystems grow more complex, managing identities across organizational boundaries has become a strategic priority. In this webinar, KuppingerCole unveils the first results from its Leadership Compass on B2B Identity and Access Management, offering a preview of the Leader chart, key market](/content/events/2026/06/navigating-b2b-iam/index.html)

\ \ Jun 17, 2026\ \ Rethinking Privileged Access\ \ \ Historically, privileged access was associated primarily with human administrators responsible for maintaining servers, networks, and enterprise applications. That model no longer reflects how organizations operate today. This webinar draws on a Leadership Compass covering over 35 vendors to](/content/events/2026/06/rethinking-pam/index.html)

\ \ Jun 24, 2026\ \ Redefining MDR: From Alert Handling to Outcome‑Focused Security Operations\ \ \ Cyber threats continue to target organizations across endpoints, networks, cloud environments, identity systems, and connected devices, while many security teams still struggle with skills shortages, operational complexity, and the challenge of maintaining effective 24x7 monitoring and response. In](/content/events/2026/06/redefining-mdr/index.html)

Videos

All latest videos

European Identity and Cloud Conference 2025

cyberevolution 2024

KuppingerCole Webinars

KuppingerCole Analyst Chat

[See all videos\ \

\ \ Jun 15, 2026\ \ B2B Identity & Access Management: A New Market Unpacked\ \ \ Business relationships are complex and traditional IAM wasn't built for them. In this episode, Matthias Reinwarth sits down with Principal analyst John Tolbert, author of KuppingerCole Analysts' first-ever B2B IAM Leadership Compass, to explore why Business-to-Business Identity and Access](/content/watch/b2b-iam-new-market-unpacked/index.html)

\ \ Jun 12, 2026\ \ Is Your CDN Secure? CDN vs. DDoS Mitigation Unpacked with Qrator Labs\ \ \ Speed and security are no longer separate concerns. In this videocast, Osman Celik sits down with Andrey Leskin, CTO of Qrator Labs, to break down what Content Delivery Networks really are in 2026 and why they've become a critical piece of modern security infrastructure, not just a performance](/content/watch/videocast-qrator-secure-cdn/index.html)

\ \ Jun 10, 2026\ \ From SAP IDM to Modern IGA: Closing the AD Lifecycle Gap Before 2027\ \ \ SAP Identity Management reaches end of mainstream maintenance in December 2027, and every IGA vendor is offering a replacement. But most migration guidance misses a critical gap: organizations following SAP's recommended path to Microsoft Entra will still lack proper Active Directory lifecycle](/content/watch/sap-idm-to-modern-iga/index.html)

\ \ May 09, 2025\ \ PANEL: The REAL Business Case for Decentralized Identity & EU DI Wallet\ \ \ While the promise of decentralized identity (DID) and the EU Digital Identity Wallet (EUDI Wallet) is often framed in terms of privacy and user control, the real driver for widespread adoption will be compelling business value. This panel will move beyond the hype to examine what truly makes](/content/watch/panel-the-real-business-case-eic25/index.html)

\ \ May 09, 2025\ \ PANEL: Delegation with Boundaries: Ownership, Accountability, and Trust in B2B Federations\ \ \ As digital ecosystems become more interconnected, organizations increasingly rely on federated identity and access models to collaborate across business boundaries. Yet this reliance raises a crucial question: How much control should be retained internally, and how much can be safely delegated to](/content/watch/panel-delegation-with-boundaries-eic25/index.html)

[AI at your Service  [Intermediate]\ \ May 09, 2025\ \ AI at your Service [Intermediate]\ \ \ Imagine a future where AI seamlessly handles Identity Governance and Administration (IGA) tasks—whether you’re an administrator, a helpdesk agent, or an end user. Instead of navigating complex workflows and esoteric User Interfaces, AI will be at your service, executing tasks through](/content/watch/ai-at-your-service-eic25/index.html)

\ \ Dec 05, 2024\ \ Transforming Ecosystem Partner Security Risk Management: Lessons Learned and Insights for DORA Implementation\ \ \ As organizations face increasing regulatory demands and evolving cyber threats, effective Ecosystem Partner security risk management has become a critical priority. This session will explore a successful transformation journey in Ecosystem Partner security risk management, highlighting the](/content/watch/transforming-ecosystem-partner-security-risk-management-cre24/index.html)

\ \ Dec 05, 2024\ \ In der digitalen Arena: Digitalisierung bei Bayern München - aber sicher](/content/watch/arena-digitalisierung-bayern-munchen-cre24/index.html)

\ \ Dec 05, 2024\ \ Enhancing Cyber Resilience: Integrating Identity Management, Multi-Cloud Strategies, and Advanced Threat Detection](/content/watch/enhancing-cyber-resilience-cre24/index.html)

\ \ Jun 04, 2026\ \ Unified Governance Across SAP and Business Applications\ \ \ As organizations expand beyond SAP into hybrid ecosystems of SaaS and LoB applications, governance becomes fragmented and inconsistent. Traditional access control approaches no longer suffice, requiring a shift toward holistic Business Application Risk Management that leverages integrated](/content/watch/heterogeneous-it/index.html)

\ \ May 28, 2026\ \ Beyond SOAR: The Rise of the AI SOC\ \ \ The AI SOC market is expanding rapidly as security vendors race to deliver security automation systems that help deliver smarter triage, improved investigations, and faster responses. But not every AI claim translates into meaningful operational improvement. \ This webinar examines what is](/content/watch/rise-of-ai-soc/index.html)

\ \ Jun 08, 2026\ \ PAM Is No Longer a Vault: The New Identity Security Layer\ \ \ Privileged Access Management has outgrown the vault. In this episode, Matthias sits down with lead analyst Alejandro Leal, author of KuppingerCole's newly released PAM Leadership Compass, to explore how the definition of privilege itself has changed, what NHIs and agentic AI mean for PAM, and why](/content/watch/pam-no-longer-a-vault/index.html)

\ \ Jun 01, 2026\ \ Know Your Attack Surface: ASM, DRP & Brand Protection\ \ \ Not all cyber threats target your systems, some target your reputation, your customers, and your brand. In this episode, Matthias Reinwarth sits down with research analyst Osman Celik to unpack three closely related but distinct markets: Attack Surface Management (ASM), Digital Risk Protection](/content/watch/know-your-attack-surface/index.html)

Advisory

Advisory Services Success stories IAM Maturity Assessment Identity Fabric & Reference Architecture

Advisory Services

KuppingerCole's Advisory stands out due to our regular communication with vendors and key clients, providing us with in-depth insight into the issues and knowledge required to address real-world challenges.

[See Advisory Services\ \

Contact our advisors

E-mail info@kuppingercole.com

[Meet our Advisors\ \

Boehringer Ingelheim, a leading pharmaceutical company, sought to enhance its Identity and Access Management (IAM) capabilities in the digital age. We collaborated to develop a strategic IAM roadmap in just five months, aligning their IT infrastructure with their global leadership position.

View Case Study

Global chemical company revamped its Identity and Access Management with KuppingerCole's IAM strategy: guidance, assessment, roadmap. Enhanced security and efficiency.

View Case Study

IAM Maturity Assessment

Discover your IAM maturity level across key areas, benchmarked against KuppingerCole’s Reference Architecture, and receive a personalized report with expert recommendations.

[Get Started\ \

Identity Fabric & Reference Architecture

Explore how to unify, modernize, and scale your IAM ecosystem with a consistent architectural foundation.

[Learn More\ \

Membership

About Professional Expert Corporate

Your gateway to Identity Security excellence

Unlock the power of industry-leading insights and expertise. Gain access to our extensive knowledge base, vibrant community, and tailored analyst sessions—all designed to keep you at the forefront of identity security.

[Learn More\ \

Stay ahead of industry trends and make informed decisions

Access essential knowledge at your fingertips with KuppingerCole's extensive resources. From in-depth reports to concise one-pagers, leverage our complete security library to inform strategy and drive innovation.

[Learn More\ \

Elevate your expertise and expand your professional network

Gain access to comprehensive resources, personalized analyst consultations, and exclusive events – all designed to enhance your decision-making capabilities and industry connections.

[Learn More\ \

Empower your team with the knowledge and connections to drive change

Gain a true partner to drive transformative initiatives. Access comprehensive resources, tailored expert guidance, and networking opportunities.

[Learn More\ \

Company

About us Success Stories People Career Opportunities Newsroom Cybersecurity Council Technology Providers Contact us

Discover Our Passion for Advancing Identity and Security

We are specialized in the strategic management of digital identities, privileges, authentication, and access control as well as cybersecurity and business resilience.​

[Read more about our philosophy\ \

Success Stories

\ \ Empowering Boehringer Ingelheim through IAM Transformation\ \ \ Boehringer Ingelheim, a leading pharmaceutical company, sought to enhance its IAM capabilities in the digital age. We collaborated to develop a strategic roadmap in just five months, aligning their IT infrastructure with their global leadership position.](/content/success-story-boehringer-ingelheim/index.html)

\ \ sharelock.ai Success Story\ \ \ Discover how sharelock.ai, an innovative ITDR startup, refined its market positioning and strategy with KuppingerCole’s guidance—unlocking clarity, differentiation, and readiness for growth in the identity security space.](/content/success-story-sharelock/index.html)

\ \ KuppingerCole Success Story - Chemical Industry\ \ \ Global chemical company revamped IAM with KuppingerCole's IAM strategy: guidance, assessment, roadmap. Enhanced security and efficiency.](/content/success-story-leading-chemical-company/index.html)

[View All Success Stories\ \

Analysts & Advisors

Meet our team of analysts and advisors who are highly skilled and experienced professionals dedicated to helping you make informed decisions and achieve your goals.

Business Team

Meet our business team committed to helping you achieve success. We understand that running a business can be challenging, but with the right team in your corner, anything is possible.

[Meet the Team\ \

Career Opportunities

\ \ Events\ \ Wiesbaden\ \ Ausbildung zum Veranstaltungskaufmann/-frau (m/w/d)\ \ \ Die KuppingerCole Analysts AG ist ein IT-Analystenunternehmen mit Hauptsitz in Wiesbaden und weiteren Standorten rund um die Welt. Insgesamt beschäftigen wir aktuell rund 50 Mitarbeiter. KuppingerCole unterstützt seine Kunden mit Leistungen in den Bereichen Events, Advisory und Research.](/content/jobs/62/index.html)

[View All Job Offers\ \

Latest Press Releases

\ \ Press Release\ \ May 22,\ 2026\ \ KuppingerCole Analysts Wraps Up EIC 2026: Europe’s Leading Identity Conference Explores Digital Trust Through Intelligent Identity\ \ \ The European Identity and Cloud Conference (EIC) 2026 concluded in Berlin after four days of discussions on digital trust, AI-driven identity, authorization, governance, and the future of intelligent identity systems. Hosted by KuppingerCole Analysts, the event gathered over 1,500 attendees, 250+](/content/press-release/eic-2026-wrapped/index.html)

\ \ Press Release\ \ March 18,\ 2026\ \ KuppingerCole Analysts Launches Product Value Navigator to Validate the Business Impact of Technology Investments\ \ \ Product Value Navigator is a new research framework from KuppingerCole Analysts designed to validate the economic value of enterprise technology solutions. By combining independent technical evaluation with financial modelling and open-source intelligence data, it provides transparent insight into](/content/press-release/product-value-navigator/index.html)

\ \ Press Release\ \ February 19,\ 2026\ \ KuppingerCole Analysts and Forum INCYBER Enter Strategic Partnership to Strengthen European Cybersecurity Market Intelligence\ \ \ KuppingerCole Analysts and Forum INCYBER announce a strategic partnership to strengthen European cybersecurity market intelligence, thought leadership, and cross-regional collaboration across France, Benelux, and DACH.](/content/press-release/kuppingercole-analysts-forum-incyber/index.html)

Cybersecurity Council

With the Cybersecurity Council, we bring together world-class information security professionals in leading positions from across many industries and schools of thought to exchange and discuss how to secure the rapidly growing cyber economy. The results of these fruitful discussions will flow into every of our services.

[Learn more\ \

Services for Technology Providers

You're building the future in a crowded, skeptical market. KuppingerCole Analysts helps you stand out with neutral credibility, market insights, and direct access to key decision-makers. We empower technology providers with the visibility, insights, and analyst-backed influence to win in a competitive market.

[Learn more\ \

Basic contact information

KuppingerCole Analysts AG

Wilhelmstr. 20-22

65185 Wiesbaden

Germany

info@kuppingercole.com

[See all locations\ \

Use AI-powered search to answer my question

Use AI-powered search to answer my question

KuppingerCole Analysts Blog

Guest Blog

Apr 23, 2026

Like this?

Don't like this?

Log in to make your opinion count! We will also use your feedback to tune your personal recommendations.

Log in to hear your voice heard. We'll also make sure to update your personal recommendations.

Login

Don't have a KC account yet? Join Now

Why don't you like this?

This isn't relevant for me

I don't like the content

SubmitCancel

0

Save

Bookmarks

Save your favorite items in your personal watch list so that you can read them later and find them again easily.

Login

Don't have a KC account yet? Join Now

[LinkedIn [Facebook [X / TwitterCopy URL

IAM Is Having a Moment. Here Is How to Make It Yours.

\ \ Katja Olkhovaia\ \ Guest Author](/content/speakers/3952/index.html)

This guest post reflects the views of the author and does not necessarily represent the views of KuppingerCole Analysts. It is provided for informational purposes only and should not be interpreted as independent research, analysis, endorsement, or advisory services by KuppingerCole Analysts.

From developer to architect, sysadmin to IGA consultant - a structured guide to entering identity management from any IT background

Not long ago, identity management meant one thing in most organisations: a sysadmin who managed Active Directory groups, a password policy that enforced a change every twelve months, and a rough understanding of who was in which department. That was sufficient. It was not glamorous, but it worked well enough for the threat environment of the time.

The world that produced that model no longer exists.

Today, the same discipline has grown a full vocabulary of hashtag-worthy abbreviations (#IGA, #PAM, #CIAM, #ITDR, #NHI, #ZeroTrust) fills dedicated conference tracks at every major security event, and commands the attention of CISOs, regulators, and board-level risk committees simultaneously. IAM has become, without much ceremony, one of the most structurally important specialisations in enterprise security. It is also one of the most underserved in terms of qualified talent.

I have watched this shift accelerate over the past two years from the recruiting and market research side, and the pattern is now legible enough to describe clearly. In this piece I want to explain why it is happening, what it means for professionals who want to move toward IAM, and specifically which existing skills and backgrounds translate most directly into the roles the market is actually hiring for. The data and job market references throughout this article draw primarily on the German market, which I have analysed in detail. The structural patterns - which technical backgrounds transfer, which platforms are worth learning, and how to build credibility without years of IAM-specific experience - apply broadly across European and global markets.

Why IAM Has Real and Durable Career Potential

The demand for IAM professionals is not a trend driven by vendor marketing cycles. It is driven by three structural forces that are not going away.

The first is regulation. NIS2, which came into force across EU member states in October 2024, mandates that organisations in critical sectors implement identity-based access controls, enforce least-privilege principles, and demonstrate governance over who can access sensitive systems. DORA, the Digital Operational Resilience Act applying to financial entities from January 2025, adds requirements for managing access to critical functions and third-party access governance. GDPR has long required organisations to demonstrate that personal data is accessed only by those with legitimate need. These are not soft compliance expectations. Non-compliance carries penalties reaching 4% of global annual revenue. Organisations that have not yet invested in mature IAM programmes are building them under regulatory pressure, and they are discovering that they cannot find enough people to do the work.

The second is the threat landscape. Identity-based attacks now represent the primary vector in the majority of enterprise breaches. Organisations are investing in IAM not only because regulators require it, but because their insurers increasingly mandate it and their incident post-mortems keep pointing to the same root causes: over-privileged accounts, unmanaged service accounts, access that was never removed after role changes, and credentials that were never properly governed.

The third, which is obviously an obvious consequence of the first two points, is the talent gap, and it is severe. In my analysis of 10,098 open IAM positions on StepStone you can check the data in detail.

What matters for anyone considering a move toward IAM is this: the demand is structural and regulatory in origin, the talent supply is not keeping up, and the organisations feeling the most pressure (German banks, insurers, manufacturers, and public sector bodies) are among the most willing to pay for qualified people. The door is open. The question is how to position yourself to walk through it.

What Technical Tools Experience You Can Bring Directly Into IAM

The fastest transitions into IAM are the ones where a professional arrives with technical skills that map onto specific platform requirements without needing to be retrained from zero. These mappings are more specific than most career guides acknowledge.

Java developers → SailPoint. SailPoint is the IGA platform that saw the largest year-on-year demand increase in German job postings in 2025. It exists in two distinct forms, and the distinction matters for where you invest your learning. SailPoint IdentityIQ (IIQ) is the legacy on-premises product, widely deployed in large German enterprises, particularly banking and insurance, that have not yet migrated to the cloud. IIQ is Java-based at its core: custom connectors, provisioning rules, correlation logic, and workflow automation are all written in Java and BeanShell, a Java-compatible scripting language. A Java developer can reach productive implementation depth on IIQ faster than almost any other route into SailPoint consulting. However, SailPoint's strategic direction is firmly toward Identity Security Cloud (ISC), its SaaS platform. New implementations increasingly favour ISC, and SailPoint's own certification programme now centres on it. The practical recommendation for Java developers is to understand both: IIQ knowledge is immediately billable given the volume of existing on-premises deployments, but ISC fluency is where the market is heading. Starting with IIQ concepts and transitioning toward ISC as you build experience is the realistic path for most consultants entering the SailPoint ecosystem today.

.NET and C# developers → Omada. Omada Identity is a European IGA platform with strong market penetration in German mid-market and public sector organisations. It runs on the Microsoft .NET stack. Workflow customisation, connector development, and integration logic in Omada are written in the same language ecosystem that .NET developers already work in daily. The transition here is one of domain knowledge, not technology relearning. A C# developer who spends two to three months learning Omada's IdentityPROCESS+ methodology and identity governance concepts can arrive in the consulting market at a level that would take a non-developer significantly longer to reach.

Python developers and scripters → Cross-platform IAM automation. Every major IAM platform (Okta, SailPoint Identity Security Cloud, Microsoft Entra ID, CyberArk) exposes REST APIs. Python SDKs exist for most of them. The work of writing provisioning scripts, building automated joiner/mover/leaver workflows, scripting access certification reporting, and integrating IAM platforms with HR systems or ticketing tools falls naturally to Python developers with API experience. This is platform-agnostic value, which means Python skills open doors across the entire IAM toolset rather than in one specific niche.

PowerShell experience → Microsoft identity stack. Microsoft Entra ID remains the most widely deployed identity platform in Germany, present in 68% of IAM job postings. Professionals who manage Active Directory, Azure AD Connect, Group Policy, and Entra conditional access policies through PowerShell already operate the foundation layer of the German enterprise IAM market. The transition requires adding governance knowledge and regulatory context on top of operational fluency.

LDAP and directory services experience → Any enterprise IAM project. LDAP is the protocol that underpins identity resolution across virtually every enterprise IAM integration. Professionals who have managed OpenLDAP, Novell eDirectory, or Red Hat Directory Server carry a conceptual understanding of directory hierarchies, attribute mapping, and schema design that translates directly into IAM connector configuration, source correlation, and identity data quality troubleshooting.

What Field Experience Transfers Into IAM, and Where It Lands

Tools are one dimension. The other is the broader professional background that shapes which IAM roles you are naturally positioned for. The German market rewards several transition paths consistently.

Cybersecurity analysts → PAM and ITDR. The mental model of a security analyst (threat vectors, privilege escalation paths, lateral movement techniques, log analysis) maps directly onto Privileged Access Management and Identity Threat Detection and Response. A security analyst who understands how attackers exploit over-privileged service accounts or compromised credentials arrives in PAM and ITDR with a perspective that purely administrative IAM professionals lack. CyberArk, BeyondTrust, and the emerging ITDR vendors are the platforms where this background translates most directly.

System administrators and engineers → IGA operations and implementation. This is the most established transition path in the market, and it works because sysadmins already perform the operational core of IAM: provisioning accounts, managing group memberships, handling access requests, maintaining the directory. The gap to close is strategic and conceptual: identity governance frameworks, regulatory compliance context, IGA platform knowledge, and the ability to speak to access decisions in business language rather than technical configuration terms. A sysadmin who adds SailPoint or Omada platform knowledge and earns a vendor certification does not look like someone changing careers. They look like an IAM professional who already understands the infrastructure.

DevOps engineers and CI/CD practitioners → Cloud IAM and machine identity. The shift toward Zero Trust architectures, cloud-native IAM, and the governance of non-human identities is pulling DevOps skills directly into the identity domain. DevOps professionals who understand Infrastructure-as-Code, secrets management with tools like HashiCorp Vault, container identity in Kubernetes environments, and CI/CD pipeline security bring a technical foundation that is specifically relevant to the fastest-growing corner of the market. According to Entro's follow-up NHI & Secrets Risk Report H1 2025 (July 2025; public summary at nhimg.org) the workload-to-human identity ratio in German organisations reached 144:1 by the end of 2025 - up from 92:1 the previous year ( 2025 State of Non-Human Identities and Secrets in Cybersecurity, September 2024). Managing that explosion of machine identities requires people who understand how software is deployed, not just how users are managed.

Cloud architects and engineers → Cloud IAM specialisation. Deep familiarity with AWS IAM policy structures, Azure RBAC and Entra ID Governance, or GCP Identity is no longer a subset of cloud knowledge, it is an IAM specialisation in its own right. Cloud-heavy organisations dealing with multi-cloud entitlement sprawl, CIEM (Cloud Infrastructure Entitlement Management), and hybrid identity architectures are actively looking for people who understand both the cloud layer and the identity governance layer simultaneously. This is a relatively young specialisation where the talent supply is even thinner than in traditional IGA or PAM.

AI and machine learning practitioners → The emerging ITDR and AI agent identity frontier. This is the transition path that barely existed two years ago. Identity platforms are now embedding ML-based anomaly detection, AI-driven access recommendations, and behavioural analytics into their core governance capabilities. At the same time, the governance of AI agent identities - managing what credentials an autonomous AI process can access, under what conditions, and with what accountability trail - is a problem that no established professional community has fully solved yet. Professionals with ML background who understand model behaviour, probabilistic risk scoring, and anomaly detection have an opportunity to enter IAM at the frontier of its most technically demanding open questions.

IT consultants → IAM programme management and advisory. The most overlooked supply of IAM talent is in the general IT consulting community. Professionals who have delivered enterprise technology programmes, managed stakeholder relationships across business and IT, and translated business requirements into technical architectures are carrying skills that senior IAM roles depend on but rarely find in purely technical candidates.

Education: Starting from Scratch or Catching Up Fast

If you are planning a longer-term path from the beginning, a Bachelor's degree in Computer Science, Applied Informatics, or Business Informatics (Wirtschaftsinformatik) remains the standard entry expectation at German consulting firms and enterprise teams. The degree choice shapes where you land. Wirtschaftsinformatik, offered at universities including TU Darmstadt, University of Mannheim, and Leuphana University Lüneburg, specifically develops the combination of IT architecture understanding and business process literacy that senior IAM consulting roles require. A Master's in Cybersecurity or Information Security - offered at TU Berlin, Ruhr University Bochum, and the University of Applied Sciences Munich (Hochschule München), among others - provides deeper technical depth for those targeting engineering and architecture roles. If you are already in a Bachelor's programme in a related field, a specialisation in cybersecurity or digital identity at Master's level is a direct path to IAM without requiring a full career pivot.

If you want to transition as quickly as possible with existing IT experience, the certification sequence that produces the best results in the German market follows a clear order:

Free and immediate (start today):

  • SailPoint's Identity Security Leader credential is 4.5 hours of structured, vendor-agnostic IGA learning available without charge through SailPoint's Identity University. It removes the conceptual gaps that disqualify candidates at screening.
  • Microsoft's free SC-900 (Security, Compliance and Identity Fundamentals) is a two-to-three-week self-study path that establishes the Microsoft identity vocabulary that appears in nearly every German IAM context.

Short investment, high return (4–8 weeks):

  • Microsoft SC-300 (Identity and Access Administrator) is a four-to-six-week preparation path that leads to a certification directly relevant to Entra ID configuration.
  • Okta's Professional certification path typically requires six to eight weeks of study plus access to a free Okta developer account for hands-on practice; the Okta Certified Professional exam costs around $250 and validates the foundational Okta skills.
  • Keycloak deployment and configuration, while not vendor-certified, can be set up in a home lab environment over a weekend and learned to production-competency level in four to six weeks; it teaches SAML, OIDC, OAuth 2.0, and LDAP federation in a free, open-source context.

Medium investment, specialist credibility (2–4 months):

  • CyberArk's Defender certification covers PAM architecture, vault configuration, and privileged session management; the official training is a two-to-three-week instructor-led course, and the exam is widely recognised in German banking and critical infrastructure hiring.
  • SailPoint's Identity Security Cloud Administrator credential (formerly IdentityNow) requires approximately two months of structured learning plus hands-on platform access; SailPoint recommends six months of practical experience before sitting the full engineer certification, but the administrator path is accessible earlier and already valued by consulting partners.
  • Omada's partner training programme is the most direct route into Omada-specific skills for .NET developers; the programme is delivered through Omada's partner network and typically runs two to four weeks of structured content.
  • CIAM (Certified Identity and Access Manager) from the Identity Management Institute is the most IAM-specific governance credential available and is directly relevant for those targeting programme management and advisory roles. It requires roughly 4 years of combined IT background to qualify, involves around 2 months of self-study, and costs $390 including the study guide and up to three exam attempts. For professionals already working in IT who are transitioning toward IAM consulting or programme ownership, it sits comfortably within a two-month preparation window.

IAM did not become the most structurally important security discipline by accident. It became that because everything else in enterprise security - Zero Trust, NIS2 compliance, cloud adoption, AI agent governance - ultimately depends on knowing who has access to what, when, and why. The organisations that cannot answer that question clearly are the ones that appear in the breach reports. The organisations that can are the ones investing aggressively in building the teams that make it possible.

The market is not waiting for the university pipeline to produce certified IAM graduates. It is pulling in developers who already know Java, consultants who already understand regulatory frameworks, DevOps engineers who already manage secrets, and security analysts who already think in terms of privilege escalation. The platforms, certifications, and learning paths exist to close the remaining gaps. The question is whether you recognise the skills you are already carrying as the entry credential they actually are.

Two years from now, the professionals who acted on that recognition in 2026 will be the senior specialists and architects that the next round of recruiters cannot find. That pattern is already visible in the data. The only variable is which side of it you end up on.

Vendors in this Blog

\ \ BeyondTrustBlog Mention](/content/vendors/beyondtrust/index.html) \ \ CyberArkBlog Mention](/content/vendors/cyberark/index.html) \ \ EntroBlog Mention](/content/vendors/entro/index.html) \ \ HashiCorpBlog Mention](/content/vendors/hashicorp/index.html) \ \ KeycloakBlog Mention](/content/vendors/keycloak/index.html) \ \ MicrosoftBlog Mention](/content/vendors/microsoft/index.html) \ \ OktaBlog Mention](/content/vendors/okta/index.html) \ \ OmadaBlog Mention](/content/vendors/omada/index.html) \ \ SailPointBlog Mention](/content/vendors/sailpoint/index.html)

Top related content

\ \ Event Recording\ \ \ 25 Years of IAM Pitfalls: Why Identity Programs Keep Failing - and What Must Change\ \ Jeroen Remie](/content/watch/25-years-of-iam-pitfalls-eic26 "Event Recording: 25 Years of IAM Pitfalls: Why Identity Programs Keep Failing - and What Must Change"/index.html) \ \ Analyst Chat\ \ \ B2B Identity & Access Management: A New Market Unpacked\ \ John Tolbert](/content/watch/b2b-iam-new-market-unpacked "Analyst Chat: B2B Identity & Access Management: A New Market Unpacked"/index.html) \ \ Webinar Recording\ \ \ Identity Security and Management – Why IGA Alone May Not Be Enough\ \ Martin Kuppinger](/content/watch/enhancing-identity-ecosystem "Webinar Recording: Identity Security and Management – Why IGA Alone May Not Be Enough"/index.html) \ \ Event Recording\ \ \ How to Find and Educate Your IAM Team](/content/watch/idpro-finding-your-iam-team-eic25 "Event Recording: How to Find and Educate Your IAM Team"/index.html) \ \ Event Recording\ \ \ IAM in 2025: Trends, Challenges, and findings from a global survey [Intermediate]\ \ Nitish Deshpande](/content/watch/iam-in-2025-trends-eic25 "Event Recording: IAM in 2025: Trends, Challenges, and findings from a global survey [Intermediate]"/index.html) \ \ Webinar Recording\ \ \ The Impact of Expanding Attack Surfaces on Enterprise Cybersecurity and Why You Need a Strong IAM Posture\ \ Martin Kuppinger](/content/watch/strengthening-enterprise-cybersecurity "Webinar Recording: The Impact of Expanding Attack Surfaces on Enterprise Cybersecurity and Why You Need a Strong IAM Posture"/index.html) \ \ Webinar Recording\ \ \ Identity-Governance-Strategien für die Post-IDM Ära\ \ Matthias Reinwarth](/content/watch/identity-governance-strategien "Webinar Recording: Identity-Governance-Strategien für die Post-IDM Ära"/index.html)