Topics
Customer Identity and Access Management Data and Information Protection Fraud Prevention Identity Governance and Administration Identity Threat Detection and Response Non-Human Identity Zero Trust
Research
Leadership Compass Buyer's Compass Advisory Note Whitepaper Executive View Leadership Brief Rising Star Product Value Navigator Blog
Advisory
Advisory Services Meet our Advisors Strategy Navigator Success Stories
Events
IF Impact Day 2026 AI & NHI Impact Day 2026 CIAM Impact Day 2026 EIC 2027 EIC 2026 Upcoming Events Upcoming Webinars
Videos
All latest videos European Identity and Cloud Conference 2025 cyberevolution 2024 KuppingerCole Webinars KuppingerCole Analyst Chat
Membership
About Professional Expert Corporate
Company
About us Success Stories People Jobs Newsroom Cybersecurity Council Technology Providers Contact us
Customer Identity and Access Management
Data and Information Protection
Fraud Prevention
Identity Governance and Administration
Identity Threat Detection and Response
Non-Human Identity
Zero Trust
See All Topics
Research
[See all research\ \
\ \ May 19, 2026\ \ Identity Governance and Administration (IGA)\ \ \ This Leadership Compass Identity Governance and Administration (IGA) provides an overview of the IGA market and a compass to help you find a solution that best meets your needs. It examines solutions that provide both identity lifecycle management and access governance capabilities. Solutions have](/content/research/lc80864/identity-governance-and-administration-iga/index.html)
\ \ May 18, 2026\ \ Privileged Access Management (PAM)\ \ \ This KuppingerCole Leadership Compass provides an overview of the leading vendors in the Privileged Access Management (PAM) market, assessing their innovation, product capabilities, and market presence. PAM solutions enable organizations to control, manage, and monitor privileged access across](/content/research/lc81007/privileged-access-management-pam/index.html)
\ \ Apr 29, 2026\ \ Managed Detection and Response\ \ \ This KuppingerCole Analysts Leadership Compass provides an overview of the Managed Detection and Response (MDR) market in 2026. It examines services that detect, analyze, investigate, and respond to cyber threats across diverse environments, and evaluates the ability of vendors to deliver](/content/research/lc80871/managed-detection-and-response/index.html)
\ \ May 19, 2026\ \ Identity Governance and Administration (IGA)\ \ \ Modern access governance is strained by identity sprawl (including non-human identities), complex joiner/mover/leaver lifecycles, manual reviews at scale, and integration gaps that create blind spots. IGA platforms centralize identity/entitlement inventories, automate provisioning and](/content/research/bc81004/identity-governance-and-administration-iga/index.html)
\ \ May 18, 2026\ \ Privileged Access Management (PAM)\ \ \ Privileged access has expanded from admin accounts to high-impact actions across human, machine, application, and automated identities in dynamic hybrid/cloud environments. Key problems include action-based privilege definition, fragmented visibility, non-human identity risk, privilege sprawl, and](/content/research/bc81009/privileged-access-management-pam/index.html)
\ \ May 11, 2026\ \ Managed Detection and Response\ \ \ Escalating threats, alert overload, fragmented tooling, and scarce SOC skills drive slow detection and response. Managed Detection and Response (MDR) provides 24/7 monitoring, telemetry correlation, validated detection, and analyst-led investigation/response, augmented by automation and AI. Modern](/content/research/bc81061/managed-detection-and-response/index.html)
\ \ May 15, 2026\ \ Navigating the Agentic AI Security Landscape\ \ \ Enterprise AI deployments have passed a threshold that most security frameworks were not designed for. Agentic AI (autonomous, tool-using systems that chain actions, delegate to sub-agents, and operate continuously on behalf of users) is already in production across a growing number of](/content/research/an82020/navigating-the-agentic-ai-security-landscape/index.html)
\ \ Apr 22, 2026\ \ KuppingerCole 2nd Level Reference Architecture for CIAM\ \ \ The purpose of this document is to define the KuppingerCole Analysts 2nd Level Reference Architecture for CIAM, providing a structured and consistent model for designing, evaluating, and evolving Customer Identity and Access Management (CIAM) solutions.\ It focuses exclusively on capabilities](/content/research/an81080/kuppingercole-2nd-level-reference-architecture-for-ciam/index.html)
\ \ Mar 23, 2026\ \ Make or Buy: Bringing Structure and Transparency to Strategic Decisions\ \ \ Make or buy decisions are a recurring challenge in Identity and Access Management (IAM) and beyond. While the question appears straightforward, the underlying decision is rarely simple. Organizations must balance multiple, often conflicting dimensions such as cost, functionality, technical](/content/research/an82018/make-or-buy/index.html)
\ \ Jun 01, 2026\ \ Application Inventory - Identify What to Protect. Are You Missing Critical Assets?\ \ \ This whitepaper examines Application Inventory Management (AIM) as a critical, yet often underestimated, enabler for Identity and Access Management (IAM). It shows how incomplete or poorly maintained application inventories undermine IAM initiatives by increasing manual effort, fragmentation, and](/content/research/wp81148/application-inventory-identify-what-to-protect-are/index.html)
\ \ May 13, 2026\ \ Governing Third-Party Privileged Access: Moving Beyond VPN-Based Collaboration\ \ \ Organizations rely on third parties that require remote access to internal systems and operational platforms. Managing this privileged third-party access creates operational and security challenges, particularly when external identities fall outside established governance processes. Many](/content/research/wp81146/governing-third-party-privileged-access/index.html)
\ \ Apr 22, 2026\ \ Access Fabric: Uniting Access Control across Endpoints, Networks and Identity\ \ \ Access Fabric presents a transformative approach in enhancing enterprise security frameworks by integrating identity, network, device, and business signals into a unified, context-aware system. It describes how this new model resolves the limitations of traditional, siloed security practices,](/content/research/wp81140/access-fabric/index.html)
\ \ May 11, 2026\ \ Tuebora\ \ \ Modern IGA struggles with manual governance, siloed identity data, and rising non-human identities (bots, service accounts, AI agents). Tuebora’s roadmap targets lower IGA TCO via dual AI vs deterministic operation, natural-language configuration in Tuebora Studio, a Neo4j-based Unified Identity](/content/research/ev81301/tuebora/index.html)
\ \ Mar 20, 2026\ \ NEXIS Platform - IVIP Capabilities\ \ \ Identity Visibility and Intelligence Platforms (IVIP) unify data from IGA, PAM, AM, and ITDR to resolve fragmented access visibility and enable analytics-driven governance. The NEXIS Platform delivers IVIP plus converged IAM/GRC: role management/mining, cross-application SoD, identity graphs,](/content/research/ev81145/nexis-platform-ivip-capabilities/index.html)
\ \ Jan 18, 2026\ \ Memority\ \ \ Identity Fabrics unify disparate IAM solutions, enabling secure, scalable identity management across complex environments. Leveraging microservices, API-centric design, and Zero Trust principles, these fabrics offer seamless integration and advanced analytics. Memority’s 360° Identity Factory,](/content/research/ev81445/memority/index.html)
\ \ May 28, 2026\ \ No API Security, No AI Security\ \ \ Every AI system acts through APIs: retrieving context, invoking tools, and chaining decisions across enterprise infrastructure. Yet most organizations govern API security, generative AI defense, and non-human identity management as separate disciplines, leaving the gaps unprotected. This Leadership](/content/research/lb80920/no-api-security-no-ai-security/index.html)
\ \ May 15, 2026\ \ Crypto-Agility: Managing Cryptographic Change in the Post-Quantum Era\ \ \ Crypto-agility has become an urgent enterprise requirement as post-quantum cryptography, expanding machine identity ecosystems, and growing regulatory expectations expose the risks of treating cryptographic infrastructure as static. This Leadership Brief examines why organizations struggle to](/content/research/lb80919/crypto-agility/index.html)
\ \ May 11, 2026\ \ Model Context Protocol: The API Security Problem Nobody Is Ready For\ \ \ The Model Context Protocol (MCP) has rapidly become the connective tissue of the agentic AI ecosystem, and it is being deployed at enterprise scale without a mature authentication baseline or reliable runtime enforcement. Security has not kept pace with adoption. This Leadership Brief examines MCP](/content/research/lb80918/model-context-protocol/index.html)
\ \ May 15, 2026\ \ Rising Star TechJutsu\ \ \ Contact Center Authentication strengthens voice and agent-assisted channels by replacing vulnerable knowledge-based questions with IdP-backed MFA. TechJutsu’s CallerVerify triggers verification from ITSM, collaboration, and IVR tools using Okta/Auth0 or Microsoft Entra factors. OrgVerify adds](/content/research/rs81153/rising-star-techjutsu/index.html)
\ \ May 11, 2026\ \ Rising Star Bare.ID\ \ \ Bare.ID is a self-funded Wiesbaden IAM vendor (founded 2022) focused on EMEA mid-market needs within Identity Fabrics. Its subscription offering extends Keycloak into a comprehensive package combining Access Management, IGA, and PAM, with strong UI/UX, open-standard APIs, self-service automation,](/content/research/rs81152/rising-star-bare-id/index.html)
\ \ Nov 18, 2025\ \ Rising Star AuthZed\ \ \ AuthZed provides scalable authorization solutions leveraging SpiceDB for global, fine-grained permissions. Supported by $15.8M funding, their cloud products optimize performance and deployment flexibility. With innovative Materialize technology, AuthZed enhances rapid permission checks. Despite](/content/research/rs81131/rising-star-authzed/index.html)
\ \ Mar 18, 2026\ \ ManageEngine PAM360\ \ \ Privileged Access Management (PAM) is a priority in hybrid environments where ransomware risk, misconfigurations, and audit expectations are rising. Buyers need rapid, practical governance that fits existing identity and monitoring ecosystems, but must still verify modernization, extensibility, and](/content/research/pv81149/manageengine-pam360/index.html)
\ \ Jun 03, 2026\ \ From the Floor, Not the Stage: An Advisory View on EIC 2026\ \ \ AI was the headline at EIC 2026, but the real story was the gap between hype and the unfinished plumbing of identity. In hallway conversations and unfiltered case studies, the same theme kept surfacing: teams can’t govern agents they can’t yet govern users, apps, and access. Here’s what surfaced](/content/blog/schuetze/advisory-view-on-eic-2026/index.html)
\ \ Jun 02, 2026\ \ Your AI Agent Has a Supply Chain Problem\ \ \ Learn how MCP can quietly turn agentic AI into a Log4Shell-like dependency blind spot, and how to get ahead of it. You’ll leave with a practical checklist to inventory MCP endpoints, harden provenance and review of manifests/configs, avoid “valid token = safe code” thinking, and add runtime](/content/blog/balaganski/your-ai-agent-has-a-supply-chain-problem/index.html)
\ \ Jun 01, 2026\ \ Securing and Governing AI: Why AI Security Requires a Fabric, not a Category\ \ \ AI isn’t “just another app,” and your security stack can’t pretend it is. Prompts can be poisoned, retrieval can be manipulated, and agents can take actions across systems faster than reviews can keep up. The answer isn’t a new category, it’s a connected fabric of identity, data, policy, runtime](/content/blog/gardiner/securing-and-governing-ai/index.html)
Events
[See past events\ \
Identity Fabric Impact Day 2026
Identity Fabric Impact Day is a focused, one-day, practice-oriented event for IAM professionals, security leaders, and solution providers seeking hands-on guidance on Identity Fabrics - modular, flexible, and scalable architectures that address identity and access needs across the enterprise. Identity Fabrics enable secure, seamless access for employees, customers, partners, and machines, while improving efficiency, supporting compliance, and strengthening security across hybrid and multi-cloud environments.
To the\ Event [Call for Speakers\ \
AIdentity & Non-Human Identity Impact Day 2026
Join the leading event dedicated to securing and governing non-human identities at scale and learn about AIdentity. Explore how dynamic credentials, automated governance, and Identity Fabric architectures transform how organizations secure workloads, APIs, and services across multi-cloud environments. Connect with experts shaping the future of identity automation, where governance meets agility, and ownership is non-negotiable.
To the\ Event [Call for Speakers\ \
Customer Identity & Access Management (CIAM) Impact Day 2026
This event is dedicated to transforming Customer Identity & Access Management (CIAM) into the next era of digital engagement. Explore how EUDI Wallets, verifiable credentials, decentralized identity, and passwordless authentication reshape customer experiences, trust, and digital safety. Connect with identity innovators, security leaders, and business strategists defining how organizations authenticate, protect, and understand their customers in a global, omnichannel world.
To the\ Event [Call for Speakers\ \
European Identity and Cloud Conference 2027
Join Europe’s leading event on Digital Identity, Security, Privacy, and Governance in an AI-driven world. Connect with a vibrant community and dive into the technologies shaping the future.
To the\ Event [Call for Speakers\ \
European Identity and Cloud Conference 2026
To the\ Event [Agenda Overview\ \
\ \ Sep 09, 2026\ \ Identity Fabric Impact Day 2026\ \ \ Identity Fabric Impact Day is a focused, one-day, practice-oriented event for IAM professionals, security leaders, and solution providers seeking hands-on guidance on Identity Fabrics - modular, flexible, and scalable architectures that address identity and access needs across the enterprise.](/content/events/ifid2026/index.html)
\ \ Oct 06, 2026\ \ AIdentity & Non-Human Identity Impact Day 2026\ \ \ Join the leading event dedicated to securing and governing non-human identities at scale and learn about AIdentity.\ Explore how dynamic credentials, automated governance, and Identity Fabric architectures transform how organizations secure workloads, APIs, and services across multi-cloud](/content/events/nhiid2026/index.html)
\ \ Nov 18, 2026\ \ Customer Identity & Access Management (CIAM) Impact Day 2026\ \ \ This event is dedicated to transforming Customer Identity & Access Management (CIAM) into the next era of digital engagement.\ Explore how EUDI Wallets, verifiable credentials, decentralized identity, and passwordless authentication reshape customer experiences, trust, and digital safety. Connect](/content/events/ciamid2026/index.html)
\ \ Jun 16, 2026\ \ Navigating B2B IAM: Leadership Compass Results Revealed\ \ \ As B2B ecosystems grow more complex, managing identities across organizational boundaries has become a strategic priority. In this webinar, KuppingerCole unveils the first results from its Leadership Compass on B2B Identity and Access Management, offering a preview of the Leader chart, key market](/content/events/2026/06/navigating-b2b-iam/index.html)
\ \ Jun 17, 2026\ \ Rethinking Privileged Access\ \ \ Historically, privileged access was associated primarily with human administrators responsible for maintaining servers, networks, and enterprise applications. That model no longer reflects how organizations operate today. This webinar draws on a Leadership Compass covering over 35 vendors to](/content/events/2026/06/rethinking-pam/index.html)
\ \ Jun 24, 2026\ \ Redefining MDR: From Alert Handling to Outcome‑Focused Security Operations\ \ \ Cyber threats continue to target organizations across endpoints, networks, cloud environments, identity systems, and connected devices, while many security teams still struggle with skills shortages, operational complexity, and the challenge of maintaining effective 24x7 monitoring and response. In](/content/events/2026/06/redefining-mdr/index.html)
Videos
European Identity and Cloud Conference 2025
[See all videos\ \
\ \ Jun 15, 2026\ \ B2B Identity & Access Management: A New Market Unpacked\ \ \ Business relationships are complex and traditional IAM wasn't built for them. In this episode, Matthias Reinwarth sits down with Principal analyst John Tolbert, author of KuppingerCole Analysts' first-ever B2B IAM Leadership Compass, to explore why Business-to-Business Identity and Access](/content/watch/b2b-iam-new-market-unpacked/index.html)
\ \ Jun 12, 2026\ \ Is Your CDN Secure? CDN vs. DDoS Mitigation Unpacked with Qrator Labs\ \ \ Speed and security are no longer separate concerns. In this videocast, Osman Celik sits down with Andrey Leskin, CTO of Qrator Labs, to break down what Content Delivery Networks really are in 2026 and why they've become a critical piece of modern security infrastructure, not just a performance](/content/watch/videocast-qrator-secure-cdn/index.html)
\ \ Jun 10, 2026\ \ From SAP IDM to Modern IGA: Closing the AD Lifecycle Gap Before 2027\ \ \ SAP Identity Management reaches end of mainstream maintenance in December 2027, and every IGA vendor is offering a replacement. But most migration guidance misses a critical gap: organizations following SAP's recommended path to Microsoft Entra will still lack proper Active Directory lifecycle](/content/watch/sap-idm-to-modern-iga/index.html)
\ \ May 09, 2025\ \ PANEL: The REAL Business Case for Decentralized Identity & EU DI Wallet\ \ \ While the promise of decentralized identity (DID) and the EU Digital Identity Wallet (EUDI Wallet) is often framed in terms of privacy and user control, the real driver for widespread adoption will be compelling business value. This panel will move beyond the hype to examine what truly makes](/content/watch/panel-the-real-business-case-eic25/index.html)
\ \ May 09, 2025\ \ PANEL: Delegation with Boundaries: Ownership, Accountability, and Trust in B2B Federations\ \ \ As digital ecosystems become more interconnected, organizations increasingly rely on federated identity and access models to collaborate across business boundaries. Yet this reliance raises a crucial question: How much control should be retained internally, and how much can be safely delegated to](/content/watch/panel-delegation-with-boundaries-eic25/index.html)
[
\
\
May 09, 2025\
\
AI at your Service [Intermediate]\
\
\
Imagine a future where AI seamlessly handles Identity Governance and Administration (IGA) tasks—whether you’re an administrator, a helpdesk agent, or an end user. Instead of navigating complex workflows and esoteric User Interfaces, AI will be at your service, executing tasks through](/content/watch/ai-at-your-service-eic25/index.html)
\ \ Dec 05, 2024\ \ Transforming Ecosystem Partner Security Risk Management: Lessons Learned and Insights for DORA Implementation\ \ \ As organizations face increasing regulatory demands and evolving cyber threats, effective Ecosystem Partner security risk management has become a critical priority. This session will explore a successful transformation journey in Ecosystem Partner security risk management, highlighting the](/content/watch/transforming-ecosystem-partner-security-risk-management-cre24/index.html)
\ \ Dec 05, 2024\ \ In der digitalen Arena: Digitalisierung bei Bayern München - aber sicher](/content/watch/arena-digitalisierung-bayern-munchen-cre24/index.html)
\ \ Dec 05, 2024\ \ Enhancing Cyber Resilience: Integrating Identity Management, Multi-Cloud Strategies, and Advanced Threat Detection](/content/watch/enhancing-cyber-resilience-cre24/index.html)
\ \ Jun 04, 2026\ \ Unified Governance Across SAP and Business Applications\ \ \ As organizations expand beyond SAP into hybrid ecosystems of SaaS and LoB applications, governance becomes fragmented and inconsistent. Traditional access control approaches no longer suffice, requiring a shift toward holistic Business Application Risk Management that leverages integrated](/content/watch/heterogeneous-it/index.html)
\ \ May 28, 2026\ \ Beyond SOAR: The Rise of the AI SOC\ \ \ The AI SOC market is expanding rapidly as security vendors race to deliver security automation systems that help deliver smarter triage, improved investigations, and faster responses. But not every AI claim translates into meaningful operational improvement. \ This webinar examines what is](/content/watch/rise-of-ai-soc/index.html)
\ \ Jun 08, 2026\ \ PAM Is No Longer a Vault: The New Identity Security Layer\ \ \ Privileged Access Management has outgrown the vault. In this episode, Matthias sits down with lead analyst Alejandro Leal, author of KuppingerCole's newly released PAM Leadership Compass, to explore how the definition of privilege itself has changed, what NHIs and agentic AI mean for PAM, and why](/content/watch/pam-no-longer-a-vault/index.html)
\ \ Jun 01, 2026\ \ Know Your Attack Surface: ASM, DRP & Brand Protection\ \ \ Not all cyber threats target your systems, some target your reputation, your customers, and your brand. In this episode, Matthias Reinwarth sits down with research analyst Osman Celik to unpack three closely related but distinct markets: Attack Surface Management (ASM), Digital Risk Protection](/content/watch/know-your-attack-surface/index.html)
Advisory
Advisory Services Success stories IAM Maturity Assessment Identity Fabric & Reference Architecture
Advisory Services
KuppingerCole's Advisory stands out due to our regular communication with vendors and key clients, providing us with in-depth insight into the issues and knowledge required to address real-world challenges.
[See Advisory Services\ \
Contact our advisors
E-mail info@kuppingercole.com
[Meet our Advisors\ \
Boehringer Ingelheim, a leading pharmaceutical company, sought to enhance its Identity and Access Management (IAM) capabilities in the digital age. We collaborated to develop a strategic IAM roadmap in just five months, aligning their IT infrastructure with their global leadership position.
Global chemical company revamped its Identity and Access Management with KuppingerCole's IAM strategy: guidance, assessment, roadmap. Enhanced security and efficiency.
IAM Maturity Assessment
Discover your IAM maturity level across key areas, benchmarked against KuppingerCole’s Reference Architecture, and receive a personalized report with expert recommendations.
[Get Started\ \
Identity Fabric & Reference Architecture
Explore how to unify, modernize, and scale your IAM ecosystem with a consistent architectural foundation.
[Learn More\ \
Membership
About Professional Expert Corporate
Your gateway to Identity Security excellence
Unlock the power of industry-leading insights and expertise. Gain access to our extensive knowledge base, vibrant community, and tailored analyst sessions—all designed to keep you at the forefront of identity security.
[Learn More\ \
Stay ahead of industry trends and make informed decisions
Access essential knowledge at your fingertips with KuppingerCole's extensive resources. From in-depth reports to concise one-pagers, leverage our complete security library to inform strategy and drive innovation.
[Learn More\ \
Elevate your expertise and expand your professional network
Gain access to comprehensive resources, personalized analyst consultations, and exclusive events – all designed to enhance your decision-making capabilities and industry connections.
[Learn More\ \
Empower your team with the knowledge and connections to drive change
Gain a true partner to drive transformative initiatives. Access comprehensive resources, tailored expert guidance, and networking opportunities.
[Learn More\ \
Company
About us Success Stories People Career Opportunities Newsroom Cybersecurity Council Technology Providers Contact us
Discover Our Passion for Advancing Identity and Security
We are specialized in the strategic management of digital identities, privileges, authentication, and access control as well as cybersecurity and business resilience.
[Read more about our philosophy\ \
Success Stories
\ \ Shaping Pathlock's Identity Governance and Security Strategy\ \ \ Pathlock has been a client of KuppingerCole for over three years now, aided by KC in shaping their strategy as they navigate their path through broader identity governance and security market.](/content/success-story-pathlock/index.html)
\ \ Immuta’s AI-Driven Access Control & Compliance\ \ \ Discover how Immuta’s automated data governance platform streamlines policy enforcement, ensures regulatory compliance, and accelerates analytics innovation—helping enterprises unlock the full value of their data securely and at scale.](/content/success-story-immuta/index.html)
\ \ Futurae Technologies AG\ \ \ Futurae Technologies AG, founded in 2016 as a spin-off from ETH Zurich, is a Swiss cybersecurity company specializing in user-centric multi-factor authentication and transaction signing solutions. Their platform combines strong security with seamless user experience, serving banks, insurers, and](/content/success-story-futurae/index.html)
[View All Success Stories\ \
Analysts & Advisors
Meet our team of analysts and advisors who are highly skilled and experienced professionals dedicated to helping you make informed decisions and achieve your goals.
Business Team
Meet our business team committed to helping you achieve success. We understand that running a business can be challenging, but with the right team in your corner, anything is possible.
[Meet the Team\ \
Career Opportunities
\ \ Events\ \ Wiesbaden\ \ Ausbildung zum Veranstaltungskaufmann/-frau (m/w/d)\ \ \ Die KuppingerCole Analysts AG ist ein IT-Analystenunternehmen mit Hauptsitz in Wiesbaden und weiteren Standorten rund um die Welt. Insgesamt beschäftigen wir aktuell rund 50 Mitarbeiter. KuppingerCole unterstützt seine Kunden mit Leistungen in den Bereichen Events, Advisory und Research.](/content/jobs/62/index.html)
[View All Job Offers\ \
Latest Press Releases
\ \ Press Release\ \ May 22,\ 2026\ \ KuppingerCole Analysts Wraps Up EIC 2026: Europe’s Leading Identity Conference Explores Digital Trust Through Intelligent Identity\ \ \ The European Identity and Cloud Conference (EIC) 2026 concluded in Berlin after four days of discussions on digital trust, AI-driven identity, authorization, governance, and the future of intelligent identity systems. Hosted by KuppingerCole Analysts, the event gathered over 1,500 attendees, 250+](/content/press-release/eic-2026-wrapped/index.html)
\ \ Press Release\ \ March 18,\ 2026\ \ KuppingerCole Analysts Launches Product Value Navigator to Validate the Business Impact of Technology Investments\ \ \ Product Value Navigator is a new research framework from KuppingerCole Analysts designed to validate the economic value of enterprise technology solutions. By combining independent technical evaluation with financial modelling and open-source intelligence data, it provides transparent insight into](/content/press-release/product-value-navigator/index.html)
\ \ Press Release\ \ February 19,\ 2026\ \ KuppingerCole Analysts and Forum INCYBER Enter Strategic Partnership to Strengthen European Cybersecurity Market Intelligence\ \ \ KuppingerCole Analysts and Forum INCYBER announce a strategic partnership to strengthen European cybersecurity market intelligence, thought leadership, and cross-regional collaboration across France, Benelux, and DACH.](/content/press-release/kuppingercole-analysts-forum-incyber/index.html)
Cybersecurity Council
With the Cybersecurity Council, we bring together world-class information security professionals in leading positions from across many industries and schools of thought to exchange and discuss how to secure the rapidly growing cyber economy. The results of these fruitful discussions will flow into every of our services.
[Learn more\ \
Services for Technology Providers
You're building the future in a crowded, skeptical market. KuppingerCole Analysts helps you stand out with neutral credibility, market insights, and direct access to key decision-makers. We empower technology providers with the visibility, insights, and analyst-backed influence to win in a competitive market.
[Learn more\ \
Basic contact information
KuppingerCole Analysts AG
Wilhelmstr. 20-22
65185 Wiesbaden
Germany
[See all locations\ \
Use AI-powered search to answer my question
Use AI-powered search to answer my question
[Insight\ \
Guide
The Definitive Guide to Identity & Access Management
\ \ Martin Kuppinger](/content/people/kuppinger/index.html)
What Is Identity & Access Management?
Identity & Access Management (IAM) is one of today’s core disciplines of IT (Information Technology), and an essential element within every cybersecurity strategy. However, IAM is not limited to security, but is also one of the enablers of digital transformation.
IAM Core Technologies: IGA, Access Management, PAM
Dealing with customers, consumers, or connected things is about dealing with their digital identities. It is about IAM. IAM, sometimes abbreviated to Identity Management, is easy to describe: It is everything that helps in managing identities and their access. It is about the “who” and the “what”: Who can do what in IT? Who can log on? Who can access which data?
IAM consists of a wide range of technologies. However, there are three technologies at the core:
- User Lifecycle Management & Access Governance
- Access Management & Federation
- Privileged Access Management
While these areas form the foundation of IAM, there are more elements in IAM such as directory services as sort of a database of all the users, and Identity Verification for the first-time proof of an identity during the onboarding process, e.g., by comparing the face via video with the photo on the person’s passport.
Traditional IAM Architecture: What Is the Foundation of IAM?
The first core area of IAM, User Lifecycle Management & Access Governance, is also referred to as IGA (Identity Governance & Administration). User Lifecycle Management is also called Identity Provisioning. But what are all these terms about? Essentially, there are two parts: the management of the user’s lifecycle, and the governance of access.
The Foundation: User Lifecycle Management & Identity Provisioning
User Lifecycle Management is about the entire identity management process from creating a digital identity when onboarding a person such as a new employee, to retiring that digital identity. It involves creating user accounts in systems and managing changes, e.g., when someone moves to another department. These processes are commonly referred to as JML (joiner, mover & leaver) processes. User Lifecycle Management supports and automates such processes.
The other part of User Lifecycle Management & Access Governance is about requesting, approving, and reviewing access entitlements. It is about who should have access to which systems, applications, and data. Automated and manual requests for data must be supported, including access request and approval workflows. Access reviews are required for regulatory compliance, to check regularly whether the access is still needed or must be revoked.
User Lifecycle Management is tightly coupled with Identity Provisioning. While User Lifecycle Management looks at the JML processes and other parts of the lifecycle, Identity Provisioning is about technically connecting IGA with the target systems such as Microsoft Active Directory or SAP, for e.g., creating user accounts, and assigning entitlements.
Authentication and More: Access Management & Identity Federation
The second major discipline of IAM, Access Management & Federation or just Access Management, is about access to systems at runtime. After a user has an account, that user will log on.
.png)
That requires authentication, i.e. the verification that credentials such as user name and password have been entered correctly. Access Management also includes federation to other systems, a concept where for instance a user is authenticated in his organization and then logs on to the organization’s tenant of a SaaS (Software as a Service) application such as Salesforce. In that case, Salesforce trusts the organization to manage authentication correctly, and federates the users from that organization to the respective tenant in Salesforce. Access federation is based on established standards such as OAuth2, SAML (Security Assertion Markup Language), and OIDC (OpenID Connect).
Protecting Most Critical Access: Privileged Access Management
Last not least, there is PAM or Privileged Access Management, which is a most technical discipline of IAM that deals with the specifics of highly privileged users such as administrators logging into systems, e.g., as Windows administrator or root user on Linux.
Some of the aspects covered by PAM solutions are rotating passwords for shared accounts, and session management. Shared accounts such as root can be used by multiple persons. To mitigate the risks, users of privileged accounts must not use the same password. PAM ensures (amongst many other features) that privileged account users always get a new password for each new access. The session management part of PAM is about recording sessions, e.g., for forensics, and for logging and monitoring what happens during privileged access.
Understanding the Downside of Legacy IAM
Traditionally, these three groups of capabilities have been deployed on-premises, with specialized tools for each of the areas. Most organizations started with User Lifecycle Management & Access Governance, and Access Management, adding Privileged Access Management later.
The Tough Part of IAM: Connecting to the Managed IT Systems
Creating user accounts in a range of systems such as Microsoft Active Directory, Microsoft Azure Active Directory, LDAP servers, on email servers, mainframes, business applications such as SAP, specialized banking apps, new SaaS services, and many more requires technical integration with these systems via connectors. That part of integration is challenging, despite SCIM (System for Cross-domain Identity Management) becoming increasingly established as a standard.
Standards Evolving: SaaS Is Easier to Manage
With the shift of workloads to SaaS services, SCIM for User Lifecycle Management and other standards such as OAuth and OIDC for authentication are becoming the norm, simplifying integration. For Access Management & Federation, this is already the norm. For the other areas, there is also a tendency towards IDaaS (Identity as a Service), even while the maturity of solutions is still is lower than for Access Management.
The Benefits of Modern IAM Platforms
Modern IAM platforms deliver various benefits. The obvious one is that they are deployed using as-a-service models, avoiding the complex installation and operation of IAM on-premises. However, integration with legacy backends such as mainframes still requires setting up connectors..
The Need for Flexibility: Pure On-Premises IAM Is Not Sufficient Anymore
Most, but not all, IDaaS offerings in the market are available in both pure SaaS deployments and other options, enabling, e.g., hybrid deployments or a simplified migration from on-premises to the cloud. Modern architectures, based on microservices and building on container-based deployments, give the customer much more flexibility in deployment than traditional models.
Updates and patches in SaaS are managed by the providers, simplifying operations and allowing the customers to concentrate on the user-focused and business-focused aspects of IAM, instead of technology, such as building efficient workflows and managing user access.
The Role of Microservices and APIs in IAM
Furthermore, customization is simplified in modern architectures, because customizations can be well-segregated from the IAM service into separate microservices. This also is due to the fact that modern IAM comes with a comprehensive set of APIs (Application Programming Interfaces), which expose the capabilities of the IAM products and can be utilized in customization.
The Identity Fabric: A Paradigm for Modern IAM
IAM, over the years, evolved – and became increasingly complex. Aside from the major disciplines, many specialized solutions appeared and, sometimes, disappeared again. With IAM starting to support other groups of users such as customers, new disciplines such as CIAM (Consumer/Customer IAM) evolved.
Unifying IAM: Managing Access of Everyone and Everything to Every Service
The paradigm of the Identity Fabric, defined by KuppingerCole Analysts, provides model for a unified approach to IAM. It starts with looking at what IAM is for: The task of IAM is enabling seamless, controlled, and secure access of everyone and everything to every service. Not more, not less.
The Identity Fabric is based on analyzing the major capabilities required by an organization, which should be done based on the use cases (such as managing access of consumers to an ecommerce system) and the required technical capabilities. The latter can be, e.g., based on a Reference Architecture. These capabilities are grouped into services that are delivered by technology. Ideally, that technology is provided in modern architectures, i.e., container-based deployments and based on microservices, providing a comprehensive set of APIs.
Identity Fabrics: Enabling Both Agility and Gradual Migration
Identity Fabrics support both legacy applications, and modern SaaS applications and digital services. They connect to existing solutions, either directly or by utilizing legacy IAM solutions. They also use standards such as SCIM and OIDC, but also specialized connectors, to connect to modern SaaS services.
Based on the broad set of APIs, they also enable modern digital services to request IAM services. Thus, a digital service, e.g., can use APIs for registering new users, instead of creating a user registration capability for each new digital service. Identity Fabrics help in moving from traditional IAM architectures towards modern architectures, but also in unifying different IAM initiatives across capability areas such as User Lifecycle Management and Access/Federation, or across identity types, such as Employee IAM and Customer IAM.
The IAM Reference Architecture
On a more technical level, there is the KuppingerCole IAM Reference Architecture, which describes the various components that make up IAM or are related to IAM. The Reference Architecture is split into four vertical columns and three horizontal layers. Let's dive right in.
Administration, Auditing, Authentication, and Authorization
The vertical columns are Administration, Auditing, Authentication, and Authorization – the four As of IAM.
- Administration: Managing digital identities, the user accounts, passwords, etc.
- Auditing: The governance capabilities such as access review or SoD (Segregation of Duties) controls.
- Authentication: Everything around authentication, from Identity Verification and risk- and context-based authentication to Identity Federation.
- Authorization: The authorization of access requests, e.g., by supporting requests from digital services to authorize users at runtime, the so-called Dynamic Authorization Management.
Anne Bailey and Matthias Reinwarth take on Verified Digital Identity in an episode of the Analyst Chat podcast. Listen in and explore what these are, why they are becoming increasingly important and where they add new aspects to the concept of digital identity. The horizontal layers are Core IAM, Extended IAM, and related areas.
The latter may be considered as part of IAM, or separate disciplines. As with every reference architecture, this is a blueprint that can be adjusted to specific requirements of an organization. It helps in identifying and prioritizing the relevant elements in an IAM and creating the roadmap towards the own IAM infrastructure.
IAM Vendors Overview
Even in the core IAM market, there is already more than 100 vendors. Looking at all the specialized disciplines, there are a hundreds of vendors. Let's take a look at the key players of each segment.
Key Players in IGA
Thus, identifying the right set of capabilities – e.g., by utilizing the IAM Reference Architecture – and defining a blueprint – e.g., based on the Identity Fabrics model – is the foundation to identify the capabilities and a reasonable set of technology providers for the IAM core capabilities and specialized further capabilities that are required. For User Lifecycle Management & Access Governance, the leading vendors (based on Overall Leadership in the relevant KuppingerCole Leadership Compasses) include, in alphabetical order, Broadcom, EmpowerID, Hitachi ID, IBM, Micro Focus, Microsoft, Okta, Omada, One Identity, Oracle, RSA, SailPoint, SAP, and Saviynt.
Key Players in Access Management
For Access Management & Federation, these are, again in alphabetical order, Broadcom, CyberArk, ForgeRock, IBM, Ilantus, Micro Focus, Microsoft, Okta, OneLogin, Oracle, Ping Identity, and RSA.
Key Players in Privileged Access Management
For Privileged Access Management, these are (in alphabetical order) BeyondTrust, Broadcom, Centrify, CyberArk, Hitachi ID, One Identity, SSH, Thycotic, and Wallix. However, as mentioned, there are many more vendors in these market segments as well as in the overall market. Our KuppingerCole Leadership Compass and Market Compass documents provide a comprehensive overview about the most relevant IAM vendors.
What to Consider When Choosing a Vendor
Selecting IAM vendors – as with every other vendor in IT – should always start with the requirements. What are the main use cases and what are the most relevant technical capabilities? Which areas should be prioritized?
Don’t Start With the Tool – Understand Your Requirements First
Based on the requirements, the relevant market segments must be identified. Don’t compare apples and oranges, but look for the right solutions for the right problem. Again, the KuppingerCole Leadership Compass and Market Compass documents as well as the Buyer’s Compass, list key requirements, criteria, and critical capabilities to provide guidance.
For the market segment, a longlist of vendors containing all vendors that may be a fit should be created. In a first round of evaluation, the four to six vendors that are the best fit from a high-level capability perspective, but also with respect to supported deployment models, should be selected. These are then included in the RfI (Request for Information) and RfP (Request for Proposal). The RfI looks in detail at functional and non-functional requirements, while the RfP adds the cost perspective. The RfI process also includes vendor presentation.
The Right Approach: Longlist, Shortlist, Proof of Concept
From the shortlisted vendors, commonly two are included in a subsequent PoC (Proof of Concept), where major use cases and capabilities are tested in practice, before making a final decision and moving to contract negotiations. When looking at this from a high-level perspective, it is most important to select vendors that support the full breadth of systems well, in modern architectures and deployments.
It is equally important to find a good balance between supporting all the specific requirements and a reasonably small set of providers to avoid ending up with a zoo of tools. Machine Learning systems are ideally suited to the tasks of systems management where there are clear rules and well-defined environments.
IAM Outlook: What Does the Future Hold for IAM?
IAM is under constant change. Cloud first strategies, IAM modernization, modern architecture models and agile IT are just some of the factors driving the evolution of IAM. Don’t stop with where you are on your IAM journey, but always look for what is next in IAM. IAM is constantly evolving. There are many new evolutions and trends in IAM. Three of the most important ones are:
- Identity of things, devices, and services: IAM is not only about humans. It is also about the identity of things (such as in IoT, the Internet of Things), of devices (such as mobile devices), and services (such as apps or software robots). IAM also is about the relationship between humans, things, and devices. Digital transformation use cases do not work without supporting all these devices and their relationships – just think about the different people owning and driving connected vehicles and controlling these with apps from their smartphones.
- Decentralized Identity: While identities traditionally have been managed by the applications, the reuse of identities, e.g., as a consumer dealing with many retailers, has become essential. With the concept of decentralized identities (DIDs), there is a new paradigm that supports this concept.
- Integration into other platforms: More and more identity capabilities are shifting into SaaS and IaaS platforms, including, e.g., ITSM/ESM (IT Service Management/Enterprise Service Management). This allows for a more seamless integration of processes. That integration brings both opportunities and challenges, with the risk of identity capabilities sprawling across too many places.
Again: There is continual innovation in IAM, which delivers new options for customers. Modern architectures such as the Identity Fabric help in preparing for IAM evolution, in contrast to the traditional, monolithic IAM tools running on-premises.
Bottom Line and Recommendations
Ready for a new, a better, a more modern IAM? Understand today’s and the future requirements, make a plan, define your own IAM and Identity Fabric and execute on it, for serving the Digital Transformation of your organization.
7 Steps Towards A Successful IAM Program
The seven steps are:
- Get your stakeholders on board
- Understand the requirements of business and IT
- Define a program, and gather the funding
- Define your blueprint & architecture – your vision of a future Identity Fabric that fits to your organization
- Build your IAM organization
- Select the technology & tools you need, based on your requirements, blueprint & architecture
- Execute in well-defined steps – the projects within your program
IAM is at the core of the digital transformation, at the core of cybersecurity, and at the core of regulatory compliance. It is essential, therefore, to have both a mature and a modern IAM in place. For many organizations, there is a need for IAM modernization, shifting from traditional approaches towards a modern IAM.
Both the models such as the KuppingerCole Identity Fabric, and the technology, as described in the KuppingerCole Leadership Compass and Market Compass documents, are available for building a modern IAM infrastructure.
Top related content
\ \ Jun 05, 2024\ \ \ Whitepaper: The Future of Identity: Beyond Today’s IAM\ \ Martin Kuppinger](/content/research/wp81265/the-future-of-identity-beyond-today-s-iam "Whitepaper: The Future of Identity: Beyond Today’s IAM"/index.html) \ \ Jun 12, 2025\ \ \ Leadership Compass: Access Management\ \ Alejandro Leal](/content/research/lc80867/access-management "Leadership Compass: Access Management"/index.html) \ \ May 06, 2025\ \ \ Event Recording: Designing your Future Identity Fabric: Operationalizing the KuppingerCole IAM Reference Frameworks\ \ Matthias Reinwarth](/content/watch/identity-fabrics-workshop-p1-eic25 "Event Recording: Designing your Future Identity Fabric: Operationalizing the KuppingerCole IAM Reference Frameworks"/index.html) \ \ May 10, 2024\ \ \ Advisory Note: Modernizing IAM for Today's Business Needs\ \ Alejandro Leal](/content/research/an80882/modernizing-iam-for-today-s-business-needs "Advisory Note: Modernizing IAM for Today's Business Needs"/index.html)
Table of Contents
[What Is Identity & Access Management?\ \ \ \ \ \ \ \
IAM Core Technologies: IGA, Access Management, PAM
[Traditional IAM Architecture: What Is the Foundation of IAM?\ \ \ \ \ \ \ \
The Foundation: User Lifecycle Management & Identity Provisioning Authentication and More: Access Management & Identity Federation Protecting Most Critical Access: Privileged Access Management
[Understanding the Downside of Legacy IAM\ \ \ \ \ \ \ \
The Tough Part of IAM: Connecting to the Managed IT Systems Standards Evolving: SaaS Is Easier to Manage
[The Benefits of Modern IAM Platforms\ \ \ \ \ \ \ \
The Need for Flexibility: Pure On-Premises IAM Is Not Sufficient Anymore The Role of Microservices and APIs in IAM
[The Identity Fabric: A Paradigm for Modern IAM\ \ \ \ \ \ \ \
Unifying IAM: Managing Access of Everyone and Everything to Every Service Identity Fabrics: Enabling Both Agility and Gradual Migration
[The IAM Reference Architecture\ \ \ \ \ \ \ \
Administration, Auditing, Authentication, and Authorization
[IAM Vendors Overview\ \ \ \ \ \ \ \
Key Players in IGA Key Players in Access Management Key Players in Privileged Access Management
[What to Consider When Choosing a Vendor\ \ \ \ \ \ \ \
Don’t Start With the Tool – Understand Your Requirements First The Right Approach: Longlist, Shortlist, Proof of Concept
IAM Outlook: What Does the Future Hold for IAM? [Bottom Line and Recommendations\ \ \ \ \ \ \ \
7 Steps Towards A Successful IAM Program
Back to top
Table of Contents
Table of contents
Close
[What Is Identity & Access Management?\ \ \ \ \ \ \ \
[Traditional IAM Architecture: What Is the Foundation of IAM?\ \ \ \ \ \ \ \
[Understanding the Downside of Legacy IAM\ \ \ \ \ \ \ \
[The Benefits of Modern IAM Platforms\ \ \ \ \ \ \ \
[The Identity Fabric: A Paradigm for Modern IAM\ \ \ \ \ \ \ \
[The IAM Reference Architecture\ \ \ \ \ \ \ \
[IAM Vendors Overview\ \ \ \ \ \ \ \
[What to Consider When Choosing a Vendor\ \ \ \ \ \ \ \