Topics

[Customer Identity and Access Management](/content/insights/customer-identity-and-access-management/index.html) [Data and Information Protection](/content/insights/data-protection/index.html) [Fraud Prevention](/content/insights/fraud-prevention/index.html) [Identity Governance and Administration](/content/insights/identity-governance-and-administration/index.html) [Identity Threat Detection and Response](/content/insights/identity-threat-detection/index.html) [Non-Human Identity](/content/insights/non-human-identity/index.html) [Zero Trust](/content/insights/zero-trust/index.html)

Research

[Leadership Compass](/content/research?f=leadershipcompass/index.html) [Buyer's Compass](/content/research?f=buyerscompass/index.html) [Advisory Note](/content/research?f=advisorynote/index.html) [Whitepaper](/content/research?f=whitepaper/index.html) [Executive View](/content/research?f=executiveview/index.html) [Leadership Brief](/content/research?f=leadershipbrief/index.html) [Rising Star](/content/research?f=risingstar/index.html) [Product Value Navigator](/content/research?f=productvaluenavigator/index.html) [Blog](/content/blog/index.html)

Advisory

[Advisory Services](/content/advisory/index.html) [Meet our Advisors](/content/people/index.html) [Strategy Navigator](/content/advisory#navigator/index.html) [Success Stories](/content/advisory#success-stories/index.html)

Events

[IF Impact Day 2026](/content/events/ifid2026/index.html) [AI & NHI Impact Day 2026](/content/events/nhiid2026/index.html) [CIAM Impact Day 2026](/content/events/ciamid2026/index.html) [EIC 2027](/content/events/eic2027/index.html) [EIC 2026](/content/events/eic2026/index.html) [Upcoming Events](/content/events/index.html) [Upcoming Webinars](/content/webinars/index.html)

Videos

[All latest videos](/content/videos/index.html) [European Identity and Cloud Conference 2025](/content/videos/eic2025/index.html) [cyberevolution 2024](/content/videos/cyberevolution2024/index.html) [KuppingerCole Webinars](/content/videos/webinars/index.html) [KuppingerCole Analyst Chat](/content/videos/analystchat/index.html)

Membership

[About](/content/memberships/index.html) [Professional](/content/memberships/single#single-user/index.html) [Expert](/content/memberships/single#single-user/index.html) [Corporate](/content/memberships/teams#for-teams/index.html)

Company

[About us](/content/about/index.html) [Success Stories](/#success-stories) [People](/content/people/index.html) [Jobs](/content/jobs/index.html) [Newsroom](/content/newsroom/index.html) [Cybersecurity Council](/content/cybersecurity-council/index.html) [Technology Providers](/content/technology-provider/index.html) [Contact us](/content/contact/index.html)

[Become a Member](/content/memberships/index.html)

Customer Identity and Access Management

Data and Information Protection

Fraud Prevention

Identity Governance and Administration

Identity Threat Detection and Response

Non-Human Identity

Zero Trust

See All Topics

Research

[Leadership Compass](/content/research?f=leadershipcompass/index.html)

[Buyer's Compass](/content/research?f=buyerscompass/index.html)

[Advisory Note](/content/research?f=advisorynote/index.html)

[Whitepaper](/content/research?f=whitepaper/index.html)

[Executive View](/content/research?f=executiveview/index.html)

[Leadership Brief](/content/research?f=leadershipbrief/index.html)

[Rising Star](/content/research?f=risingstar/index.html)

[Product Value Navigator](/content/research?f=productvaluenavigator/index.html)

[Blog](/content/blog/index.html)

[See all research\\
\\

\\
\\
May 19, 2026\\
\\
Identity Governance and Administration (IGA)\\
\\
\\
This Leadership Compass Identity Governance and Administration (IGA) provides an overview of the IGA market and a compass to help you find a solution that best meets your needs. It examines solutions that provide both identity lifecycle management and access governance capabilities. Solutions have](/content/research/lc80864/identity-governance-and-administration-iga/index.html)

\\
\\
May 18, 2026\\
\\
Privileged Access Management (PAM)\\
\\
\\
This KuppingerCole Leadership Compass provides an overview of the leading vendors in the Privileged Access Management (PAM) market, assessing their innovation, product capabilities, and market presence. PAM solutions enable organizations to control, manage, and monitor privileged access across](/content/research/lc81007/privileged-access-management-pam/index.html)

\\
\\
Apr 29, 2026\\
\\
Managed Detection and Response\\
\\
\\
This KuppingerCole Analysts Leadership Compass provides an overview of the Managed Detection and Response (MDR) market in 2026. It examines services that detect, analyze, investigate, and respond to cyber threats across diverse environments, and evaluates the ability of vendors to deliver](/content/research/lc80871/managed-detection-and-response/index.html)

\\
\\
May 19, 2026\\
\\
Identity Governance and Administration (IGA)\\
\\
\\
Modern access governance is strained by identity sprawl (including non-human identities), complex joiner/mover/leaver lifecycles, manual reviews at scale, and integration gaps that create blind spots. IGA platforms centralize identity/entitlement inventories, automate provisioning and](/content/research/bc81004/identity-governance-and-administration-iga/index.html)

\\
\\
May 18, 2026\\
\\
Privileged Access Management (PAM)\\
\\
\\
Privileged access has expanded from admin accounts to high-impact actions across human, machine, application, and automated identities in dynamic hybrid/cloud environments. Key problems include action-based privilege definition, fragmented visibility, non-human identity risk, privilege sprawl, and](/content/research/bc81009/privileged-access-management-pam/index.html)

\\
\\
May 11, 2026\\
\\
Managed Detection and Response\\
\\
\\
Escalating threats, alert overload, fragmented tooling, and scarce SOC skills drive slow detection and response. Managed Detection and Response (MDR) provides 24/7 monitoring, telemetry correlation, validated detection, and analyst-led investigation/response, augmented by automation and AI. Modern](/content/research/bc81061/managed-detection-and-response/index.html)

\\
\\
May 15, 2026\\
\\
Navigating the Agentic AI Security Landscape\\
\\
\\
Enterprise AI deployments have passed a threshold that most security frameworks were not designed for. Agentic AI (autonomous, tool-using systems that chain actions, delegate to sub-agents, and operate continuously on behalf of users) is already in production across a growing number of](/content/research/an82020/navigating-the-agentic-ai-security-landscape/index.html)

\\
\\
Apr 22, 2026\\
\\
KuppingerCole 2nd Level Reference Architecture for CIAM\\
\\
\\
The purpose of this document is to define the KuppingerCole Analysts 2nd Level Reference Architecture for CIAM, providing a structured and consistent model for designing, evaluating, and evolving Customer Identity and Access Management (CIAM) solutions.\\
It focuses exclusively on capabilities](/content/research/an81080/kuppingercole-2nd-level-reference-architecture-for-ciam/index.html)

\\
\\
Mar 23, 2026\\
\\
Make or Buy: Bringing Structure and Transparency to Strategic Decisions\\
\\
\\
Make or buy decisions are a recurring challenge in Identity and Access Management (IAM) and beyond. While the question appears straightforward, the underlying decision is rarely simple. Organizations must balance multiple, often conflicting dimensions such as cost, functionality, technical](/content/research/an82018/make-or-buy/index.html)

\\
\\
Jun 01, 2026\\
\\
Application Inventory - Identify What to Protect. Are You Missing Critical Assets?\\
\\
\\
This whitepaper examines Application Inventory Management (AIM) as a critical, yet often underestimated, enabler for Identity and Access Management (IAM). It shows how incomplete or poorly maintained application inventories undermine IAM initiatives by increasing manual effort, fragmentation, and](/content/research/wp81148/application-inventory-identify-what-to-protect-are/index.html)

\\
\\
May 13, 2026\\
\\
Governing Third-Party Privileged Access: Moving Beyond VPN-Based Collaboration\\
\\
\\
Organizations rely on third parties that require remote access to internal systems and operational platforms. Managing this privileged third-party access creates operational and security challenges, particularly when external identities fall outside established governance processes. Many](/content/research/wp81146/governing-third-party-privileged-access/index.html)

\\
\\
Apr 22, 2026\\
\\
Access Fabric: Uniting Access Control across Endpoints, Networks and Identity\\
\\
\\
Access Fabric presents a transformative approach in enhancing enterprise security frameworks by integrating identity, network, device, and business signals into a unified, context-aware system. It describes how this new model resolves the limitations of traditional, siloed security practices,](/content/research/wp81140/access-fabric/index.html)

\\
\\
May 11, 2026\\
\\
Tuebora\\
\\
\\
Modern IGA struggles with manual governance, siloed identity data, and rising non-human identities (bots, service accounts, AI agents). Tuebora’s roadmap targets lower IGA TCO via dual AI vs deterministic operation, natural-language configuration in Tuebora Studio, a Neo4j-based Unified Identity](/content/research/ev81301/tuebora/index.html)

\\
\\
Mar 20, 2026\\
\\
NEXIS Platform - IVIP Capabilities\\
\\
\\
Identity Visibility and Intelligence Platforms (IVIP) unify data from IGA, PAM, AM, and ITDR to resolve fragmented access visibility and enable analytics-driven governance. The NEXIS Platform delivers IVIP plus converged IAM/GRC: role management/mining, cross-application SoD, identity graphs,](/content/research/ev81145/nexis-platform-ivip-capabilities/index.html)

\\
\\
Jan 18, 2026\\
\\
Memority\\
\\
\\
Identity Fabrics unify disparate IAM solutions, enabling secure, scalable identity management across complex environments. Leveraging microservices, API-centric design, and Zero Trust principles, these fabrics offer seamless integration and advanced analytics. Memority’s 360° Identity Factory,](/content/research/ev81445/memority/index.html)

\\
\\
May 28, 2026\\
\\
No API Security, No AI Security\\
\\
\\
Every AI system acts through APIs: retrieving context, invoking tools, and chaining decisions across enterprise infrastructure. Yet most organizations govern API security, generative AI defense, and non-human identity management as separate disciplines, leaving the gaps unprotected. This Leadership](/content/research/lb80920/no-api-security-no-ai-security/index.html)

\\
\\
May 15, 2026\\
\\
Crypto-Agility: Managing Cryptographic Change in the Post-Quantum Era\\
\\
\\
Crypto-agility has become an urgent enterprise requirement as post-quantum cryptography, expanding machine identity ecosystems, and growing regulatory expectations expose the risks of treating cryptographic infrastructure as static. This Leadership Brief examines why organizations struggle to](/content/research/lb80919/crypto-agility/index.html)

\\
\\
May 11, 2026\\
\\
Model Context Protocol: The API Security Problem Nobody Is Ready For\\
\\
\\
The Model Context Protocol (MCP) has rapidly become the connective tissue of the agentic AI ecosystem, and it is being deployed at enterprise scale without a mature authentication baseline or reliable runtime enforcement. Security has not kept pace with adoption. This Leadership Brief examines MCP](/content/research/lb80918/model-context-protocol/index.html)

\\
\\
May 15, 2026\\
\\
Rising Star TechJutsu\\
\\
\\
Contact Center Authentication strengthens voice and agent-assisted channels by replacing vulnerable knowledge-based questions with IdP-backed MFA. TechJutsu’s CallerVerify triggers verification from ITSM, collaboration, and IVR tools using Okta/Auth0 or Microsoft Entra factors. OrgVerify adds](/content/research/rs81153/rising-star-techjutsu/index.html)

\\
\\
May 11, 2026\\
\\
Rising Star Bare.ID\\
\\
\\
Bare.ID is a self-funded Wiesbaden IAM vendor (founded 2022) focused on EMEA mid-market needs within Identity Fabrics. Its subscription offering extends Keycloak into a comprehensive package combining Access Management, IGA, and PAM, with strong UI/UX, open-standard APIs, self-service automation,](/content/research/rs81152/rising-star-bare-id/index.html)

\\
\\
Nov 18, 2025\\
\\
Rising Star AuthZed\\
\\
\\
AuthZed provides scalable authorization solutions leveraging SpiceDB for global, fine-grained permissions. Supported by $15.8M funding, their cloud products optimize performance and deployment flexibility. With innovative Materialize technology, AuthZed enhances rapid permission checks. Despite](/content/research/rs81131/rising-star-authzed/index.html)

\\
\\
Mar 18, 2026\\
\\
ManageEngine PAM360\\
\\
\\
Privileged Access Management (PAM) is a priority in hybrid environments where ransomware risk, misconfigurations, and audit expectations are rising. Buyers need rapid, practical governance that fits existing identity and monitoring ecosystems, but must still verify modernization, extensibility, and](/content/research/pv81149/manageengine-pam360/index.html)

\\
\\
Jun 03, 2026\\
\\
From the Floor, Not the Stage: An Advisory View on EIC 2026\\
\\
\\
AI was the headline at EIC 2026, but the real story was the gap between hype and the unfinished plumbing of identity. In hallway conversations and unfiltered case studies, the same theme kept surfacing: teams can’t govern agents they can’t yet govern users, apps, and access. Here’s what surfaced](/content/blog/schuetze/advisory-view-on-eic-2026/index.html)

\\
\\
Jun 02, 2026\\
\\
Your AI Agent Has a Supply Chain Problem\\
\\
\\
Learn how MCP can quietly turn agentic AI into a Log4Shell-like dependency blind spot, and how to get ahead of it. You’ll leave with a practical checklist to inventory MCP endpoints, harden provenance and review of manifests/configs, avoid “valid token = safe code” thinking, and add runtime](/content/blog/balaganski/your-ai-agent-has-a-supply-chain-problem/index.html)

\\
\\
Jun 01, 2026\\
\\
Securing and Governing AI: Why AI Security Requires a Fabric, not a Category\\
\\
\\
AI isn’t “just another app,” and your security stack can’t pretend it is. Prompts can be poisoned, retrieval can be manipulated, and agents can take actions across systems faster than reviews can keep up. The answer isn’t a new category, it’s a connected fabric of identity, data, policy, runtime](/content/blog/gardiner/securing-and-governing-ai/index.html)

Events

[IF Impact Day 2026](/content/events/ifid2026/index.html)

[AI & NHI Impact Day 2026](/content/events/nhiid2026/index.html)

[CIAM Impact Day 2026](/content/events/ciamid2026/index.html)

[EIC 2027](/content/events/eic2027/index.html)

[EIC 2026](/content/events/eic2026/index.html)

[Upcoming Events](/content/events/index.html)

[Upcoming Webinars](/content/webinars/index.html)

[See past events\\
\\

Identity Fabric Impact Day 2026

Identity Fabric Impact Day is a focused, one-day, practice-oriented event for IAM professionals, security leaders, and solution providers seeking hands-on guidance on Identity Fabrics - modular, flexible, and scalable architectures that address identity and access needs across the enterprise.
Identity Fabrics enable secure, seamless access for employees, customers, partners, and machines, while improving efficiency, supporting compliance, and strengthening security across hybrid and multi-cloud environments.

[To the\\
Event](/content/events/ifid2026/index.html) [Call for Speakers\\
\\

AIdentity & Non-Human Identity Impact Day 2026

Join the leading event dedicated to securing and governing non-human identities at scale and learn about AIdentity.
Explore how dynamic credentials, automated governance, and Identity Fabric architectures transform how organizations secure workloads, APIs, and services across multi-cloud environments.
Connect with experts shaping the future of identity automation, where governance meets agility, and ownership is non-negotiable.

[To the\\
Event](/content/events/nhiid2026/index.html) [Call for Speakers\\
\\

Customer Identity & Access Management (CIAM) Impact Day 2026

This event is dedicated to transforming Customer Identity & Access Management (CIAM) into the next era of digital engagement.
Explore how EUDI Wallets, verifiable credentials, decentralized identity, and passwordless authentication reshape customer experiences, trust, and digital safety. Connect with identity innovators, security leaders, and business strategists defining how organizations authenticate, protect, and understand their customers in a global, omnichannel world.

[To the\\
Event](/content/events/ciamid2026/index.html) [Call for Speakers\\
\\

European Identity and Cloud Conference 2027

Join Europe’s leading event on Digital Identity, Security, Privacy, and Governance in an AI-driven world. Connect with a vibrant community and dive into the technologies shaping the future.

[To the\\
Event](/content/events/eic2027/index.html) [Call for Speakers\\
\\

European Identity and Cloud Conference 2026

[To the\\
Event](/content/events/eic2026/index.html) [Agenda Overview\\
\\

\\
\\
Sep 09, 2026\\
\\
Identity Fabric Impact Day 2026\\
\\
\\
Identity Fabric Impact Day is a focused, one-day, practice-oriented event for IAM professionals, security leaders, and solution providers seeking hands-on guidance on Identity Fabrics - modular, flexible, and scalable architectures that address identity and access needs across the enterprise.](/content/events/ifid2026/index.html)

\\
\\
Oct 06, 2026\\
\\
AIdentity & Non-Human Identity Impact Day 2026\\
\\
\\
Join the leading event dedicated to securing and governing non-human identities at scale and learn about AIdentity.\\
Explore how dynamic credentials, automated governance, and Identity Fabric architectures transform how organizations secure workloads, APIs, and services across multi-cloud](/content/events/nhiid2026/index.html)

\\
\\
Nov 18, 2026\\
\\
Customer Identity & Access Management (CIAM) Impact Day 2026\\
\\
\\
This event is dedicated to transforming Customer Identity & Access Management (CIAM) into the next era of digital engagement.\\
Explore how EUDI Wallets, verifiable credentials, decentralized identity, and passwordless authentication reshape customer experiences, trust, and digital safety. Connect](/content/events/ciamid2026/index.html)

\\
\\
Jun 16, 2026\\
\\
Navigating B2B IAM: Leadership Compass Results Revealed\\
\\
\\
As B2B ecosystems grow more complex, managing identities across organizational boundaries has become a strategic priority. In this webinar, KuppingerCole unveils the first results from its Leadership Compass on B2B Identity and Access Management, offering a preview of the Leader chart, key market](/content/events/2026/06/navigating-b2b-iam/index.html)

\\
\\
Jun 17, 2026\\
\\
Rethinking Privileged Access\\
\\
\\
Historically, privileged access was associated primarily with human administrators responsible for maintaining servers, networks, and enterprise applications. That model no longer reflects how organizations operate today. This webinar draws on a Leadership Compass covering over 35 vendors to](/content/events/2026/06/rethinking-pam/index.html)

\\
\\
Jun 24, 2026\\
\\
Redefining MDR: From Alert Handling to Outcome‑Focused Security Operations\\
\\
\\
Cyber threats continue to target organizations across endpoints, networks, cloud environments, identity systems, and connected devices, while many security teams still struggle with skills shortages, operational complexity, and the challenge of maintaining effective 24x7 monitoring and response. In](/content/events/2026/06/redefining-mdr/index.html)

Videos

[All latest videos](/content/videos/index.html)

[European Identity and Cloud Conference 2025](/content/videos/eic2025/index.html)

[cyberevolution 2024](/content/videos/cyberevolution2024/index.html)

[KuppingerCole Webinars](/content/videos/webinars/index.html)

[KuppingerCole Analyst Chat](/content/videos/analystchat/index.html)

[See all videos\\
\\

\\
\\
Jun 15, 2026\\
\\
B2B Identity & Access Management: A New Market Unpacked\\
\\
\\
Business relationships are complex and traditional IAM wasn't built for them. In this episode, Matthias Reinwarth sits down with Principal analyst John Tolbert, author of KuppingerCole Analysts' first-ever B2B IAM Leadership Compass, to explore why Business-to-Business Identity and Access](/content/watch/b2b-iam-new-market-unpacked/index.html)

\\
\\
Jun 12, 2026\\
\\
Is Your CDN Secure? CDN vs. DDoS Mitigation Unpacked with Qrator Labs\\
\\
\\
Speed and security are no longer separate concerns. In this videocast, Osman Celik sits down with Andrey Leskin, CTO of Qrator Labs, to break down what Content Delivery Networks really are in 2026 and why they've become a critical piece of modern security infrastructure, not just a performance](/content/watch/videocast-qrator-secure-cdn/index.html)

\\
\\
Jun 10, 2026\\
\\
From SAP IDM to Modern IGA: Closing the AD Lifecycle Gap Before 2027\\
\\
\\
SAP Identity Management reaches end of mainstream maintenance in December 2027, and every IGA vendor is offering a replacement. But most migration guidance misses a critical gap: organizations following SAP's recommended path to Microsoft Entra will still lack proper Active Directory lifecycle](/content/watch/sap-idm-to-modern-iga/index.html)

\\
\\
May 09, 2025\\
\\
PANEL: The REAL Business Case for Decentralized Identity & EU DI Wallet\\
\\
\\
While the promise of decentralized identity (DID) and the EU Digital Identity Wallet (EUDI Wallet) is often framed in terms of privacy and user control, the real driver for widespread adoption will be compelling business value. This panel will move beyond the hype to examine what truly makes](/content/watch/panel-the-real-business-case-eic25/index.html)

\\
\\
May 09, 2025\\
\\
PANEL: Delegation with Boundaries: Ownership, Accountability, and Trust in B2B Federations\\
\\
\\
As digital ecosystems become more interconnected, organizations increasingly rely on federated identity and access models to collaborate across business boundaries. Yet this reliance raises a crucial question: How much control should be retained internally, and how much can be safely delegated to](/content/watch/panel-delegation-with-boundaries-eic25/index.html)

[![AI at your Service  [Intermediate]](/content/pictures/400/2025_eic_1280-720_miniature.jpg)\\
\\
May 09, 2025\\
\\
AI at your Service \[Intermediate\]\\
\\
\\
Imagine a future where AI seamlessly handles Identity Governance and Administration (IGA) tasks—whether you’re an administrator, a helpdesk agent, or an end user. Instead of navigating complex workflows and esoteric User Interfaces, AI will be at your service, executing tasks through](/content/watch/ai-at-your-service-eic25/index.html)

\\
\\
Dec 05, 2024\\
\\
Transforming Ecosystem Partner Security Risk Management: Lessons Learned and Insights for DORA Implementation\\
\\
\\
As organizations face increasing regulatory demands and evolving cyber threats, effective Ecosystem Partner security risk management has become a critical priority. This session will explore a successful transformation journey in Ecosystem Partner security risk management, highlighting the](/content/watch/transforming-ecosystem-partner-security-risk-management-cre24/index.html)

\\
\\
Dec 05, 2024\\
\\
In der digitalen Arena: Digitalisierung bei Bayern München - aber sicher](/content/watch/arena-digitalisierung-bayern-munchen-cre24/index.html)

\\
\\
Dec 05, 2024\\
\\
Enhancing Cyber Resilience: Integrating Identity Management, Multi-Cloud Strategies, and Advanced Threat Detection](/content/watch/enhancing-cyber-resilience-cre24/index.html)

\\
\\
Jun 04, 2026\\
\\
Unified Governance Across SAP and Business Applications\\
\\
\\
As organizations expand beyond SAP into hybrid ecosystems of SaaS and LoB applications, governance becomes fragmented and inconsistent. Traditional access control approaches no longer suffice, requiring a shift toward holistic Business Application Risk Management that leverages integrated](/content/watch/heterogeneous-it/index.html)

\\
\\
May 28, 2026\\
\\
Beyond SOAR: The Rise of the AI SOC\\
\\
\\
The AI SOC market is expanding rapidly as security vendors race to deliver security automation systems that help deliver smarter triage, improved investigations, and faster responses. But not every AI claim translates into meaningful operational improvement. \\
This webinar examines what is](/content/watch/rise-of-ai-soc/index.html)

\\
\\
Jun 08, 2026\\
\\
PAM Is No Longer a Vault: The New Identity Security Layer\\
\\
\\
Privileged Access Management has outgrown the vault. In this episode, Matthias sits down with lead analyst Alejandro Leal, author of KuppingerCole's newly released PAM Leadership Compass, to explore how the definition of privilege itself has changed, what NHIs and agentic AI mean for PAM, and why](/content/watch/pam-no-longer-a-vault/index.html)

\\
\\
Jun 01, 2026\\
\\
Know Your Attack Surface: ASM, DRP & Brand Protection\\
\\
\\
Not all cyber threats target your systems, some target your reputation, your customers, and your brand. In this episode, Matthias Reinwarth sits down with research analyst Osman Celik to unpack three closely related but distinct markets: Attack Surface Management (ASM), Digital Risk Protection](/content/watch/know-your-attack-surface/index.html)

Advisory

[Advisory Services](/content/advisory/index.html) [Success stories](/content/advisory#success-stories/index.html) [IAM Maturity Assessment](/content/advisory/iam-maturity-assessment/index.html) [Identity Fabric & Reference Architecture](/content/identity-fabric-reference-architecture/index.html)

Advisory Services

KuppingerCole's Advisory stands out due to our regular communication with vendors and key
clients, providing us with in-depth insight into the issues and knowledge required to
address real-world challenges.

[See Advisory Services\\
\\

Contact our advisors

E-mail [info@kuppingercole.com](mailto:info@kuppingercole.com)

[Meet our Advisors\\
\\

Boehringer Ingelheim, a leading pharmaceutical company,
sought to enhance its Identity and Access Management (IAM) capabilities in the
digital age. We collaborated to develop a strategic IAM roadmap in just five months,
aligning their IT infrastructure with their global leadership position.

[View Case Study](/content/success-story-boehringer-ingelheim/index.html)

Global chemical company revamped its Identity and Access
Management with KuppingerCole's IAM strategy: guidance, assessment, roadmap.
Enhanced security and efficiency.

[View Case Study](/content/success-story-leading-chemical-company/index.html)

IAM Maturity Assessment

Discover your IAM maturity level across key areas, benchmarked against KuppingerCole’s Reference Architecture, and receive a personalized report with expert recommendations.

[Get Started\\
\\

Identity Fabric & Reference Architecture

Explore how to unify, modernize, and scale your IAM ecosystem with a consistent architectural foundation.

[Learn More\\
\\

Membership

[About](/content/memberships/index.html) [Professional](/content/memberships#compare/index.html) [Expert](/content/memberships#compare/index.html) [Corporate](/content/memberships#compare/index.html)

Your gateway to Identity Security
excellence

Unlock the power of industry-leading insights and expertise. Gain access to our extensive
knowledge base, vibrant community, and tailored analyst sessions—all designed to keep you at
the forefront of identity security.

[Learn More\\
\\

Stay ahead of industry trends and make informed
decisions

Access essential knowledge at your fingertips with KuppingerCole's extensive resources. From
in-depth reports to concise one-pagers, leverage our complete security library to inform
strategy and drive innovation.

[Learn More\\
\\

Elevate your expertise and expand your
professional network

Gain access to comprehensive resources, personalized analyst consultations, and exclusive
events – all designed to enhance your decision-making capabilities and industry connections.

[Learn More\\
\\

Empower your team with the knowledge and
connections to drive change

Gain a true partner to drive transformative initiatives. Access comprehensive resources,
tailored expert guidance, and networking opportunities.

[Learn More\\
\\

Company

[About us](/content/about/index.html) [Success Stories](/#success-stories) [People](/content/people/index.html) [Career Opportunities](/content/career/index.html) [Newsroom](/content/newsroom/index.html) [Cybersecurity Council](/content/cybersecurity-council/index.html) [Technology Providers](/content/technology-provider/index.html) [Contact us](/content/contact/index.html)

Discover Our Passion for Advancing Identity and Security

We are specialized in the strategic management of digital identities, privileges,
authentication, and access control as well as cybersecurity and business resilience.​

[Read more about our philosophy\\
\\

Success Stories

\\
\\
Empowering Boehringer Ingelheim through IAM Transformation\\
\\
\\
Boehringer Ingelheim, a leading pharmaceutical company, sought to enhance its IAM capabilities in the digital age. We collaborated to develop a strategic roadmap in just five months, aligning their IT infrastructure with their global leadership position.](/content/success-story-boehringer-ingelheim/index.html)

\\
\\
Futurae Technologies AG\\
\\
\\
Futurae Technologies AG, founded in 2016 as a spin-off from ETH Zurich, is a Swiss cybersecurity company specializing in user-centric multi-factor authentication and transaction signing solutions. Their platform combines strong security with seamless user experience, serving banks, insurers, and](/content/success-story-futurae/index.html)

\\
\\
Empowering Tuebora to Innovate in the IGA Space\\
\\
\\
Tuebora, a leading player in the IGA market, partnered with KuppingerCole Analysts to gain critical insights into customer pain points, market challenges, and emerging opportunities.](/content/success-story-tuebora/index.html)

[View All Success Stories\\
\\

Analysts &
Advisors

Meet our team of analysts and advisors who are highly skilled and experienced
professionals dedicated to helping you make informed decisions and achieve your goals.

Business Team

Meet our business team committed to helping you achieve success. We understand that
running a business can be challenging, but with the right team in your corner, anything
is possible.

[Meet the Team\\
\\

Career
Opportunities

\\
\\
Events\\
\\
Wiesbaden\\
\\
Ausbildung zum Veranstaltungskaufmann/-frau (m/w/d)\\
\\
\\
Die KuppingerCole Analysts AG ist ein IT-Analystenunternehmen mit Hauptsitz in Wiesbaden und weiteren Standorten rund um die Welt. Insgesamt beschäftigen wir aktuell rund 50 Mitarbeiter. KuppingerCole unterstützt seine Kunden mit Leistungen in den Bereichen Events, Advisory und Research.](/content/jobs/62/index.html)

[View All Job Offers\\
\\

Latest Press Releases

\\
\\
Press Release\\
\\
May 22,\\
2026\\
\\
KuppingerCole Analysts Wraps Up EIC 2026: Europe’s Leading Identity Conference Explores Digital Trust Through Intelligent Identity\\
\\
\\
The European Identity and Cloud Conference (EIC) 2026 concluded in Berlin after four days of discussions on digital trust, AI-driven identity, authorization, governance, and the future of intelligent identity systems. Hosted by KuppingerCole Analysts, the event gathered over 1,500 attendees, 250+](/content/press-release/eic-2026-wrapped/index.html)

\\
\\
Press Release\\
\\
March 18,\\
2026\\
\\
KuppingerCole Analysts Launches Product Value Navigator to Validate the Business Impact of Technology Investments\\
\\
\\
Product Value Navigator is a new research framework from KuppingerCole Analysts designed to validate the economic value of enterprise technology solutions. By combining independent technical evaluation with financial modelling and open-source intelligence data, it provides transparent insight into](/content/press-release/product-value-navigator/index.html)

\\
\\
Press Release\\
\\
February 19,\\
2026\\
\\
KuppingerCole Analysts and Forum INCYBER Enter Strategic Partnership to Strengthen European Cybersecurity Market Intelligence\\
\\
\\
KuppingerCole Analysts and Forum INCYBER announce a strategic partnership to strengthen European cybersecurity market intelligence, thought leadership, and cross-regional collaboration across France, Benelux, and DACH.](/content/press-release/kuppingercole-analysts-forum-incyber/index.html)

Cybersecurity Council

With the Cybersecurity Council, we bring together world-class information security professionals
in leading positions from across many industries and schools of thought to exchange and discuss
how to secure the rapidly growing cyber economy. The results of these fruitful discussions will
flow into every of our services.

[Learn more\\
\\

Services for Technology Providers

You're building the future in a crowded, skeptical market. KuppingerCole Analysts helps you stand out with neutral credibility, market insights, and direct access to key decision-makers. We empower technology providers with the visibility, insights, and analyst-backed influence to win in a competitive market.

[Learn more\\
\\

Basic contact
information

KuppingerCole Analysts AG

Wilhelmstr. 20-22

65185 Wiesbaden

Germany

[info@kuppingercole.com](mailto:info@kuppingercole.com)

[See all locations\\
\\

Use AI-powered search to answer my question

Use AI-powered search to answer my question

In order to watch this video, you have to log in or create an account, if you don't have one yet.

[Log in\\
\\
 [Register\\
\\
 [Choose your membership package\\
\\

Webinar Recording

### Like this?

### Don't like this?

Log in to make your opinion count! We will also use your feedback to tune your personal recommendations.

Log in to hear your voice heard. We'll also make sure to update your personal recommendations.

[Login](/content/login?back=/watch/enterprise-passwordless-authentication/index.html)

Don't have a KC account yet?
[Join Now](/content/register?back=/watch/enterprise-passwordless-authentication/index.html)

### Why don't you like this?

This isn't relevant for me

I don't like the content

SubmitCancel

2

Save

### Bookmarks

Save your favorite items in your personal watch list so that you can read them later and find them again easily.

[Login](/content/login?back=/watch/enterprise-passwordless-authentication/index.html)

Don't have a KC account yet?
[Join Now](/content/register/index.html)

[LinkedIn [Facebook [X / TwitterCopy URL

# Adopting Passwordless Authentication for Modern Enterprises

\\
\\
Dave Taku\\
\\
VP of Product Management and User Experience\\
\\
RSA](/content/speakers/4014/index.html) \\
\\
Guillaume Teixeron\\
\\
Senior Analyst\\
\\
KuppingerCole Analysts](/content/speakers/3981/index.html)

Posted on May 15, 2026

Close

As cyber threats grow in sophistication, traditional password-based authentication is increasingly inadequate. Enterprises are adopting passwordless approaches leveraging passkeys, biometrics, and device trust to enhance security and user experience. However, this shift introduces challenges around legacy integration, secure recovery, and hybrid IT, while adaptive access and phishing-resistant methods redefine identity assurance and access control strategies.

**Guillaume Teixeron**, Senior Analyst at KuppingerCole Analysts will provide insights grounded in KuppingerCole’s latest Leadership Compass research, highlighting how the passwordless authentication market is evolving, what capabilities define leading solutions, and where vendors are differentiating. He will also examine key enterprise considerations, including deployment flexibility, orchestration, and support for hybrid and regulated environments.

**Dave Taku**, VP of Product Management and User Experience at RSA, will contribute a hands-on, practitioner perspective. With over 25 years in cybersecurity and identity, he will share practical insights on deploying passwordless authentication at enterprise scale, drawing on real-world experience from building and operating modern identity platforms.

Lead Sponsor

Video Description

Short Summary

Interesting Facts

Recommendations

Takeaways

Lorem ipsum odor amet, consectetuer adipiscing elit. Luctus fames rutrum metus habitasse donec quis turpis.

Nibh porta tristique sociosqu eleifend condimentum sapien ultricies. Dapibus rhoncus urna elit commodo blandit ut vestibulum tristique. Ante parturient morbi maecenas leo ac est dolor aliquam iaculis.

Leo vehicula vivamus ipsum lacinia cubilia torquent accumsan! Viverra a dictumst dapibus; nam consequat felis mus. Euismod semper iaculis congue mauris nullam.

Sign up and get more insights

Become a member of the KuppingerCole Community to access this and thousands of other publications.

[Log in or register\\
\\

Lorem ipsum odor amet, consectetuer adipiscing elit. Luctus fames rutrum metus habitasse donec quis turpis.

Leo vehicula vivamus ipsum lacinia cubilia torquent accumsan! Viverra a dictumst dapibus; nam consequat felis mus. Euismod semper iaculis congue mauris nullam.

Sign up and get more insights

Become a member of the KuppingerCole Community to access this and thousands of other publications.

[Log in or register\\
\\

Lorem ipsum odor amet, consectetuer adipiscing elit. Luctus fames rutrum metus habitasse donec quis turpis.

Leo vehicula vivamus ipsum lacinia cubilia torquent accumsan! Viverra a dictumst dapibus; nam consequat felis mus. Euismod semper iaculis congue mauris nullam.

Sign up and get more insights

Become a member of the KuppingerCole Community to access this and thousands of other publications.

[Log in or register\\
\\

Lorem ipsum odor amet, consectetuer adipiscing elit. Luctus fames rutrum metus habitasse donec quis turpis.

Leo vehicula vivamus ipsum lacinia cubilia torquent accumsan! Viverra a dictumst dapibus; nam consequat felis mus. Euismod semper iaculis congue mauris nullam.

Sign up and get more insights

Become a member of the KuppingerCole Community to access this and thousands of other publications.

[Log in or register\\
\\

Top related content

\\
\\
Advisory Note](/content/research/an80979/passkeys-in-practice-security-usability-and-the-post-quantum-horizon/index.html)

Passkeys in Practice: Security, Usability, and the Post-Quantum Horizon

Jul 24, 2025

\\
\\
Leadership Compass](/content/research/lc80877/passwordless-authentication-for-enterprises/index.html)

Passwordless Authentication for Enterprises

Sep 03, 2024

\\
\\
Buyer's Compass](/content/research/bc81002/passwordless-authentication-b2b/index.html)

Passwordless Authentication B2B

Mar 17, 2026

\\
\\
Buyer's Compass](/content/research/bc81001/passwordless-authentication-b2c/index.html)

Passwordless Authentication B2C

Jan 29, 2026

\\
\\
Blog](/content/blog/ashford/beyond-the-password-making-identity-the-living-perimeter-of-cybersecurity/index.html)

Beyond the Password: Making Identity the Living Perimeter of Cybersecurity

Oct 15, 2025

\\
\\
Buyer's Compass](/content/research/bc81271/passwordless-authentication-for-enterprises-and-consumers-hid/index.html)

Passwordless Authentication for Enterprises and Consumers: HID​

Nov 15, 2024

\\
\\
Leadership Compass](/content/research/lc80894/passwordless-authentication-for-enterprises/index.html)

Passwordless Authentication for Enterprises

Mar 10, 2026

\\
\\
Blog](/content/blog/neuenschwander/the-second-law-of-authn-dynamics/index.html)

The Second Law of AuthN Dynamics

Aug 28, 2023

\\
\\
Advisory Note](/content/research/an80916/analyst-s-view-passwordless-authentication-for-enterprises/index.html)

Analyst's View: Passwordless Authentication for Enterprises

Sep 11, 2024

\\
\\
Leadership Compass](/content/research/lc80914/passwordless-authentication-b2c/index.html)

Passwordless Authentication B2C

Jan 29, 2026

Hide Transcript

Show Transcript

Hello everyone, welcome to this KuppingerCole webinar on enterprise passwordless authentication. I am Guillaume Teixeron, Senior Analyst at KuppingerCole. Today's session is based on my latest leadership compass on the passwordless authentication B2B market, and at the end of my presentation I will be joined for a moderated conversation by Dave Taku, VP of Product Management at RSA. Hello Dave. So let's start. A little bit of housekeeping information before we start. You are all muted, don't worry, no need to mute or unmute yourself, everything is under control.

Pause, there will be two pauses along this presentation. You will be able to participate with filling your answer in the panel in the livestorm tool.

Q&A, there will be a Q&A session at the end of this webinar. Make sure you participate, happy to answer, feel free to fill in your question in the livestorm control panel. And finally, everything will be made available for download in the coming days. I don't know the exact date, but in the days to come. So you will have everything including recording and slides. So let me start by getting your attention with two numbers. Two Airbus phone calls over half a billion dollars in losses.

In 2023, attackers called the Las Vegas MGM Resorts, IT Airbus and impersonated an employee. They convinced the support staff to reset multi-factor authentication. The breach cost MGM around 100 billion dollars. In April 2025, the same playbook was used against Marks and Spencer in the UK. The estimated profit recognized by the company exceeds 300 million pounds.

Now, here is the part most people miss. Not a single password was cracked in either attack. The attacker didn't break authentication. They went around it through the recovery flows. Most organizations in this digital virtual room have certainly deployed MFA. Many of you have deployed passkey probably. And most still have an Airbus recovery flow that would have failed in the exact same way. That is the uncomfortable truth I want to start with. Because passwordless without recovery hardening is just theater.

Here's what I want you to take away from the next 25 minutes before I bring Dave from RSA for a practitioner perspective. First, I want you to understand where this market actually stands in 2026. Not where vendors say it is, but where buyers experience it.

Second, you will be able to evaluate solutions on the dimension that now matters most. I will give you three points. Why passkeys are now the baseline and not the differentiator. Why recovery is a real test of any passwordless project. And why device trust and adaptive risk now belong inside the authentication decision itself. And finally, and this is the practical one I want you to live with, you will know which question to put in your next RFP. If you only stay for the next 20 minutes, 25 minutes, you will live with all three. So let's start from there. Here is where the market stands.

Passwordless authentication has shifted from emerging best practice to structural requirement for enterprise identity security. That is the conclusion I want to learn first. Four forces are driving this shift.

First, phishing-resistant authentication is now the minimum acceptable level. OTP, SMS, push-only MFA no longer meet most risk and compliance requirements. In a report very soon, and the report was the Data Breach Investigation Report. In one of their report, they confirm it. Stolen credentials remain the number one initial access vector of breaches at 22%. The second point is that passkeys have moved from novelty to baseline. They are supported across all major operating systems now. The adoption barrier is no longer technical.

The third point is the fact that zero-trust programs have raised the bar. Authentication is no longer a single moment. It must combine cryptography with continuous contextual verification. What was a differentiator years ago, two years ago, is now considered standard. And vendors who have not evolved are visibly falling behind in the leadership combat. And there is a fourth force, naming regulation.

In Europe, EIDAS-related initiatives align public sector identity program with phishing-resistant assurance level. In the US, NIST has formalized AM2 and AM3 requirements that now explicitly call for hardware-bound phishing-resistant authenticator. In financial services and critical infrastructure, sector-level regulations are increasingly referencing this framework directly in their criteria. The practical consequences for buyers in regulated industry, in the industry, in banking, in telco, and so on, is that being passwordless is no longer purely a security decision.

It's a compliance obligation. And that changed the procurement conversation. Beyond that, even if regulated and large enterprises are leading investment, we see that mid-market adoption is now also accelerating. As cloud-delivered and OS-native capabilities reduce the implementation, everything is there to accelerate. This market is not broadening.

Sorry, this market is broadening. It's not narrowing. It's expanding. But adoption is uneven. On one side, what is now mature, you do have the success, the modern web application, the managed Windows and macOS endpoint, file-to-server availability, the easy half of the estate is largely sold. This is there. This is a problem. It works. But on the other side, you have what is still hard to tackle.

All the legacy applications we are all running since years, Reduce, VPN, VDI, shared workstation, the management of contractors and partner access, and obviously at the bottom of the list, the most critical, the recovery. So the enterprise passwordless conversation is no longer about authentication method per se. It's about recovery and assurance across the full estate. And I'm curious to know where is your organization today on its passwordless journey. So here is a quick poll. You can see the option on your screen. Take a moment to answer.

Your responses will tell us where most of you actually are, and I will reflect on the results in a moment. So where do you feel that your organization is today? Still passwordless with MFA, fast key deployed for some application, passwordless across most workforce access, fully passwordless, including recovery. Okay. So let's move with the triple advice I wanted to give you, and let's start with the first one. You should treat fast keys and 502 as the minimum, not the differentiator. Three pieces of evidence to support that statement.

If you read the leadership compass, virtually all leaders now ship 502 and web of fast keys alongside platform authenticators, like Windows Hello, Touch ID, Face ID, Android biometrics. All of them. Second one, second point supporting that statement, operating system level fast key operating system level fast key support, it has removed the historical adoption barrier. The fact that all the operating system, the major operating systems support fast keys, the barrier is gone. Let's be honest. The question is no longer whether user can use fast keys. It is whether the enterprise can govern them.

And the third point is that OTP, SMS, and push only MFA are explicitly called out as no longer sufficient for most risk and compliance requirements. So what? So stop evaluating vendor on whether they support fast keys. Evaluate them on how they govern fast keys at enterprise scales. So what does that mean? What governance of fast keys actually mean? Four different things. Four different pillars should be used to answer that question.

First, the environment. Credentials should be issued against a verified identity, not via anonymous self-service. Wherever you bind that fast key to, you need to know who they actually are. Device binding. Credentials must be cryptographically bound to hardware-backed key storage.

TPM, secure enclave, or equivalent. Without this, you do not have phishing resistance. You have a stronger password, and that's not what you want. Lifecycle. The automated provisioning and deprovisioning across managed device and personal device. When someone leaves, their access goes with them without negotiation. And the fourth one, recovery, which is the next line because that is where most projects quietly fail. So let's focus a little bit on recovery. That's my Power BI 2, and this is where I want you to lean in.

If your recovery flow uses a password, an SMS, or a security question, you are not passwordless. Three pieces of evidence to support that statement.

First, post-mortem breach analysis states explicitly that most authentication failures occur during onboarding, re-enrollment, or recovery, not during regular login. Second, many vendors still allow fallback to email OTP, SMS OTP, or knowledge-based questions during the recovery flow. The moment you do that, you have reintroduced the phishable factor that passwordless was supposed to eliminate.

Third, and this is the operational reality, helpdesk-driven recovery is now an active attack vector. The group behind the MGM, and Marks and Spencer attack, and many others, they succeed in almost every public 2025 incident by calling the helpdesk. So what? So you must evaluate passwordless projects by the strengths of their recovery and lifecycle control, not only by their authentication method. And there is a corollary to the recovery program that I want to name, because buyers frequently miss it. If enrollment was weak, your recovery cannot be strong.

Several leaders in the leadership compass have built identity proofing directly into their enrollment workflow. Needs to align onboarding, or government ID verification, or some sort of biometric proofing, but at the moment, the user first buying their credential. The logic is simple. Recovery is only as strong as the identity you can verify at re-enrollment. If you enroll with a corporate email confirmation, your recovery will rely on the corporate email confirmation, which is phishable, which is TIA.

The vendors who close this gap are the ones who treat onboarding and recovery as two sides of the same identity assurance problem, not as a separate helpdesk workflow. The RFP implication of that is that you should ask vendors what identity assurance level they target at enrollment, not just at login, and what recovery pattern they support.

Because, according to me, three recovery patterns enterprise should now require. The first one, the verified device rebinding. Re-enrollment is gated by possession of a previously trusted device or other authenticator. The user proves they still control the original credential, so they can recover.

Second, identity proofing bake recovery. Government ID verification or biometric reproofing replace knowledge-based questions. The recovery becomes as strong as the original onboarding. And the third one, the policy control helpdesk assisted flows. The helpdesk is involved, but the process has administrative oversight. Audit trace, out-of-band verification, and clear escalation. Not a self-service form filled with old and so on. These three patterns are the difference between a passwordless project that holds and a passwordless project that becomes a 1 million dollar headline.

The third power point I want to share with you is that authentication is no longer a single moment. It's a continuous decision. Strong cryptography alone is not enough. Device posture and contextual risk now decide whether or not to Strong cryptography alone is not enough. Device posture and contextual risk now decide whether a credential is honored or not. The first evidence of that and that is identified in the leadership compass is that the device trust and posture are core elements of the passwordless authentication. Not optional add-ons. Core.

The second one is that adaptive risk engines that evaluate IP replication, geovelocity, device health, behavior, anomalies, name it, are now standard among the leaders. The vendors who don't have them, they are visibly behind. The third evidence I want to share with you is that integration with MDM, UEM, and EDR determines how reliably you can distinguish a managed device from a personal device from a shared workstation. And without such integration, your policy is simply guessing. So what to take from that?

So as a buyer, you should require device posture and adaptive risk as part of the authentication decision itself. Not as a separate access control. It should be included. It should be part of the solution. And this brings me to a capability the leadership compass calls out as a meaningful differentiator between the two. The leadership compass calls out as a meaningful differentiator among vendors, that is orchestration. A mature passwordless platform does not just evaluate signals. It acts on them through configurable policy joining.

A user logging in from a managed device, from LC device, on a trusted network, at a normal time, passkey alone. That's fine. The same user on an unregistered device from an unusual location, step up, additional biometric confirmation or blocking. Vendors have invested heavily in what the leadership compass calls journey orchestration. This is the ability to design these flows without writing code. Conditional access rule, multi-stage authentication, recovery procedures, all configured through policies, not through engineering, tickets, integration, development, blah, blah, blah.

The buyers who get this right stop thinking about authentication as a control point and start treating the authentication as a policy surface. Every authentication event becomes an enforcement moment, not just an identity check. And for architects in the audience, if any, the question to ask is whether the platform exposes the policy engine you own or whether you are locked into vendor-defined flows. And that's a very important question to ask. Three buyer questions you can take into your next RFP based on that. The first one, how does the vendor evaluate device health and binding?

And especially, does it work consistently across managed, personal device, and shared workstations? Because vendors will demo on managed windows, but the R scenarios are the rest. The second one you should bring with you, which contextual signals does the risk engine actually consume? IP reputation, geovelocity, device posture, behavioral anomalies, and critically, can policy act on them in real time? Can you allow step-up denied automatically at the moment of the authentication? These are questions to ask. And the third one, how does it integrate with your existing stack?

Your MDM, your UEM, your EDR, your SIEM, natively or through custom work? Because the answer determines whether you deploy in three months or in three years. That being said, I would be curious, you knowing what I just introduced for the moment, which of these is the biggest gap in your current authentication strategy? As you wrote, let me share what I expect and what we tend to see in that vis-a-vis work. Most organizations underestimate gap number three, recovery and enrollment. But I'm curious to see what is for you the biggest gap at the moment.

The phishing-resistant method deployment at scale, the management of the device, trust, and posture, your recovery and enrollment, or your capacity to play with adaptive risk and contextual access. Wherever you place your vote, the next two slides give you the inline takeaways and the action to work out with.

So, three things to take with you. If you remember only three things from this session, remember this. Phishing resistance is the fraud. Select vendors on how they govern, pass keys, not on whether they support them, because they must. Recovery is the real test. A passwordless project that recovers with a password is not passwordless. And the third one, authentication is now a continuous decision. Device trust and adaptive risk belong inside the framework. Before I conclude, let me give you one market observation that will shape how you read the vendor landscape.

So, the leadership compass identified 50 overall leaders in this market. This is a large number, and looking across them, a clear superposition of the top 50 50 overall leaders in this market. This is a large number, and looking across them, a clear superposition has emerged between two buying archetypes. The first archetype is the platform consolidator. Vendors who embed passwordless directly into their broader IAM suite. If you already operate their platform, adoption is lower friction.

The trade-off is that passwordless becomes one capability among many, and the assurance depth may be shallower than a dedicated solution. The second archetype is the specialist. Vendors who are built specifically around high assurance device-bound passwordless. Their differentiation is depth. Tighter posture integration, stronger recovery hardening, more granular credential governance. The trade-off is integration work alongside your existing IAM stack. Why does this matter? Because when you evaluate vendors, you are not just evaluating features, you are also choosing an architectural question.

Add onto your existing platform or introduce a dedicated authentication thing. There is no universally right answer to that question, but the question belongs in your RFP because you see the first demo. I will finish on that slide, and I will give you two concrete actions I advise you to take for next Monday morning. The first one is audit your current recovery flows. Map every fallback factor. If any are fishable, that is the first project, not your next RFP, your current testing. Second one, add the three bias questions from this session to your next RFP.

Passkey governance, recovery patterns, device trust integration. And three, use the leadership compass as a starting point for shortlisting and pair it with a proof of concept against your actual estate, including the legacy and shared device scenarios. The vendors who demo well or manage windows are not always the ones who survive contact with reality. This is my analyst view of the market, and to bring this back to the operating reality, I would like to bring in Dave from RSA who has been working with enterprise on exactly this question.

Dave, welcome back. Give us a little bit of an introduction of you and your job at RSA and present us where you sit at RSA, what has changed the most in enterprise passwordless conversation over the past months, and what has surprised you?

Yeah, well, happy to, and welcome everyone here to the webinar today. So RSA has been, for the last 35 years, one of the leaders in multi-factor authentication and now passwordless solutions.

I think what's unique and maybe a perspective that Yeom I can bring in this conversation is that as the vice president of product management at RSA, I've had the opportunity to work with and consult with hundreds of different customers, enterprises, nationally, internationally, of all sizes on their passwordless journey, but even more so as RSA, you know, we take this very, very seriously and we are our own first and probably most difficult, challenging, and demanding customer.

We embarked on this passwordless journey ourselves, and over the course of about six months of time, we were able to get to a point where today we are about 94% passwordless for all users and use cases across RSA, right? So, I mean, we've lived this, we've breathed this ourselves, and so I can bring a perspective not only as a vendor and a consultant of authentication solutions, but also as a practitioner helping to roll out these solutions and as an end user, right? And I do think that the end user perspective is very, very important.

It's something that I'd love to dig into a little bit more as we go, you know, through this particular conversation. As far as what I've seen in the market over the last 12 to 18 months, I think you hit on something really important, right? FIDO has really reached the stage of maturity within the market today, and I think there's a couple of key things that are really driving that. Not only is FIDO now ubiquitously supported across all major web browsers and a lot of the operating system platforms, but I think there's been two significant changes over the last 12 to 18 months.

First is that FIDO historically was really the domain of hardware authenticators, right? I mean, you saw a lot of hardware token-based solutions, and yes, the FIDO specs did have the UAF standards, which allowed for interaction within a mobile app, but the ability to use your mobile phone as an authenticator, as a companion device authenticating to other systems, which is something that people have become very familiar with in the MFA world, was not possible until very recently with the addition of the hybrid transport specifications in the FIDO.

So now the ability to use either a mobile device or hardware authenticator really opens up, I think, FIDO technology to the masses and a much broader set of users. I think the second thing that I've seen is that FIDO has now really hit mainstream within the consumer world, and much like we saw with technologies like Face ID and Touch ID, as users become more familiar with using these technologies in their personal lives, the ability then to adopt those within the enterprise becomes much, much stronger and much easier. And so today, I think FIDO has actually done a fantastic job on this.

If you're interacting with a mobile app and you go to your favorite consumer service, whether that's an Amazon or an eBay or something like that, and you're asked, well, would you like to use Face ID next time you log in instead of a password? You say, yes, I would. What many people don't actually realize is that Face ID is just the first factor unlocking the FIDO passkey underneath.

So I mean, FIDO passkeys are very ubiquitous in the consumer world. And it's interesting to see now, even like my father was asking me about passkeys the other day, right?

I mean, this is something that's become mainstream, and those things are all helping to drive adoption within the enterprise. We're also seeing that even within the FIDO Alliance, the FIDO Alliance now is starting to focus much more on enterprise use cases. And RSA is a co-leader within many of the workforce specific sub-working groups within the FIDO Alliance to help drive the necessary supporting standards, things like how we handle recovery and how we handle secure enrollment to really make this an enterprise-grade solution.

So I think one of the things that's really surprised me the most so far is that, I think similar to your poll, it'd be interesting to see the results there, is that as I speak with customers and even at the CISO level, I think everyone today now is saying, yes, we know we need to go passwordless, we know the phishing risk is real, we know we need to do something about that. But I think a lot of folks are still struggling with how to take the first steps of that journey. They're looking to their peers, they're looking to others for advice.

And so that's why I think a webinar like this is so valuable today. That's very interesting to hear. And when we discuss with large enterprise that they do not run a single user population. They have employees, contractors, frontline workers, privileged administrators, or whatever. So from a product standpoint, what does it actually take to deliver phishing-resistant authentication consistently across all of those different populations in a coherent manner for those enterprises? So it's a challenging problem. It's one that even we RSA face as we are rolling out passwordless internally.

If you have a workforce employee, it's much easier to dictate particular terms or even to justify the investment of a hardware-based passkey. If you're working with contractors or external parties, that becomes more challenging, not only the cost aspect of a hardware authenticator, but also secure distribution and management of those keys and recovery of those when people are on a short-term contract. And so having that range of authentication options I think is really important.

So as I mentioned earlier, hardware authenticators and mobile passkey options provide a lot of additional flexibility. I think the other challenge that large enterprises are seeing today is that a traditional large enterprise may be using a lot of SaaS applications and services fronted by web services on the front end, but there's also a lot of legacy infrastructure in those environments.

And so whether these are servers in your data center, your IT or your OT infrastructure, or other legacy applications, there are a lot of use cases in which it's not necessarily easy to use something like a FIDO passkey technology. So one of the things we had to look at, and we advise our customers on as well, is to understand what your phishing risk is in those various different environments, and don't settle for a password. If FIDO is not possible for a particular use case, settling on password is not enough.

There are other multi-factor and passwordless options that you can use to help plug those gaps. And so for example, if you're looking at a mainframe infrastructure within a data center, the phishing risk or attack surface there is much different than it would be for a SaaS-based application. So something like an OTP, for example, may work very well in that type of environment, and it doesn't have the same level of phishing resistance as FIDO, but is certainly far better than a password.

And if it's a time-based OTP, then that attack window would have to be a very specific spear phishing type of attack, and have to be able to leverage that in real time, right? So use FIDO wherever you can, but if you can't, then use something equivalent. So where that becomes interesting then is that if you have users in your population, and some have hardware, some have mobile, and you have some applications that are FIDO, others are using OTP, user experience is where the rubber hits the road, where the real challenge comes into play.

So when we rolled out these solutions internally, we did an experiment on ourselves, right? We knew that ultimately where we are today is we're FIDO everywhere we can, everywhere that's possible to use FIDO, we're using FIDO. But at first, we made every authentication method available to every user just to see what would happen. And we knew what was going to happen, but we played out the experiment anyhow. Sure enough, people got very, very confused that, you know, the experience was different every single time they went to a different application.

And so what we kind of really settled in on that was there seemed to be sort of a nice complement between a couple of passwordless authentication methods. Again, FIDO wherever you could, but then also QR code and OTP. Those three seem to naturally kind of work together, particularly OTP and FIDO, because you can have a hardware authenticator that supported both methods, you can have a mobile authenticator that supported both methods. And if you implement it correctly, you could have a unified user experience where the user really doesn't have to think about the underlying technology.

So imagine the user experience, I come into an application, I'm asked to authenticate, either I pull out my mobile phone, or I stick in my FIDO passkey, security key, and I'm asked to enter a PIN. And from there, the technology magic happens, right? It doesn't matter if that magic is a passkey interaction, or if it's an OTP submission, we can make that experience such that it's invisible to the end user, right? So we're using technology to apply the right credential in the right place, but the user doesn't have to think about that.

That was a really, really important part of us being able to drive successful user adoption within our enterprise. Yeah, there is no one single solution. There is a portfolio of solutions, and you should pick the best one for the best application. Right. And one of the points that I try to make in my presentation is about the recovery flow.

That is, for me, where most of the projects face when we talk about passwordless. They want to eliminate the password, and at the end, they use the password to recover from a passwordless solution. So I'm curious about your point of view, and whether a recovery flow that doesn't break the passwordless promise actually looks like in practice, according to you.

Yeah, so I really appreciate your presentation, right? Because this is something that, as Arash said, we've been saying for years, that phishing resistance is the first step. But in order to really secure the passwordless ecosystem, you need to go beyond phishing to address a number of other factors, right? And so the recovery, the enrollment, these are the types of what we call bypass attacks that we've seen at MGM and in other places where attackers don't need to steal a credential. They don't need a hacker credential, right?

They can just request a credential, whether that's through a self-service portal or by compromising the help desk. So this is a narrative that I would say, as we've spoken with our customer base, has really, really resonated. Regardless of where folks are in their passwordless journey, they realize that they're already behind the eight ball because the attackers have changed their tactics and are going off of these weak enrollment processes. So there's a couple of things I would say, right?

And you laid out, I think, some good recommendations of options that you can begin to use, whether that's identity verification or some sort of a secure device rebinding. A couple of things I would say. Number one, your enrollment process and your recovery process has to be multi-factor, right? It can't rely on a single factor and it certainly can't rely on a factor that's knowledge-based.

I mean, not only if we think passwords are bad, right? It's even worse when you go to a help desk interaction and you're using knowledge-based questions, like what's your manager's name or your employee badge ID, right? So we have to eliminate those from the equation. So anywhere you can use multiple factors.

Now, I'm not a fan of SMS OTP or email OTP, right? I mean, those things are very, very weak, particularly when used in isolation. But if you have to use a known phone number or known email as one of multiple factors, it's still better than just using a password, right? And the other thing that, as you talked about, continuous authentication, the ability to use risk-based context as part of that interaction, I think, is really, really important as well. So it's really all about a defense in depth type of strategy.

If you can go back to something like an identity verification, I think that's fantastic, right? But there is certainly a burden or a load on end users to have to have a password or driver's license and go through that type of a process for recovery. And depending on your risk profile, that may be what you need to do. But there are other ways of being able to match multiple factors plus risk to be able to achieve that as well.

Now, one of the most interesting areas is definitely the help desk, right? Because when you're in a self-service portal, you're doing things electronically, you have certain tools available to you. Classically, when you're talking to a help desk, whether that's over a telephone or via Teams chat or Slack chat, you don't have as many tools available to you to be able to do that, right? And so there's two different attack vectors that we see.

Attackers pretending to be end users requesting credentials from the help desk, and also attackers pretending to be the help desk contacting your end users and tricking them into providing their credentials. So it's really important that whatever solutions you use, and RSA has rolled out a solution called LiveVerify, for example, that is able to do bidirectional authentication, authenticate the user to the help desk and the help desk to the end user, and to do that electronically using the means that you would have similar to an authentication or identity verification flow.

And so we've seen those types of solutions to be very powerful in terms of plugging those particular gaps within the recovery process. Okay, good to understand. I hadn't thought about the two-way authentication. You go both ways, yeah. And that's true because, yeah, someone tried to call me pretending being my bank, but that's the same thing with help desk. They can pretend to be the help desk.

Yeah, and you talk about adaptive risk, and that's also something I mentioned in my presentation, but I advertise and I talk about that for years, but I think that there is a kind of momentum around that. But from a product perspective, what is the hardest part of getting that right at scale? Because this is not simple to move from yes or no authentication to adaptive authentication. There is a kind of philosophical gap around that. And so from your side, how do you see that? How do you pitch that? What do you see as a journey for the future?

Yeah, so I think there's a lot of moving parts involved, right? So many solution providers today, including RSA, will have risk engines that use things like behavioral analytics and conditional variables to understand the risk level of a user attempting to access a particular resource. The problem there is that authentication is a front door, right? So once a user passes through a front door, typically these authentication systems lose visibility. So you mentioned things like device posture, right?

These are very important sources of input into these authentication products to understand a level of risk associated with these solutions. Now, if you have something like a managed Windows PC or managed Chrome browser or Edge browser, then you have tools available to be able to extract that information from a posture perspective or your MDM. When you deal with unmanaged devices, which is far more common when you talk about mobile authenticators, that's where things become a little bit more challenging.

And so one of the things RSA has done is we've taken mobile threat detection technology and embedded that directly within our authenticator app as a part of a solution called mobile lock so that we can do device posture even on unmanaged mobile devices. But I think where the industry is going is in order to get to continuous authentication, we really need to have a better understanding of what happens after the user passes through that front door, right?

So I'm really excited about a lot of the work that's going on right now around the shared signals framework and more vendors beginning to adopt this particular standard, which will allow more of your security ecosystem to share information with each other around risk in a standards-based way, right? So imagine, if you will, an authentication product like RSA, we evaluate risk as the user passes through the front door, everything's fine, but after that user passes through that door, they start doing really weird things within that target application.

We want to be able to know about that so we can not only terminate that session, but if we're involved in a single sign-on solution as well, that we may want to terminate other sessions associated with that user as well. We maybe want to be able to report that activity to the SIEM. We may want to flag that within a governance system for account review.

And so that ability to share information within the ecosystem has traditionally been one of the most difficult problems out there, but with shared signals framework, this is something that hopefully over the next couple of years has become far more standardized, and that's one of the things I'm most looking forward to here.

Okay, but one of the things I see about the continuous authentication concept and adaptive risk and so on, it works very well for the last generation of application and so on, but as everybody, we have to deal with legacy application, with our former reduced authentication, authenticated application and VPN and so on. So for all of those legacy ecosystem, if I may say, how realistic is it today to bring those systems into a passwordless solution? What is the gap to switch to an adaptive risk model?

How do you see that the people transitioning to more modern authentication, that is a requirement today? Right, yeah. So for legacy systems, it's far more challenging to do things like risk analytics. A lot of what you see of these risk engines today are really assuming a browser interaction, the ability to pull information through the browser.

Now, if you have a radius channel, you get zero information about what's going on on the client side, other than a username and a password or an OTP or something else that you've submitted through that channel on behalf of the user. The good news is that if you take a look at your overall ecosystem, 90% of your users aren't using those applications, right? You have privileged administrators, network administrators, other key people. So if you can begin to sort of assess and refine, you can limit the scope of where those types of situations exist.

And we found that at RSA, very similar to that, it was only less than 10% of users who were really involved in those types of legacy applications. At that point in time, then you want to do the best that you can, right? Apply the strongest forms of authentication, even if FIDO is not a possibility in those particular use cases. But then you also want to look at how you're going to manage and migrate those solutions over time.

So it may not necessarily mean migrating a legacy solution to a cloud, but even if we can change the integration point from being radius-based to an agent-based, for example, that agent code then provides a vendor with more ability to collect at least basic intelligence information like IP address and do geolocation and other things based on that, right? So there is a migration path even for some of those legacy applications. Okay.

One of the points I try to make is the importance of identity verification before the passwordless journey and everything around government ID checks and biometric proofing and so on. How do you see that? Is that discussion you do have in parallel of the passwordless discussion you may have? Is it well understood that it's, and maybe it's only my opinion, but that's the foundation of starting your passwordless journey because you can only prove an identity that is strong enough at the beginning.

So it is something that you need to account, it's the same conversation or you push that message on the side of the passwordless journey? Yeah, so it is a very important part of the story and it's a conversation that we do have with all of our customers as we look at how we go to beyond phishing and protecting against bypass attacks and other things like that. Identity verification solutions, there's a number of them on the market today. They have very broad coverage now where virtually whatever country you're in, you have the ability to use government issued documentation.

I would say that it does put some burden on the end user. You have to be able to find your passport. Most people don't have that on them every day of the week. So for a credential recovery use case, it becomes a little bit more challenging. For initial onboarding, it's the same thing that you would do when you join a company and you get vetted by your HI department. So I think it works really great in those onboarding use cases. Now what we are seeing and I think the next level of this is this move towards verifiable digital credentials.

We see a number of projects within the EU like the IDaaS project that is starting to standardize different types of verifiable credentials. But I think that's going to make it much easier for end users to be able to participate in these processes and then also to be able to have control over what information they share and only sharing what is necessary as part of that onboarding process. So I do think that as these types of solutions become more ubiquitous, that the identity verification process is going to become much easier.

Yeah and I agree with you and identity verification to me will be where passwordless is today. I mean it will be a standard for everyone in the next months or years to come. Maybe a last question before we switch to the final question. If you were on the buyer side this time, what you would prioritize that organizations constantly underestimate according to you and what would be your first topic you would tackle if you would be in the user side of the equation? Yeah so I think I've seen two different broadly speaking two different types of behaviors out there.

I've seen some organizations that have said yes we must go passwordless. They jump straight into it. They roll out FIDO for their SaaS applications. They're very successful but then they get stuck because they don't know where to go next with that. And they may have chosen a solution for FIDO pass keys, not thinking about those next steps of credential recovery and enrollment and identity verification or even how to apply equivalent solutions to legacy applications within their enterprise.

The other type of scenario I've seen is one in which an organization does recognize those, kind of gets a little scared or overwhelmed by the options available and then they get paralyzed and they do nothing. So our advice has really been don't try to boil the ocean. Start small. Start with your most critical and exposed assets. So it's great to start with SaaS. Those things are outside your perimeter. Start with perimeter security, your desktops and your laptops, particularly if you have users who work remote or carry sensitive information.

Work your way back in to the center of your environment. Once you get in the data center, far more secure and far fewer number of folks who are touching that. So start outside in, plan your journey, understand where you're going, but don't let perfection be the enemy of good enough. If you can't apply FIDO today, that's fine. It's not an excuse for staying with passwords. There are other options available to you to help you bridge the gap. That makes sense and I agree with that. Now we are on schedule and we have a few questions in the Q&A, so we are going to try to tackle them.

The first one from Richard, while passwordless may be the future, the current market for password managers has grown from 500 million in 2007 to 3 billion in 2022. How would you encourage people to move away from passwords? What should security experts advise non-technical people? This may be a controversial statement on my part because I think most people in my profession would probably say stay away from password managers, they're terrible, they're still using passwords.

Again, I'm going to go back to start with FIDO, use FIDO wherever you can. If you can't use FIDO, use other forms of multi-factor authentication, work your way backwards, but whatever you do, at least do something better than passwords. So I think password managers, you got to be very careful with them. The plus side of that is that they do encourage end users to create more complex passwords that are harder to brute force, but they don't stop the smash and grab attacks.

I mean, if you're using a password vault where these are being all stored centrally on the cloud, you're just setting yourself up for a potentially very bad day if that gets breached. So there are some solutions where they're local vaulted, they're encrypted by keys that the end user holds, but just be aware that brute force attack probably isn't the thing that you should be most concerned about.

I mean, just even this last week, there was the ransomware attack on Canvas here where 8,000 universities in the U.S. were held ransom, right?

I mean, those big centralized databases of IP is what people are going after. So password managers do nothing against those types of smash and grab attacks.

No, but they are still very convenient for the average user. They are still there and they were growing so fast.

Yeah, and so one more thing, also you need to be very careful of some of these consumer-grade password vaults, right? I mean, if you think about what Google or Apple offer today, right?

Very, very convenient, but those are synced to a cloud. They're synced to every device that are registered to that user account. So if somebody gets my iCloud password and then enrolls a device with my password, they get instant access to every key I've ever stored in there, every password I've ever stored in there.

Yeah, and synchronization is a very good transition with the second question from Richard, who said, what are your views on... I didn't even see it. And does RSA provide a solution to manage the syncing of passwords?

Yeah, fantastic question, right? So this is one of the reasons why RSA has really been a leading voice for workforce use cases within the FIDO Alliance, because many of the, you know, the key sponsors and, you know, largest companies in the FIDO Alliance are really looking at this from a consumer perspective, right? And so from a consumer perspective, syncing pass keys is incredibly valuable because, you know, end users tend to change devices, lose devices, use multiple devices, right? So it's very much a convenience play.

I think what a lot of folks don't realize is that when the FIDO Alliance first started, the goal was not to improve security. Like phishing resistance kind of came out of that and is now the, you know, the hallmark of FIDO, but it was really about shifting liability, right?

I mean, these vendors who started this did not want to be victimized by smash and grab attacks where they hit the news, 40 million passwords stolen. So they said, let's make this the end user's problem. In an enterprise environment, making it the end user's problem is not acceptable. It's not the goal. It is security, right? So with an enterprise environment, I would be very, very careful about sync pass keys, you know, so there is now most products will support ability to, you know, leverage metadata from different FIDO pass keys and set policy controls over, do I allow sync pass keys?

Do I not allow sync pass keys? Now there is still some gotchas and some things that we're trying to work through with the FIDO Alliance where particularly on iOS devices, I mean, Apple is really focused on convenience above all else. So iOS actually masks some of the attestation attributes from a mobile pass key that allow platform vendors to tell whether or not it's a synced pass key, right? So this is one of the challenges that, you know, we're still trying to work around. FIDO still has a little ways to go, right?

But again, I think it's, you know, reached a very important, you know, milestone in the last 12 months or so in terms of maturity of broad stream adoption. I agree with that. And maybe the last question, because we have only three minutes left, pass keys are getting a lot of attention right now. Is this genuine progress or mostly marketing? I think it's a progress and more than marketing.

I mean, everybody does for pass keys. Let's say, as I said in my first point, it's a standard. It's not a question of if. It's a question of how do we do we manage that and how do we use that and deploy that.

But yeah, Floyd, I'm laughing because I mean, honestly, I do think that, you know, FIDO Alliance has been one of the most, you know, amazing marketing machines over the last couple of years, right? They've got phishing resistance on the tongue of everybody out there, right? But I mean, for good reason, right?

I mean, they've identified a real problem that resonates and have worked very hard to address that problem, right? So while I do believe that, you know, FIDO Alliance has done a fantastic job marketing the problem and influencing RFPs and influencing regulations, the flip side of that is true as well, right?

I mean, this is absolutely genuine progress. You know, RSA, even though we sort of invented the OTP authentication mechanism, we are 100% fully behind, you know, pass keys. We are board members of the FIDO Alliance is the primary authentication method that we use and promote today. And I think it's absolutely fantastic where the technology is going. Thank you. Thank you for all your answers and your participation.

Thank you, Dave. And thank you all for assisting to that call. It was a pleasure to be with you, Dave, and to chat with you. We'll see you here, conversation. Thank you. Have a good day, everyone. Bye-bye. Thank you.
