IAG solutions are crucial for organizations due to the security risks and compliance requirements associated with managing access rights. These solutions provide tools for identity lifecycle management, access certifications, and policy enforcement. The report distinguishes between vendors offering comprehensive Identity Governance and Administration (IGA) suites and those focused solely on IAG.
The market hosts a diverse set of vendors offering a wide range of deployment options, including on-premises, IDaaS, and hybrid models. Additionally, the incorporation of AI and machine learning in IAG solutions is driving advancements in automation, risk management, and access analytics. While some vendors provide comprehensive solutions, others focus on specific features like User Access Provisioning (UAP) or access intelligence. Buyers are urged to consider products based on specific organizational needs and to conduct detailed evaluations beyond the findings presented.
Nitish Deshpande, Research Analyst at KuppingerCole, will explore the current state of the IAG market, highlighting the core capabilities essential for IAG solutions and the key business activities they support. He will also explain our Leadership Compass methodology and process, sharing high-level insights from the latest report.
Hello everyone, welcome to today's KuppingerCole webinar on Identity and Access Governance Market Insights. My name is Nitish Deshpande, Research Analyst at KuppingerCole Analysts and this webinar follows the leadership compose on Identity and Access Governance that was published towards the end of last year. In this webinar we will share some of the findings from this leadership compose as well as walk through our leadership compose methodology and some definitions that we have.
Before we begin, here are some housekeeping rules, so you all are centrally muted, so you don't need to mute or unmute yourself. As always, we'd like to keep these webinars very interactive, so we will be running a couple of polls during this webinar, so I would like to encourage all the attendees to take part in these polls and provide your input and I look forward to seeing the results during the final Q&A session. For the Q&A session, you can enter the questions at any given time using the live stream control panel and we will address those questions towards the end.
And finally, we are recording this webinar, so the slide deck and the recording will be made available for download in the coming days. So this is the agenda for today's webinar.
First, we will take a look at the overview of Identity and Access Governance, some of the challenges they're facing right now, the top drivers for acquiring Identity and Access Governance solutions. Next, we will take a look at the leadership compose methodology of Kupinger Coal, what were the required capabilities that we analyzed for this particular leadership compose. And finally, we'll show you the results of our 2024 Identity and Access Governance leadership compose. So stay tuned, we will show you some graphs on the list of all the vendors that participated during this analysis.
So first, what is IAG, Identity and Access Governance? It's a tool to manage access and as a core part of IGA is one of the key technologies within IAM. This is due to massive impact of security and governance risk arising due to issues in managing access controls such as over entitlements, segregation of duties, enforcing the least privileged principle and other access governance controls.
There are several access related security risks in today's organizations that have a direct impact on business, which are, some of them are intellectual property theft, business fraud, policy violations, reputational damage and many more. So having an adequate access governance framework is essential right now for anyone dealing with continuously changing landscape of security and risk management.
So at its core, Identity and Access Governance is an IAM focused risk management tool that provides organizations with self-service tools that enable users to perform various actions such as request access, run reports, participate in certification campaigns, perform segregation of duty checks and many more. This can help in access management while also reducing manual human intervention and the overall administrative overhead. About this access governance, there is an additional layer which you find, it's called access intelligence.
This layer enhances the governance through data analytics and machine learning. The access intelligence layer can help you detect patterns, optimize processes, design roles more effectively and also automate access reviews. With AI driven insights, you can identify anomalies, outliers, flag security risks and proactively address the governance gaps. So what are the challenges right now? There's two faces to it. So there's technical challenges and non-technical challenges. In non-technical, you have from a customer's perspective, there's vast number of vendors out there.
So selecting the right vendor based on your requirements can be a big challenge. Also, there are budget constraints. So that is a non-technical aspect. But if we talk about the technical challenges right now, so the main one first is the toxic access combinations. It is one of the most significant concerns in access governance and it's basically about identifying and managing toxic combinations. So when users accumulate conflicting permissions across different applications, then the potential for security breaches or policy violations arises directly.
So to ensure that users only have the permissions they need is essential and that's why a well defined segregation of duties framework can help prevent these kinds of risks and make sure critical systems and data are protected. Second challenge is decentralized access governance. So many organizations, enterprises operating across multiple business units, subsidiaries, regions, with each having their own set of access management principles and policies.
So when access governance is managed separately across all these different departments, it leads to various challenges such as inconsistencies, security gaps, and overall lack of visibility. So these are some of the major concerns. So what can be done is establishing a centralized identity governance platform that enforces consistent policies and provides greater control over access permissions across the entire organization. Access rights need to be granted and revoked efficiently. Next one is static entitlements.
This is another very common issue, static entitlements, where users retain access to systems and applications long after they have used those applications and they don't need it anymore. And this can lead to unnecessary exposure, increasing the risk of unauthorized access or misuse. So moving towards a more role-based or adaptive access model will allow you to regularly reassess and adjust permissions. So to implementing automated tools that track entitlement usage and permissions can help eliminate these kind of unnecessary privileges and also improve the overall security posture.
Next is the regulatory compliance. It is an ongoing topic, ongoing challenge, as the regulatory frameworks keep on evolving, new frameworks keep on emerging. So organizations need to ensure that they meet the requirements of these industry-specific regulations and for that must integrate automated compliance monitoring and policies are enforced consistently and maintain audit-ready documentation for regulatory reviews.
Finally, challenge is about recertification. Recertification of user access is a key process in access governance but many organizations still rely on manual access reviews which is unsustainable, it's time-consuming, it's prone to human error and it's also very difficult to scale. So for access governance to be effective, reviews need to be efficient, accurate and automated. So that's why by prioritizing high-risk access for review, you can also focus on areas that matter more.
That brings us to the first poll question of today's webinar and that is what is the biggest challenge your organization faces in managing access? Is it A, over entitlement of users, B, segregation of duty violations, C, lack of centralized governance visibility or is it D, managing access for external users? I would encourage all the attendees to participate in this poll and provide your input and I look forward to seeing the results towards the end of the webinar.
So what are the emerging trends that we have observed while doing this leadership compost and what we observed is that although the market is mature, it continues to grow. Automation is a key area of innovation in the access governance market and vendors are trying to reduce the workload of repetitive tasks by automating various features like access reviews for example.
And with all the talk of artificial intelligence and machine learning in the past one and a half year, two year, we also carried out a survey a while ago to understand the status of artificial intelligence and machine learning in access governance and access management solutions. And what we found is that even though the trend shows from vendors point of view that they are innovating in the areas of AI and machine learning which is also one of the key differentiating factors when we are evaluating these solutions.
What we found from the survey is that the end user organizations, more than half of them are still not in the phase of deploying these modern techniques. So that brings us back to the main challenges is if we address those main challenges of toxic access combinations, recertifications, decentralize, those are the main formulation. Once those are addressed, I think then we can move towards the trends. These are some other emerging trends that we also observed apart from automation and that's for example, the first one is the phishing resistant multi-factor authentication.
It's getting attention and as a more secure alternative. Instead of just relying on one-time passwords, phishing resistant methods use cryptographic authentication, biometrics, or physical security keys that can be tricked. So many organizations are moving towards password authentication using things like PyroPro security keys and pass keys. Second one is deployments moving to fully IDaaS or partially IDaaS mode. We also in this survey, which I mentioned earlier, we also carried out, we asked if what is the status of the current solutions?
Are they deployed on-premise or moving to partially or fully IDaaS mode? And the trend that we observed is that organizations are moving towards a hybrid model or fully IDaaS model. Apart from a few legacy companies who need to maintain some on-premise systems, others are moving towards more cloud applications which are more easily scalable. Then the further integration of AI and machine learning as well for detecting various things like unusual behavior, outliers, access changes, and risks. Another emerging trend is the elimination of siloed approaches.
This is one of the biggest challenges in access governance as we saw is having a decentralized access governance. So that the shift is changing. Organizations are now moving towards a more unified access management platforms where all users, identities, permissions, and policies are managed from a single platform and they can be enforced to a single platform. This also makes it easier to answer these three questions. So who has access to what? When was this accessed and why? This also reduces the risk of orphan accounts and excessive permissions. So these are some of the trends.
Role mining and managing user roles is another most challenging part of access governance. So over time, employees collect more and more access than they actually need, leading to a role load and security risk. So role mining uses AI and analytics to identify patterns in user access and recommend better role structures. Now instead of manually creating and updating roles, organizations can use role mining to analyze user behavior, determine which permissions should be grouped together.
Finally, the dynamic access management model that adjusts the access rights in real time based on context and helps reduce the risk of excessive access. So what were the top drivers for acquiring IAG solutions? This is common across all industry verticals and organizations of all sizes. So what deploying organizations currently need is IAG solution that can help them for regulatory compliance, risk management, improve user experience and operational efficiency.
That brings us to the next poll of today's webinar and that is what were the top drivers or what are the top drivers for acquiring an IAG solution in your organization? Is it A, regulatory compliance?
B, enhancing security? C, improve user experience? Or is it D, automation?
Again, I would like to encourage everyone to participate in this poll and provide your answers and look forward to the result. Next up, we have a brief introduction about leadership composed methodology of Kupinger Coal and also what were some of the capabilities that were analyzed in the access governance report. So the leadership composed process of Kupinger Coal is a four-step process.
First, we do the research. We identify the vendors, then conduct briefings with them. That also includes demonstrations of the products so we can get first-hand experience to see how the product works. And we also send these vendors a technical questionnaire which they fill out and send it back to us. Once we have all this information from all the vendors, we take that and move it to the next step where we analyze this information and then we write a draft. So the report is now drafted, it passes through several rounds of internal checks and then goes towards fact check.
Fact check is where the vendors receive this report for review and for updates. So for example, between the research and fact check, sometimes it can be a couple of months of time and that time vendors may have addressed some of the challenges that we had observed. So there's an opportunity to address that issue. And finally, once all the things are agreed between the vendor and the Kupinger Coal, we publish this report on our website kupingercoal.com.
So in this particular access governance report, these were some of the eight required capabilities that we analyzed, apart from several other parameters, but these were the more top eight ones I listed down here. First is role management. This category included the ability of the solution to provide access governance and role management features around user activity monitoring, role mining, access risk management, certifications and others. The next one is SODs, segregation of duty management.
We looked at the various things such as the solution should be able to analyze enterprise as well as application roles for any segregation of duty risks and continuously monitor for new SOD risks while also simultaneously providing remediation measures. For the capabilities that were also evaluated in this segment include ability to perform access request, access approval or rejection. Third is the access risk management part. For the governance part of the IIG products, what is becoming increasingly important is the quality and the flexibility of role and risk models.
These models not only need to be relevant but also need to have a strong conceptual background with sufficient flexibility to adapt to the customer's risk management requirements. It is important that the organizations spend a lot of effort in adapting to the business processes to match the templates offered by the tool, but instead the tool that offers sufficient flexibility to adapt to the IIG requirements. So that is also seen here.
Access analytics part includes analysis of identity and entitled data to support capabilities like role management, access requests, policy management and also advanced analytics capabilities beyond reporting using other advanced approaches such as deep machine learning for automated reviews and so on. Then we have the access intelligence part, so access and risk intelligence you can say that. Then this includes capabilities that provide business related insights supporting effective decision making and potentially enhancing the overall governance.
So advanced capabilities that use machine learning techniques that enable pattern recognition for process optimization, role design, automated reviews, detection of compliance violations just like SODs and other types of anomaly detection are considered here. Other capabilities include the use of user access information from authentication and authorization events to analyze user access behavior, patterns detect anomalous behavior or to mitigate accessibility risks.
The sixth point is about user interface and mobile support and this is the ability of the solution to provide interface to request access to specific information or systems. Also the usability of the solution is considered here for features such as assigning risk scores for access requests or requesting access to IT assets from a certain access catalog. Also other features that are evaluated include that provide the ability to facilitate review and approval processes.
Target system connectivity is also very crucial, ability to connect to a wide variety of source and target systems that includes on-premise systems as well as SaaS systems and this includes standards such as SCIM. So it should not only support proprietary APIs where standards are not supported but also deep integrations around supporting complex entitled models such as frequently found in line of business solutions. Integration with identity lifecycle management and identity governance and administration are also expected. So target system connectivity is also very crucial.
Finally the compliance and reporting part for the auditing is the ability of the solution to demonstrate compliance, support auditing and forensic activities through capabilities such as report generation, logging of users access to resources, administrator changes to systems as well as running out-of-the-box ad-hoc or custom reports in various formats. Now we will take a look at the final part which is the results from the 2024 leadership compose on access governance.
So then on this slide you can see the number of report vendors that were rated around 29 but not just the rated vendors this report also includes vendors to watch. What vendors to watch is that the vendors that we believe are worth mentioning and also some other vendors that could not join this leadership compose due to some unforeseen circumstances. So if you combine this list in this report you can see there's over 50 vendors who are specializing not only in IAG but also IGA.
So it's a combination and once we carried out the research analysis part with all these vendors this is what we came to the final result is the final overall leadership diagram. Now this diagram is a combination of three different ratings that is first is the product leadership. In the product leadership we evaluate just the solutions main features and the capabilities that is taken into consideration here. The second rating is the innovation leadership.
In the innovation leadership we take a look at what are the new features the solution the vendor is bringing how are certain features being implemented so what is their roadmap for the next six months or what are the innovating so that is very crucial and that is also included here.
And finally is the market leadership rating and this is more about the vendor this is not about the solution directly more about the vendor so in which regions they operate, in which industry verticals they operate, how many employees they have, revenue, profitability, funding that is also taken into consideration and once you combine all these three features three leadership ratings you get this final overall leadership rating. On the right the red marks you see those are the overall leaders so these are the primarily the large vendors and also some of them are access governance specialists.
In the middle you have the challenger segment so these leaders these vendors in the challenger segment are the ones who have the basic set of features but are lacking in some more advanced capabilities and finally there on the left side is the follower segment. Follower segment right now does not have any vendor and this diagram kind of summarizes the access governance market which was described earlier is that this market is mature so you can see more and more moving towards the leadership and but it continues to evolve.
So this was the final result and there's one analysis which we did and the next slide here. This is an example of one vendor we do separate rating for each of the vendors in the report and we analyze all the vendors based on these eight capabilities and map them on a spider chart.
Once we have this information we have mapped them you will find in our report so this is a very in depth analysis not so only the solutions capabilities are taken into consideration for the for the spider chart and yeah I think we have just over five minutes left so maybe we can see first take a look at what were the poll results. Okay the first question was what were the first question was what is the biggest challenge the organization faces in managing access and 57 percent of you have said the lack of having centralized governance visibility.
33 percent have voted for over entitlement of users and 10 percent have voted for managing access for external users. The next poll that we had was about what were the top drivers for acquiring an IAG solution in your organization and 45 percent have voted for regulatory compliance, 39 percent have voted for enhancing security, 10 percent for automation and six percent for improved user experience.
So thank you everyone for voting in these polls and I think it kind of summarizes the results that we have seen in these polls about what we seen is the lack of a centralized governance is missing and let's we have still some time so we can maybe take a look at some of the questions from the chat. Okay how can organizations minimize risks associated with third-party access or vendor identities?
So very good one I think for this one maybe what we can do is just implement the best practices like zero trust principles just in time access is also crucial and provide continuous monitoring for third-party access so strong authentication contract based policies and also automated provisioning and deep provisioning can reduce the risks associated with third parties. Next is okay some vendors offer different tools modules for IGA like on-premise or SaaS or older and newer versions.
How can I know which one was evaluated and achieved achieved the shown rating example sale point I do know also my IQ in the good question in the report we have written down detailed about each vendor and which product we have related in that for each vendor so once you I think have access to the report you can see the name of all the solutions of each vendor so that will clarify this doubt. What role is AI and machine learning playing in IAG strategies? I think we addressed this slightly earlier so we can maybe move on to go to the next one.
I see another challenge how do users discover resources they should be entitled to access but are not able to some roles are more dynamic and need to be reviewed as per data is on boarded more applications etc. I think it comes down to having again centralized visibility again to see who is we access what who has access to when and why and how to gain access and I think having that one central framework will help. Next one we can take one more question. Can we get access to this report presented today?
It is available on our website so if you have a membership for the website I think then you can access this report otherwise we cannot disclose it but in the slide here right now we can show you other related research like we also do bios, chemicals and white paper on this topic so once you go on our website you will find lots of content around topics of IGA, access governance, policy-based access management, access management, authentication and several other topics around that. Okay I think we're right on time then.
Thank you everyone and thank you for your time and I look forward to seeing you for the next one. Thank you.
See All Locations
See All Locations