Many organizations invest in modern cloud applications, identity providers, and security tools but still face the same challenges like unclear responsibilities, manual processes, limited visibility into access rights, and increasing pressure from regulatory and security requirements. These challenges let Identity & Access Management evolve from a purely technical topic into a critical foundation for secure and scalable enterprise IT.
Christopher Schütze, Chief of Advisory and CISO at KuppingerCole, will explore why IAM initiatives frequently fail despite significant investments. He will discuss typical maturity stages of IAM programs, common structural and organizational pitfalls, and the key success factors organizations need to stabilize and modernize their identity architectures.
Deniz Algin, Advisor at KuppingerCole, will examine practical approaches for improving identity governance, reducing operational complexity, and strengthening visibility into access rights. He will also highlight how organizations can establish sustainable IAM processes that support regulatory compliance, security requirements, and scalable digital transformation.
Who Should Attend
This webinar is designed for IT security leaders, IAM professionals, enterprise architects, and IT decision-makers responsible for identity strategy, security architecture, and access governance.
Good afternoon, good evening and welcome to today's KuppingerCole webinar where we will talk about why identity and access management fails in many companies and how to set it up correctly. Today we have not a new colleague but a new colleague in doing webinars. We have Deniz on board, welcome.
Hi, glad to be here and looking forward to having a good webinar. Yeah, same for me and we have me. I'm Christopher, I'm leading the advisory team and I'm really looking forward for today's webinar sharing experiences, thoughts and really being also open for discussion. This is really a huge webinar, we have very much so many attendees so feel free to use the chat function on the right side to ask questions anytime. For the experienced KuppingerCole webinar attendees, we will start with some kind of typical hygiene, how we do this kind of webinars.
So audio control, you are essentially muted, we are controlling these features and there's no need for you to unmute yourself. Every kind of comment by you will be done via chat. Then for sure we have polls during the session, we have three of them today and as mentioned there's the option to share questions we have in Q&A part. You can question those stuff at any time using the function on the right side but we will do this combined at the end of the session. And for sure it will be recorded and you have the option to get the slides and review at the end of the session as well.
So let's jump into the topic. All right, so this is the agenda for today. What we want to do is first of all talk about the challenges we see in companies and conversations we have with our customers. And the second topic is about what successful companies do differently so we can learn from them to improve our IAM. And the third point is about the structured approach. And on the fourth point we will talk about some quick wins, what can you do quickly to take it from the webinar and take actions to do some quick stuff to improve your IAM.
And on the last part we will have some questions and answers where we would like to answer your questions you tell us in the chat. Perfect and as announced we will start by doing our first poll. I'm not reading in detail through the question and as mentioned we will go through the results at the end of the session and the poll will be active during this whole session. So question number one is how well do you know who has access to which systems in your organization and we have different options to answer.
Hopefully number five is zero at the end but we will see and I'm looking forward to discuss the results. Dennis over to you. Yes thank you very much. Yeah now for the first topic we want to talk about the common challenges we have observed during our projects with customers. And the first one is the missing transparency of the board. So in many organizations IAM is still seen as an operational IT topic so it's like something technical complex and often only relevant when auditors ask questions or some incidents occur like security incidents.
And what we typically observe is a limited understanding of business impact of IAM risk and for example coming from orphaned accounts or accounts with excessive privilege. So this risk usually remain invisible for the management and until they become incidents. So another point is the lack of metrics for the board. So there are less there are no reports or metrics that translate IAM in a business language that your leadership understands better.
And another thing customers face is that IAM initiatives compete often with other priorities because value and urgency are not clearly communicated and this results that IAM teams often struggle to get budget or the right attention to solve their problems. So keeping it short the leadership cannot see and understand the IAM risk and if they don't see it and they will not prioritize in solving them.
The second challenge we see is the unclear responsibility and this challenge typically arises when IAM is not clearly set in the organization and if the processes have grown over time without a consistent model. So in many companies the responsibilities for identity and access are distributed but not always clearly defined.
So there is often no clear end-to-end ownership for the overall processes and as a result organizations rely heavily on manual workflows like email-based access requests and responsibilities are unclear and process remain manual and this means that IAM cannot scale and will always remain reactive. The third point or the third challenge we see is the weak enforcement. This challenge is about the gap between the defined policies and the actual implementation of these policies.
So security and IAM policies often do exist like FSA should be used or access should follow least privilege but in practice these rules are often not consistently enforced. So when this leads to a situation where the intended security level is not achieved in reality and if these policies are not enforced they will not reduce the risk they are intended to be attacked. And the fourth point is the fragmented landscape.
So this challenge describes a situation where IAM has grown organically over time rather than being designed as a unified capability and in many organizations different systems and solutions have been introduced independently. For example multiple directories or identity stores and this is why IAM becomes fragmented and across the technologies teams and also the processes and a fragmented IAM landscape prevents organizations from having consistent control over the identities and access.
And the fifth point is a relative new topic agents AI and NHI and this challenge reflects a rapidly growing dimension of IAM that many organizations are not yet fully prepared for.
So today we see a significant increase in service accounts and in system identities or APIs using tokens and keys and we typically observe that credentials like API keys are long-lived or never rotated and this means that IAM is no longer just in managing human identities it's about managing everything that can access your systems and yes what other companies do correctly I would like to hand over to Christopher he will tell you more about that.
Exactly perfect so really good insight in what kind of topics are still relevant I mean some of them are not new that's something you might realize the experienced guys in the session people who attended IEIC or other webinars but still valid and a good point Oscar is sharing that information here in the chat it is really thought to discuss with each other use the chat do some kind of conversation thanks to Lukas if I traced it right and Robert is also something mentioned it's a bit difficult for us as a speaker to answer on time on this stuff but we will use these questions at the end and you can engage with each other as well.
So what do successful companies do differently? I mean there are multiple patterns but as we are an analyst company we picked out four of the most relevant ones.
First one is nothing new in 2015 or 14 Martin Kuping announced something called a central platform for identity this is also something we will consider today seeing identity really as an internal central platform HR acting as a single source for truth for identities even if you have more than one you have some kind of one policy engine especially across on-premise and then later so six seven eight years cloud was more relevant and software service stuff came up and taking all of the stuff at a single point in a central platform helps those organizations who handle it better to be prepared also for future stuff what Dennis mentioned regarding NHI or NHI is not new it is a mixture of multiple things we already have but the huge amount is the challenge here as well and then we have agents yeah next thing is what do they the successful companies good they have working automated lifecycle processes which means if a new employee joins it's not only about waiting till six seven eight nine days till they are able to log in the first time this is still a topic is that we as external people have multiple time with many organizations and for internal typical process processes around joiner mover switching the department this is true as well also not a new topic but still relevant and the foundation i wrote a lot about the basic hygiene and being prepared for the future on linkedin as well and got a lot of feedback here and the third one is risk-based access models few years ago multi-factor or second factor authorization was the first thing but you always need to be careful how you annoy your people the more authorization steps you include the slower it gets or people tend to to use methods to skip things here for me as a customer good thing is if you annoy me with two or more factors you lose me and that is a good starting point looking into the fourth one identity and access management as a business enabler onboarding of externals that's an example i've mentioned onboarding of potential customers the faster the time to create an account whether it's federation or whatever is the quicker you can convert you can get people to work and you can relate to each other and this scene and martin mentioned this last year at dic and for sure we will talk also about that this year the business opportunities behind a good identity and access management model also for enterprises is so huge it's not only a budget part for in the it operations is really really more and the question then is really how can we get from or how do successful companies do that and let's jump into the next topic of such an structured improvement of your identity and access management yes of course this structured improvement we use our two frameworks we have also the first one is our identity fabric this helps us to guide through the iam strategy and they are fundamental of course for the assessment of the result of your iam situation the identity fabric we see on the left side the different identity types separated between two human and non-human identities and on the right side we need the target systems where the identities on the left side want to have access to so the target systems may be applications legacy it or any digital services um this of course needs to be done in a proper way and the most interesting part is the middle part so this shows what is required to enable how to do it properly so the requirements are reflected as the capabilities and they are categorized by services and of course operated with the respective tools and having a short look over the upper and lower part of the fabric this is about the connector landscape and these shall ensure to consider and connect your existing iam landscape into your future strategy and the most interesting part from the identity fabric is that each identity type requires different capabilities to connect to the target system so in other words workforce identity requires different capabilities and requirements than a consumer identity and when we want to go a level deeper we use our reference architecture which will be the next slide and um christopher could you go to the all right um the reference architecture highlights the capabilities aspects and goals as i explained just one level deeper than the identity fabric so it just ensures uh to consider the capabilities we need for example on how to authenticate ourselves to access an application or what are we allowed to do within this application so this is a structured matrix with columns and rows on the columns you see the four a's of iam which are administration analytics authentication authorization and yes the four a's have become firmly established over several years and i am and the rows reflect here um the different abstraction levels beginning with the core capabilities and ending with the foundation capabilities and the core capabilities are always a good starting point to begin a maturity assessment since it covers yes the most relevant topics that needs to be considered um and privilege layer just this just covers all the privileged accounts or accounts with higher risk and the capabilities of them the extended and the integration uh layer may be a bit distance to the core capabilities but they have interaction with iam like exchanging data with it and of course all these capabilities are not managing only one tool and of course it requires many tools to cover them all and this is where the api layer helps to link these capabilities from these different tools together and this is why this capability goes across all the four a's um and the foundation the lowest layer is then um it does not all belong to iam but it is often used by iam and it is cross-sectional and of course all of these capabilities have their own details and own descriptions but we don't want to go too deep for now um but we want to show how the maturity of the of these capabilities are structured and christopher will tell us how we do it so um thanks um dennis the next thing is um really um i mean having in your mind the title of the webinar today how to set it up correctly and the journey to set up something correctly is first of all know um where are you what is the level of maturity you currently have um we had in the chat if it was lucas i guess the comment regarding depending on how mature your risk assessment in total in the organization is and the same thing applies to how you measure risk not how you measure maturity of what you have there are multiple frameworks out there uh the one is for enterprise risk management and then you have specific ones for other things here and i want to share something that we usually use and that helps customers from us or which is also available for free on a certain level um for just checking by yourself okay what's going on within my organization taking the reference architecture as a foundation um the intention is of looking into detail of the specific capabilities that dennis mentioned or building blocks in that case um how mature are you and that is some kind of starting point to achieve that level of uh the organizations that are handling identity and access management on a good level if you take for instance ita and we maybe jump back to this slide um usually things like identity proving life cycle management and provisioning and not identity proving identity life cycle management and provisioning and access governance are related here and then you need to know okay okay how good is my life cycle management how good is my provisioning how good is the related data and then you get a third first indication of whether it's um green yellow or or orange or even red for simplification we mainly use at the beginning here some kind of simple signal model with three different layers which at the end also can be matched to the common maturity model here as well so with the five levels if you are certified on eyes or whatever that is very common and then let's jump into a bit an example how this could look like this is again um an example of such a maturity assessment okay this organization in that case is really good in having identity repositories just take it for yourself and go stepwise through it i mean even for that you have a feeling sometimes but there are also other options and the challenge for this organization for instance if we stick with the ita topic at the beginning provisioning red entitlement management red workflow management orange access governance red and coming back to what do successful companies do join a mover lever and automation this company is potentially not really good in total if you take these this is an example and taking these kind of things for sure you you always need and that's what um dennis also tried to explain or explained um what needs to visualize i'm am i only focusing on ita is it bigger is hr related do i have multiple repositories for identity is identity information quality management important and also things like self-service if you talk about the typical portals where you request something for as an employee um which is also very common and then for sure you also have the level authentication authorization when you drive draw the bigger picture of identity and access management yeah that's the thing here um and a really good and uh for free available tool some advertisement must be you can find on our website especially for the core capabilities um an option to run through i think it's 17 question basic questions to identify a first version of where are your challenges and where are your strengths um feel free to to use that and look where you are also for those for for you if you are joining eic um mid of may um i philip and uh liner we will have an three-hour workshop in the morning where we exactly goes in really in detail also with questions and examples through the framework as well this also is a good part of understanding okay how does this work where can i improve and how can i measure it and yeah it's for free focus iga plus a bit access management and gives you a really good first view on that especially um regarding who asked that question in the chat robot um for 10 recommendations for a mid-sized company always depends but if you fill this for instance hours and see okay again life cycle management is orange or even red um and compared to what do successful companies do then you have your first thing you need to work well knowing that uh implementing join a mover lever processes with automation is not really a quick win and with that i would hand over back to dennis yes it's a pretty cool tool uh to use the online assessment to get a first impression of your maturity situation and haven't talked about the visualization um now we uh want to or i want to show you this category well this one is about how to visualize the analysis and set the right focus for the future actions to improve the overall iam maturity and of course with the right priorities so as you can see the dashed line in the middle it shows the balance between the maturity level and the need for action and being above the dashed line indicates a lower maturity and a high priority with a need for action and of course below the dashed line it's the opposite case and in this graphic you might have a focus on the red circle yes correct the red circle is about the urgent topics or about the capabilities you may take a first you need to start with and these are the important ones the blue box in the middle and they show maybe a higher maturity than than the capabilities uh before but they add also an an urgent um um level to to take uh actions and this might be for example some rescue security topics or maybe um um some compliance topics they need to done quickly so on this capabilities you should have always a focus on and make sure you do not lose any maturity level here and the down right is the green box this ones that should are your sweet spots so these are the topics you do well and you don't need um high priority for action but what you can do is you can take the learnings you made when you have received this uh level and use it for the ones you want to improve on the red circle so just adapt it what you what you did right to the other capabilities and yes this one visualize that you how to start with and where the focus lays and having found out which topics are the most important ones um christopher will tell you how a roadmap can help you to guide through this yeah so honestly in this example uh jumping from um uh scattergram to a roadmap there is something in between but uh my colleague charlie did some cool webinar last week or two weeks ago um it's also linked and in the appendix later on where she explains a bit more the exact phases here but just for your overview here so for sure um you have the scattergram you have the most important stuff you may might also have some kind of quick wins and then you need to prioritize need to see what is relevant so again the um business impact can be something like that how much budget do we do i have is it just an it topic or do i want to improve something from security or is there something i must improve so we have some kind of regulations or nis2 whatever if you're new to nis2 um you need to handle some stuff if you haven't done that before and then the priority is a bit externally enforced i would say which is not a bad the worst thing here so that as a uh some kind of disclaimer at the beginning and basically the operation operationalization of such um things is then really straightforward so depending on the size you build different packages in that example we had something related entitlement management but before entitlement management there was some other dependence project it's y264p4 even it's not written down and um we need to arrange that and for those of you who are experienced in bigger im projects the challenge is to end them the the thing from uh project to operations uh is sometimes a bit um unclear so uh in the past when i was working for different integrators it was really often that a project which is by definition usually a limited project was turned into operations after six seven years then at the end and as you can see in this example we really tried and that is also what we tried to give as a recommendation to our customers not to have something bigger than one or one and a half year knowing iga migration projects or things like that are bigger but maybe then you can split it up a bit and really exclude entitlement cleaning up projects from authorization multi-factor whatever is going on basically main idea and again the recommendation having a look at the webinar that my colleague did um you need some kind of plan and roadmap and this will change you can be 100 ensure or be sure that things that are written down for 28 in that example will be asked again and challenged next year and the year after and maybe some of them will not be implemented because of new threats new requirements new things that came up and that is really an important thing dennis yes we are on the poll number two and here we would like to know about the non-human identity situation in your organization um are they fully managed with clear ownership and controls or are they not actively considered or is it maybe something in between um yeah just let us know so next up we want to talk about the quick wins and maybe this five recommendations we can give to the 10 you asked for um the yes this this recommendation just tackled the challenges we uh mentioned in the beginning and starting with the missing transparency and what you can do uh first is maybe just create a single iam kpi sheet for your management so three to five key figures may be enough just to show them how your situation is and the key figures may be like uh nfa coverage and percentage in your organization or maybe what always works good is to show the amount of of your um orphaned accounts that exist in your system um because all of them might be in a text service a surface so this is what you can easily show your manager and maybe make it a bit visible the good thing here is that you don't need a tool or something to to show it you just need to collect your data that already exists in your organization you just need to collect them bring them to the sheet and showing them to your management and we are sure that this will help you to to rise the awareness of iam throughout the board the second challenge we talked about was the unclear responsibilities so the quick win here you can do is um first of all you can maybe define an iam owner and document your processes of the joiner mover and lever for the for the top three critical applications in your organization and why top three we recommend to just keep the scope low and just to not make it too complex in the beginning and you can do a workshop or maybe just draw the diagrams about the processes the joiner mover lever processes and with that you have something written down and with something you can begin with the third challenge was the weak enforcement um what you can do is you can start to enforce for example mfa for all privileged accounts because this one are uh have higher risk when they are taken over or they are attacked and um it's good to be some admin content accounts or some service desk service desk accounts and this can then can be done quickly challenge number four was the fragmented landscape um you can here create an inventory of all your identity stores for example a table that shows your directory services or your local accounts or maybe the shadow it accesses that exist in your environment maybe this sounds a bit simple but many organizations have never done this before and this might be the first step to get out of the fragmentation and challenge number five was about the nhi topic and here almost the same as before create an inventory of all the service accounts and api keys from your top five systems again keeping the scope low just to make it to keep it easy and not too complex at the beginning um and here you can for example check which of these api keys have been rotated in the last or have not been rotated in the last 90 days so this will help you to find the urgent quick ones and to yes to reduce the attack surface and now we jump to the third poll uh just a second uh tasking um i would also add um as these are some some questions um for sure i mean there are multiple more things you can achieve and it always depends on your organization you can also start um by if you are really on a basic level by picking one of the most important processes whether it's the joiner or the lever or um mover usually not um to improve that when you're today manual um you need to do that i mean as mentioned you can use the maturity or you should use some kind of maturity methodology but you can also then pick a single processes out there and the other thing is it really depends on your management or senior management in that case i don't know if we have some senior management executives today in the webinar but the thing is um depending on their background they they don't know the opportunity the business opportunities of doing erm right i mentioned some examples at the beginning whether it's quicker onboarding of customers quicker onboarding of an internal people quicker onboarding on partners and this everything of that is efficiency related and at the end cash related and if you try to explain that being the internal evangelist the champion whatever and helping those senior executives or executives that haven't been in touch with that kind of topic often helps really um that's a longer journey but uh absolutely worth to do and start um i mean depends on the company size you usually not can go directly to those guys but maybe level up and something like that that helps or share some emails was important in research could also help yeah that are my thoughts to that and um and we jump into the poll number three yes right the poll number three is just about um both the quick wins we or i have mentioned so after this webinar which of these quick wins will be the ones you want to tackle so this is a thing we want to know then we come to an end still multitasking is a challenge because i tried already tried to get access to the results of the polls um just a quick second but as mentioned we will now go through the q and a session um if we have some kind of question now your chance chance to commit them um otherwise we are getting a bit to it and but first of all let's have a look unfortunately i'm not able to share the details i don't know um if you can see that in in detail um but uh let's start with a first poll this was the other one how well do you know who has access to which systems in your organizations um a good thing is and that was in the chat discussed as well uh we have number one with 44 percent mostly transparent transparent for critical systems and that's a really good starting point critical systems risk base that is a good level and very common level where you need to start because even with a huge amount of systems it's related with high expenses to get on that level number two was partially it depends on the system 33 percent and then only four percent really answered fully transparent four percent that is not much but to be honest this is what we expected didn't we absolutely and uh the good thing is i i uh talked to dennis before that webinar mentioned um related no reliable overview hopefully below 20 percent and it's only seven percent that's good might be might be um as most people who are here are no knowing coping a call maybe since some years um we try to improve a bit here uh and you are aware of that maybe other way around wouldn't be participating that kind of webinar so that's the result for the first poll the second one was how do you manage non-human identities from service account apis agents and that is interesting fully managed with clear ownership and controls we have five percent that is one percent more than uh to the related to the access governance question um number one with 65 percent was partially managed with limited visibility and that is what what i was expecting the most relevant one dennis what do you think um i think uh yeah um this is this is something that reflects our our experience too so when we talk to our customers so yeah this reflects it and interesting um uh ten percent answered managed for critical systems only hopefully the risk management this relates to the question in the chat hopefully the risk management is on a good level and is following some kind of standard then we have the last question um that was about what is the most likely next step you will take after this webinar ha risk ones 50 answered um create transparency on identity and access management risks and priorities um question to the other 50 percent what will you do no uh the answers the the others answered uh started will start addressing non-human identities with 11 and something changed with 16 and 16 answered reduce fragmentation improve integration it's it's still changing yeah on my side too so polls are still open and yeah yeah okay uh but but the the tendency is the same so clarify roles and responsibilities and start addressing non-human identities are on the same level 20 percent and now we have 45 percent for create transparency on identity and access management risk um things here yeah we see this is a pretty important thing to yes highlight it and to show the management how urgent and how uh what risks are connected to am and yeah this seems to be a very important topic in many organizations perfect and then we have a question uh in the question tab um first of all i need to click on the next thing for here also some advertisement for the eic i did and all the other stuff um and as we can cannot answer all of the questions feel free to connect via mail or linkedin um to me or dennis so question number one was do you frame your reference architecture and the assessment into cyber security management frameworks like nist cyber security framework or iso 27 001 um this is um on the roadmap but currently not directly so copying a call itself we are iso certified it's what i did or it's another hobby of myself um we did this on a certain level we didn't publish that um it always is a bit challenging as the iso have a long list of controls and we didn't do that directly right now so but it's on the let's call it feature list so next question is i would also be interested to know if you have a specific approach applicable for mid-size organizations with weak identity and access management maturity posture how do we address feature overload and future ready topics for such business and geography geographies um maybe we start with the first thing so mid-size um it depends a bit so the idea of the identity fabric can be used for any kind of company size even with 10 people would be possible what we usually see is that you if you are a smaller company let's call it 20 to 50 people is that you rely intensively on things like whether it's google or microsoft as a foundation and um just historically this really tends to that you lose use a lot of services from a single uh vendor in that case so whether it's microsoft google or whatever just as an example and the the thing is then you need to be aware um what you have and whether you have issues like vendor lock-in all this kind of sovereignty discussions we currently have where the how they call the schwarz group is covering something with a local european google service google workspace service this is something you need to address basically um i would invite you to go on the website to the maturity assessment and see where your challenges are usually the smaller companies are also depending i've also seen very immature small companies with joiner mover lever processes um that is a starting point the challenge as well as for sure this artificial intelligence stuff so whether it's claude chachi bt and so on this will uh make a huge impact on the attack surface the user can now do things connect mcps and other stuff and uh it's it's really difficult to get a grip on that um in general i would say start with the identity fabric as well but be aware you will have potentially not that much vendors usually and focus on the most critical things again you can take the business opportunities efficiency as a starting point to see where to invest and not and at the end security is always a thing about how much risk am i willing to accept and allowed allowed means if you're nis2 regulated or dora which is unusually not a small company you are enforced and on the other level you need to see or to balance a bit whether you invest in something or accept the risk biggest recommendations here or must it's not a recommendation gdpr relevant stuff is nothing you can discuss this will harm your company if there's some breach and the the fees or the penalties here are really really high anything to add dennis i think that's it from my side to be honest then i would say thank you very much 45 minutes i'm really looking forward to see some of you at the elc feel free to contact us at the at linkedin or via mail and otherwise have a good day have a good afternoon goodbye
See All Locations
See All Locations