• Gain a clear understanding of the 2026 IGA market landscape and key trends
• Understand the critical capabilities required for modern IGA deployments
• Explore how IGA solutions support compliance, risk reduction, and operational efficiency
• Identify key considerations for selecting the right IGA solution for your organization
• Discover how identity governance is evolving in response to cloud and hybrid environments
• Walk away with actionable insights to inform your IGA strategy and roadmap
Identity Governance and Administration (IGA) continues to play a critical role in securing enterprise environments, ensuring compliance, and enabling efficient access management. As organizations face increasing complexity driven by cloud adoption, hybrid infrastructures, and evolving regulatory demands, selecting the right IGA approach requires understanding your requirements and a defined roadmap. The 2026 Leadership Compass on IGA provides a comprehensive analysis of the market, highlighting key vendors, emerging capabilities, and strategic trends shaping the future of identity governance.
Nitish Deshpande, Senior Analyst at KuppingerCole Analysts, will present key findings from the 2026 Leadership Compass on IGA, offering an independent perspective on the current market landscape. He will explore how IGA solutions are evolving to address modern challenges, discuss evaluation criteria and leadership positioning, and provide guidance on how organizations can align their identity governance strategies with business and security priorities.
Nick Nikols, VP, IAM Products, OpenText Cybersecurity, brings a hands-on, practitioner perspective to Zero Trust, focusing on how modern identity and access management solutions can be implemented in real-world environments. Drawing on decades of experience across leading cybersecurity vendors and analyst firms, he will demonstrate how organizations can translate Zero Trust principles into actionable controls—improving access governance, securing cloud environments, and enabling consistent policy enforcement across platforms.
Who Should Attend
This webinar is ideal for IT security professionals, identity architects, compliance officers, and decision-makers responsible for identity governance and access management strategies. It is particularly relevant for organizations evaluating or modernizing their IGA solutions.
Hello, everyone. Welcome to today's KuppingerCole webinar, Navigating the Evolving IGA Landscape, and we will share in this webinar some of the insights from the latest Leadership Compass, which was published on the IGA topic. My name is Nitish Deshpande, Senior Analyst, KuppingerCole Analyst, but today I'm also joined by Nick Nikols.
Nick, hi, Nick. Hello, it's a pleasure being here.
Yeah, I'm Vice President of our Identity and Access Management products at OpenText. Perfect, thank you so much, Nick. I think it will be interesting later on in the webinar when we switch to the fireside chat and try to get some more insights from you regarding more real-life applications and more challenges that we can see in the IGA space. But before we begin, here are some quick housekeeping rules for you. You all are centrally muted, so you don't need to mute or unmute yourself. And we are controlling these features.
As always, we try to keep these webinars interactive, so we'll be running a few polls in this webinar. So I would encourage all our attendees to participate in these polls and provide their answers. These polls are live in the control panel, so you can vote them whenever they will go live.
Also, if you have any questions, you can enter those questions at any time using the livestream control panel, and we will try to answer as many questions as possible towards the end of the webinar. And finally, we are recording this webinar, so the slides and the recording will be made available for download in the coming days on our website. So here's a quick agenda. It's fairly lean.
We will start with a quick introduction of IGA, and I'll provide, give you some of the sneak peek into the results of its leadership compost, and then we will invite Nick for a quick round of fireside chat type of session, where we will try to get to know more around the real-world implications and challenges, as well as the opportunities in the IGA space. So look forward to that as well, so stay tuned. But let's start today's webinar with the first poll, and that is, what is the current deployment model of IGA solution in your organization?
Is it A, fully on-premise? Is it B, partially IRIS? You have some gateways, major components on-premises, or is it C, fully IRIS? You will find this poll in the control panel, so please vote, select your preferred options, and I look forward to seeing the results during the final Q&A session.
IGA, so we recently published a leadership compost on this topic of IGA, and we were very pleasantly surprised by the response this topic received. So, but I would like to share some, maybe start with some of the findings, and what we believe is an IGA space right now.
So for us, IGA is a part of, we can say, three gears here. First is the user access provisioning. It is focused on automating provisioning, deprovisioning across your enterprise systems. Second is also then the way you deliver the right access at the right time. Then we have the identity lifecycle management module. This is mainly about managing the joiner, mover, lever processes. It is also about orchestrating different kind of identity changes from HR to your target systems. And finally, the third part of this IGA is identity and access governance.
This is the part where we try to understand who has access to what, who provided that access, and for how long has that access been provided. This also includes further capabilities such as access approvals, certifications, reviews, segregation of duties, and overall just support for compliance. On the right side, you will see our brief grouping and reference architecture. The blocks which are marked in red are the ones which we believe are very much relevant to the IGA space.
So in the administration part, you have your lifecycle management, your provisioning, your workflow management, so the self-service capabilities. While if we go into the analytics and risk, that includes basically almost everything. You have your governance capabilities, your analytics, identity analytics, access analytics, also the capabilities for detecting anomalies, outliers, threats, and how to respond to that. And we also then go into the authorization part that is also a critical component for IGA. It's different types of access control models.
You have your ABAC, DBAC, you have RBAC, and finally, you want to look at the integration, the support for integration for such as ITS and solutions.
When we did this leadership compose, there were several things that came up forward, but there was a few, you can say a common theme across all the vendors that we researched, and that includes now that the IGA solutions that are in the market right now, the leaders, the challengers, as well as the new ones, they are now including support for not just your traditional workforce identities, also your contractors, your partners, and more importantly now also the non-human identities, your service accounts, your agents, and that is directly a result of what we are seeing in the market as well as the customers are requesting for support for these inner channels.
So now the IGA solutions have expanded those capabilities to support for that as well. The next one was having continuous risk access control and studies powered by analytics, and this includes by machine learning, and it is basically displacing your purely periodic certification models with advanced analytics, machine learning, and AI.
Another thing which you saw is that now the IGA solutions are moving towards a more converse platform, towards a more integrated platform that combines all your modules in one, but also expands it to, for example, something like detection for password reset, MFAs. So IGA solutions are now trying to provide all of that into one one-stop-shop solution. And finally, the capabilities around AI, machine learning, analytics, that has been, for example, the differentiating part when you look at all the vendors in the IGA space right now.
Of course, most of the solutions, or let's say all the solutions, have the basic core capabilities for lifecycle management, governance, for auditing, reporting, but then now the differentiating part is coming into the intelligence part. How are you doing recommendations or doing anomaly detection? How are you doing your, let's say, optimizing policies? So that's where now the IGA solutions are differentiating between themselves, and it's a very interesting space. I've been looking forward to seeing how this evolves into the next 6-12 months.
But there are definitely some changes that we are also seeing right now. Historically, and even right now, IGA continues to be a very high cost of ownership, requires complex customization as well. So this can make it difficult for organizations that are trying to move away from the legacy platforms or scale their current solutions. So I think this is also a certain, there is a gap in the market right now for customers who want, let's say, an entry-level IGA solution.
We can call them something like a lean IGA solution that does baseline capabilities, but also provides some basic intelligence capabilities which are good enough for companies that are, let's say, between 500 to 2,000 to around that size of employees. So that is something which we are seeing in the market right now. We will soon be also exploring that region and sharing some insights on that in the coming months. And there is the poor role definition and role maintenance that continues to limit, let's say, causes roles for all.
It leads to inconsistent provisioning, and also there's high effort during access reviews as well. And that then leads to the access review fatigue, which basically rubber-stamping approvals. So with the advancements in AI and machine learning now, I think that space is being addressed right now, is to have more intelligent access reviews, bulk reviews. And finally, it's about the access ownership. So there's some unclear access ownership between managers, application owners, who should own which roles in which region.
And this causes some delayed approvals, and there's some inconsistent decisions, and some big accountability. There's a few challenges in there, which we have highlighted right now. And if you talk about what were the main reasons for customers going for IGA solution, and that includes customers from all types of industries, from your highly regulated industries, manufacturing, retail. So this includes everyone. And the common thing, not a surprise, is the requirement for regulatory compliance and auditoriness.
So this compliance continues to be one of the strongest drivers for IGA adoption, particularly in the highly regulated industries. Definitely in the case of proving or demonstrating who has access to what, who has content access, and for how long is critical. So that's one of the things which can be addressed to an IGA solution.
Also, the modern IGA solutions are supporting in automating certifications, SODs, and maintaining, let's say, your organization ready for audits for different kind of frameworks for Nestor, Dora, HIPAA, GDPR, and others. Other one is the operational efficiency. So by automating several of the processes, such as petroleum over labor, the provisioning, deprovisioning, this is resulting in an improved operational efficiency, and that has been, let's say, one of the drivers for customers going towards the modern IGA solutions. Third one is the access risk management and entitlement control.
I think as these IT environments become more complex, the identities often accumulate unnecessary or excessive omissions over time. So there is a requirement for IGA solutions that can continuously identify high-risk access and post-lease privilege. They can detect SODs not just at the end of the access request process, but at each stage of shopping cart process. You add any new entitlement, there's a SOD validation being done, and it tells you if there's any conflicts and toxic combinations. And finally, it's support for governance, consistent governance across your humans and NIH.
So this is some of the main drivers that are observed when we did the current report. But we talk about some specific capabilities, if we talk about what were the ones which the customers were requesting a lot. It's a unified platform that also talks about feature parity, not just on-prem deployments, but also your cloud deployments as well, so that feature parity has been a very prominent request. Then connectors, one of the most important things for IGA solutions. Organizations expect a broad connector coverage, and in some cases also expect support for creating custom connectors.
Next is the ability to have continuous access visibility with things like real-time analytics, and so that has been another capability that has been requested. AIML capabilities, this translates to mainly existing functionalities of IGA that can be improvised or enhanced through your AIML. This includes your recommendations, your access reviews, anomaly detection, and it's having a flexible deployment option. So IGA solutions that support multiple types of deployment models are highly favored.
And finally, it's about having an enhanced user experience, having a user-friendly interface, user-friendly admin interface as well, is being highly requested. Now we will move towards the sharing the results from our leadership compose on IGA. Before I begin sharing the results, I would like to maybe talk a bit more about what was the main evaluation criteria for this leadership compose, evaluation criteria for the IGA solutions. And not surprised, the first one is the lifecycle management of identities.
In this category, we refer to the ability of the solution to provision, manage identities, access entitlements, and various other identity-related information in the target system or the lifecycle. Other capabilities which also include in this category are identity stores, data modeling and mapping, as well as the ability to manage different types of identities. And that's where we also evaluated which vendors support which type of identities, and we found out that support for a wide range of identities is now almost uniform across all the vendors. Next is the access governance part.
This even deals with three questions. Who has continued access? Who has access and for how long? Here we take into account the access reviews, certifications, the segregation of duties, and overall we can say centralized governance visibility support that the solution can provide. Automation and access intelligence has been the differentiating part in most in the current report as well as it was the last few months.
So in this one, we take into account what kind of advanced capabilities is being provided by the solution that is leveraging AI or machine learning techniques for pattern recognition, for process optimization, we have anomaly detection is also considered here. Audit monitoring compliance is again very critical capability for my solution. Here we evaluated the capabilities for tracking and logging access users, also the dashboarding capabilities.
It also included support for audit trails, compliance reporting, dashboarding, integration with scene tools, and also alignment with different types of regulatory frameworks and requirements. Target system support, again a very critical thing for an IG solution is evaluated not just the breadth of the target system that is supported by a solution, but also the depth. We also try to understand which kind of directory services, ideas, and solutions. We examined also the ability of the vendor to provide customers the option of customizing the connectors.
So a wide range of things are considered in this category. And then you have the final activity around deployment flexibility and this included just the overall checking support for the vendors for providing does it support on-premise deployment, support cloud, what kind of containers it's supporting, what kind of also is there feature parity in here as well. So that is also considered. We also have some other categories in here which are not highlighted here, but they are worth mentioning is the overall understanding the end user experience.
So we also see the demonstration of all the products that are listed in this vendor. We try to understand the self-service capabilities, the admin capabilities, and also the mobile support as well. And finally, we also take a look at around the policy management capabilities of the IG solution where we also understand what kind of access control models this solution supports. Does it also support the more existing features around policy simulation, policy testing. So when we combine all of this together, we get the final picture of an IG solution.
And in this report, we had a wide range of vendors that took part in this IG report for 2026. This includes almost 30 vendors, you can say, that were part of this report. That includes not just your normal IG specialist, but also your broad, you can say, large IAM companies, also startups, upcoming vendors. And these vendors are spread across your North America, South America, EMEA, APAC. So this includes almost every major IGA player that is in the market right now.
There are also a few more IGA vendors that have been shortlisted, but they will be for the next report that we will be launching soon. But this is the current picture for this report. And finally, now we get to the results. When we take this entire leadership compost process that includes sending the questionnaire to all the vendors, conducting demonstrations and briefings, doing the analysis and the fact check process, and finally publishing, we get this final picture for this IG report. And this diagram, you can say, is a combination of three things.
One is the product leadership, second is the innovation leadership, and also the market leadership. Now, the bubble size denotes the market presence of the vendor. The x-axis denotes the product capabilities, and the y-axis denotes the innovation capabilities. And the ones in the red, you can see, are the overall leaders who have really strong product capabilities as well as innovation capabilities. The bigger the bubble size, the bigger is the market presence of the vendor. And finally, here's another example how we do the individual evaluation of each vendor.
And this is an example of a spider chart where we have not just our four, let's say, basic capabilities around security, deployment, interoperability, and usability. But then there are these eight capabilities which I spoke about that are also taken into consideration. And these are evaluated. And then you have this final picture that shows what are the strengths of the product. And this is available for all the vendors that are in the report.
And that leads me to now the second poll question of today's webinar, and that is, what were the top drivers for acquiring an IG solution in your organization? Is it first, integrity compliance? Is it second, enhancing security? Is it third, improved user experience? Or is it fourth, automation? And the poll should be live in the control panel, so you can select your option. And I look forward to seeing the results towards the end of the session. And I think now is the perfect time to invite Nick into the webinar. We were just going through the results of the poll questions.
And the first poll that we had asked was around what is the current deployment model of the IG solution. And 56% have voted for fully on-premise. Does this align with what you are saying, or can you maybe share your thoughts? Yes.
So, I mean, we still see a lot of deployments on-premise. I think it really kind of becomes a variable as to how much control the organization really wants to maintain.
And also, whether or not they have the skill sets. So, often, customers that are struggling maintaining those skills in-house look to organizations like ourselves to run and operate the solution for them. But that's a balance as to whether or not they want to have tighter control or be able to tweak things and have this in their data center where they have full control.
So, that's kind of the conditions that we see. There's a lot that are interested in going to SAS, but we still, I would say, the majority of our installed base is still on-prem. Okay.
Yes, I was also sharing my thoughts on this, that this also aligns with the survey that you did a couple of years back, and most of the respondents voted for fully on-premise. The second poll we asked was, what are the top drivers for requiring an IGA solution? And not a surprise, 86% have voted for regulatory compliance. I think this, again, aligns with what are the top drivers, which you have seen when I mentioned from our findings.
So, regulatory compliance is definitely a driver that becomes one of the main things that really start to motivate organizations to put in this kind of solution. However, based off of their maturity, I would also qualify that this is a great opportunity to improve the security posture with not just meeting the regulatory needs, but actually taking the time to really promote and enforce least privilege goals within their decision-making, and making sure that by constraining those points of access, if you will, you can improve the overall security posture of the organization. Okay.
When you talk about the compliance requirements as well, so are organizations able to balance these compliance-driven governance requirements with, let's say, the usability, operation efficiency? So, basically, are organizations good at avoiding turning compliance into just a check-the-box exercise, or is it really helping them in more efficiency as well?
So, what we've seen – I mean, so, there's certainly a motivation to make sure the auditors are taken care of and get that pressure off. However, that really does become a factor as to how they engage with the system and what the system does for them. If they're overwhelmed, if there's too many decisions and just – especially if you're doing a really heavy access review cycle and you're doing thousands and thousands of entitlements, for example, that's just overwhelming, and the default mode becomes kind of a rubber-stamping exercise. Nobody really wants to dig in too deep.
They just want to say it's okay. They don't want to change anything. They're not really thinking about the overall security implications necessarily, and sometimes they'll often miss even areas that might not be appropriate.
And so, keeping in mind that the whole idea of access review is to really have the business decide what appropriate access looks like, that that's very, very critical. And so, one of the things that we do at OpenText is we try to reduce that cognitive overload by reducing the amount of data and amount of information that they need to consume all at once.
By taking an event-driven approach and being able to support micro-certifications, we can bring their attention to just the thing that they need to be paying attention to, which makes that a whole lot easier and a whole lot more comfortable, and the activity becomes a whole lot more mindful, which allows for improvements to the security posture. So, I do think that there is a combination here of things that need to be done. It's not just about getting the compliance and the attestation report completed.
It is about kind of taking the time, because the way I look at it is the attestation report is showing that you've done your homework, but you really need to do your homework. You need to be thinking about this and trying to see how to ensure that appropriate access is really being enforced. Right. Makes sense. Completely makes sense. I recall you mentioned right now around reviews and certifications.
Now, what we are seeing in the market right now is this certain growth of NHIs and also IG solutions supporting NHIs as well. Do you think the IG solutions organizations need to look at the certifications and reviews of these NHIs differently compared to, let's say, a human identity?
Well, so I think, first off, I mean, these agents need to have first-class identity. One of the things that we see a lot of right now is that there's a lot of activity going on, a lot of experimentation with regard to agents, but all too often, the agents are being handed the personal credentials of the individual that started the agent. And piggybacking on the individual's identity is not a good practice, especially if this is something that's going to be part of an automation infrastructure in an enterprise, something that's going to be running all the time. It needs its own identity.
In circumstances where you're running an agent that's just doing something limited in conjunction with the end user, it's maybe not as much of an issue. But if you're doing these bigger operations and really running this at scale, agentic identity has to be a part of the process.
And so by defining these identities for these agents, the whole review cycle, the approach around understanding the context of what these agents are basically being employed to do, becomes really part of that review and needs to be fully covered as part of this whole access review cycle and being able to recognize what's going on, which also highlights another thing is that this pushes a lot of or puts a lot of pressure on periodic access review where you're reviewing everything all at once.
That's going to be very difficult when you start having many, many agents being introduced in addition to end users. And so going back to kind of a view of event-driven processes where you're looking for changes and basically triggering a micro certification, I think is where the approach is, it makes it much more manageable and consumable. Right. Thanks. And then with the agents, learning agents is a challenge. They are an NHI, but they also act on behalf of human identities. So address them.
When we talk about, let's say, the access control models for these kinds of agents as well, do you think traditional control models around RBAC make sense or do we need a combination of, let's say, EBAC and ABAC as well to complement them? Great question. I've always believed that it's a combination. It's never one or the other. For example, there are things that you need. I guess the way to describe this, I would actually characterize this as that there's things that you need to know in advance and then there's things that you get to know in real time.
And so a lot of these things, if you have a priori knowledge of the context of the relationship around whether it's the same, whether it's an agent or if it's a human identity, you need to leverage that. So these are the permissions, the entitlements, the roles that were defined, even the attributes that might be part of that context that you know in advance. That allows you to have that well in hand before the real-time activity starts occurring.
Where I feel the signals and other things get applied to policy bring in kind of the just-in-time attributes or just-in-time environmental variables that would be modifiers to the authorization decision. And so from a review perspective, understanding that context, understanding what kinds of thresholds, what kinds of signals would be maybe increasing risk for allowing a, let's say, a priori determined entitlement to just carry forward, that's where those modify that.
And maybe because of certain behaviors or certain risks that are happening in real time, that might restrict access further than what was initially entitled. So I kind of see that as a combination that all of these things have to work together in concert in order to really provide you with that level of dynamic control.
Right, exactly. I think that's also what we are seeing as well is RBAC remains the foundation, but ABAC and PBAC also being in exceptional use cases and also the overall IG space moving towards a more dynamic contextual authorization platform as well as to have just-in-time access, provisioning you mentioned as well. So that is also what we are seeing in the market right now. When we talk about these intelligence features around just-in-time access or any AI-assisted recommendations, what is it that you find is that being truly requested by the customer?
What is it that truly, let's say, reduces the operational complexity for the customer? Well, the big thing I think is really that they're overwhelmed with a lot of information. And so it's kind of a judicious application of AI technologies can help with that. I don't agree with kind of presenting the user with just a blank prompt screen to interrogate the system. They don't know where to go. It's like you're not giving them any cues. You're not showing them something to react to.
So that approach of just trying to use it as a general query model, I think, is very limited and doesn't really direct them in the right path. But being able to have a conversation with the data, so to speak, being able to see what's going on and have this presented to them in a meaningful way and then direct them to what actions they need to take or what recommendations would best serve the organization, I think that's where this really comes into play and being able to help them in that decision-making process.
So they're not looking at a dashboard and completely glossing over and not understanding it, but being able to drill down where needed and to be able to make decisions quickly. It makes sense. But when you're trying to, let's say, validate an AI-generated access recommendation, how should organizations act on that, for example?
Well, again, this ultimately, the point, I think the human has to make the final call, right? I'm not comfortable yet with the point of context being sufficient enough that the AI can make the decision as to whether this is appropriate or not.
That, to me, I think still relies or depends on the appropriate decision makers in the organization to do that. But these are helpers to really help them understand the decisions that they're making. I think that's really the best application for at this stage. At some point in future, who knows, maybe we get to the point where AI can fully make the decision on your behalf. I'm just not comfortable with that at this stage. I kind of feel like it's, what can we do to help the right people?
Because ultimately, when it comes down to deciding what appropriate access is, the organization is on the hook. If the wrong decision is made, somebody's accountable, right? And so going in and pointing and saying, my AI decided this is not a good answer. It makes sense. I think the accountability part is very important here. I think that's a great answer on that one. I'm just checking if you have any questions from the audience. We do have one question here. The question is, what are the biggest mistakes organizations are making when they are modernizing their IGA platforms?
Nick, do you have any experience? One of the biggest mistakes.
Well, I think that this is also, I think, a really important one is that, especially if you're taking the opportunity to modernize, it really should be an opportunity to look at and improve and not just sort of carry old models forward, right? So technology's improved. We have new capabilities within our products. We run into this somewhat with our own customers where we're in the process of moving them into our new platform, for example. That's a great opportunity to kind of simplify. Make it more sustainable.
Early on, especially in identity and access management and in IGA in particular, a lot of heavy customization was done in order to meet the needs at the time. But often we're finding that a lot of these customizations are really not necessary and that there are more standard ways of achieving the exact same thing. So you can deliver the full richness of capabilities, whether it's on-prem or in the cloud, without compromise. But you shouldn't think of this as a lift and shift.
You shouldn't think of this as just take everything that I had before, all the customizations, and just employ those again. It's actually an opportunity to re-examine, simplify, make it much more sustainable, and be able to then carry that forward for the long haul. Thank you. I think there's a follow-up question from the same person. And the follow-up question is that what would be the biggest challenges they can face in hybrid and multi-cloud environments?
Well, from a governance standpoint, from a hybrid perspective, we maintain parity between our cloud and our on-prem environments. We actually use the same code base. One of the things that we did with our solution in particular was instead of just forklifting our products into the cloud and running them there for our customers, we actually deconstructed our architectures into containerized microservices and then basically presented them and packaged them for cloud-first delivery. And then when we go to the on-prem side, it's a packaging of these containers to be able to deliver for on-prem.
So we're a strong believer in being able to support hybrid models, even mixed models, where some services are on-prem, some services are in the cloud. And so from that perspective, the identity governance should be reviewing all of the connected systems.
And also, the other thing too is the cloud systems need to be able to interact with the on-prem applications and on-prem environments as well. And so that also forces this kind of hybrid model, is that you're not just dealing with SaaS applications in most organizations. If you have a complex organization, you probably have a mix of everything. So we need to support this across all of that complexity to be able to provide a uniform process and the same model, regardless of where the application might reside, regardless of where the service might be running.
And so trying to keep some consistency across that. So to the business, it's always a very straightforward approach to simplify the decisions that they need to make and be able to report on that effectively. Understood. Thank you. Yeah. I think you mentioned about hybrid, but when we speak about, let's say, legacy deployments, what should maybe their modernization roadmap look like? Or do you observe them mainly in particular set of industries or they have certain requirements to keep it on legacy? Yeah.
The biggest qualifier that I see, it's not really based off of industry, it's not based off of sort of vertical or anything like that. It usually comes down to control.
It's like, if it's not something that you really need to have tighter control on as an organization, it's great to sort of get the benefits of offloading the overhead and running it as a SaaS service. If you need more control, then those are the examples where they want to maintain it on-prem and maintain it themselves. And so that seems to be the real differentiator between that decision. And we see that there is some variability in that from different industries.
So like government or other industries where there's certain functions they want to have tighter control on, they'll generally maintain this on-prem. But then there's others that it's like, but these other services I don't care about. So go run those in the cloud because that makes it easier for me. You see what I'm saying? So that's kind of the calculus that I see that's taking place. Our point is that we want to support whichever combination the customer needs. And also give them the flexibility of going back and forth.
You might decide that maybe initially I need to have this on-prem, but later on, it's something that I can run to the cloud. Well, I can move it over to the cloud and I can be fully functional and be able to do this and still make that change. So giving them the deployment options as to where they'd like to have it run, what are the benefits in doing so. But also making sure that that's not a decision that they're locked into. If they wish to change it and go back or revisit this later, we certainly have that flexibility.
Right, exactly. I think this also aligns with what we see as a top driver or a requirement my customer is having this deployment flexibility. Customers are expecting that from a vendor, so I think it aligns with that as well very well.
Now, I think that let's say the majority of what we have seen right now from the results as well is that most of them are on-premise deployments. In the last two, three years, it was still the same case. We believe in the next three, five years, the industry will move towards a more, let's say hybrid deployment or fully iOS model. Do you believe the control, as the control remains the main priority, there will be always an on-prem requirement? I don't think we'll ever get away from on-prem, but I do think that there is a lot of movement to the cloud.
And so there's a lot of interest in offloading. There's also challenges with a number, depending on the organization, too. Organizations sometimes have difficulties maintaining the skillset internally to maintain these infrastructures. So they really are looking for somebody to run and operate it for them. But as I mentioned earlier, one of the things is that if they need to have more control, then that's sort of the deciding factor, if you will. So I do think that there's going to be a shift more and more to cloud as we go forward. I don't think on-prem will ever really go away.
And so I think hybrid models are going to really be the norm. And having the flexibility with a hybrid model where you can go back and forth, or you can have your SaaS environment work with on-prem applications, or vice versa, for that matter, is something that is really where I think we'll end up landing as an industry, because that's going to give the customers basically the capabilities where they need it. Perfect. Thank you so much. I think we have just a few more minutes left, so I'm just checking if anyone has any questions. Nothing yet.
Maybe we can maybe wrap this up with, do you have any, maybe, closing statements or recommendations for organizations that are, let's say, in this transition from on-prem to hybrid? Well, again, one of the things, too, I think the biggest opportunity with this is to take a step back, recognize that, especially if you have a longstanding identity infrastructure in place, this is an opportunity to take advantage of a lot of new methodologies, if you will. And so we went through a period in our history for organizations that have done this for a while. If you're new, it's much easier, right?
But if you've got a lot of infrastructure that you've been using for quite some time, decisions that were made and customizations that were put in place might not necessarily need to be carried forward anymore. So it's actually a worthwhile thing to kind of take stock of that as you're making these plans to move forward to SaaS deployments.
Take a really good look at which services you really need to have in the cloud or which ones you really need to have on-prem and sort of make that decision based off of, like I said, how much control you need to have around this and have that kind of be a guiding principle. But then also look at saying, it's like, okay, well, if we can look at this and treat this, then it's not just a migration, it's actually a modernization of your environment and you'll get a lot of benefits carrying forward.
Perfect, thank you so much. Before we end today's webinar, here's some related research on the topic of IGA. You can go on our website and check out these links. We also have several other services around the adversary events, maybe not other than the basic research that we do here.
Also, we have new impact desk coming up, the first one being the IoT Fabric Impact Day that's in Cologne, Germany on 9th of September. So I think before we end today's webinar, Nick, I would like to thank you for joining today and for sharing your insights from your real-world experiences. And it's always nice to understand what's actually happening in the market right now. So thank you so much for that.
Well, thank you. Really appreciate it.
Thank you, everyone. We'll see you at the next webinar. Thank you.
See All Locations
See All Locations