Modern IAM strategies need more than just high-level ideas — they must be turned into clear, practical actions. As identity types grow and systems become more complex, CISOs face the challenge of connecting strategy with day-to-day operations without losing control or consistency.
KuppingerCole’s Identity Fabric and Reference Architecture models offer a structured way to operationalize IAM strategy. This session will explore how to use these tools to align governance, processes, and technologies across all identity types — from employees to customers to machines
Christopher Schütze, Chief of Advisory and CISO at KuppingerCole Analysts, will lead the session with insights from recent advisory engagements and practical field experience. He will highlight where organizations succeed — and where they struggle — in bridging the gap between identity strategy and implementation.
Attendees will explore real-world examples, reflect on challenges in aligning identity types under one strategic fabric, and exchange lessons learned for building resilient, scalable identity architectures.
Welcome and good afternoon to our webinar here. We will talk about Bridging Identity Fabric Strategy Across Identity Types and hopefully the weather conditions for you are more or less okay because it's a bit hot outside. Also here in Stuttgart we have almost 40 degrees so the potentially just take 25 to 30 minutes. I'm really focused on temperature today but still I really hope it will be a very interesting webinar for you, give you some insights and thoughts about how to really operationalize different identity types by using the identity fabric.
Quick word about me, I lead the advisory team here with KuppingerCole, I'm also the CISO with KuppingerCole, so I'm working in a mixture of practical stuff and theoretical stuff and that is what I try to share with you today. And also happy for having all of you here, then let's jump into the next slide. As all of you know for the new ones we have some housekeeping slide, so before we dive in just a few quick notes.
You are muted throughout the session but feel free to use the application, the chat function, the question tab to ask me some questions during the webinar and I will answer them afterwards collected. We will also have two polls, the first one will be right in two or three slides and also the results will discuss at the end.
So here's the journey for today, the first part we will talk about how to meaningfully structure different identity types within a shared identity and access management strategy and the second part really important how to operationalize that strategy into something real useful. So really driving the progress and I try to bring it a bit to life with practical stories or ideas what we did for customers to make it a bit more feasible or touchable for you.
So identities are everywhere, we have employees, we have customers, we have partners, suppliers, devices, bots, APIs, that is all known since almost two years. We have some more fun around agents which is basically some kind of thing, tool, whatever that can do stuff like an internal or external employee. So just an additional challenge, something we need to be aware of and each of those different identities brings unique access needs, governance demands and also life cycle patterns from responsibility to just the typical join a mover lever stuff we all know.
So not a new phrase, identity the new perimeter and our job is to manage that perimeter on a very strategical level with a structure and a structure that helps us not to lose the flexibility. So let's kick things off with as mentioned a short poll. The question is do you have a structured approach to managing all your identity and access management topics across different identity types? Take a moment to vote, we will as mentioned return to results later and use them to reflect on the journey we have covered during that webinar.
The coping a call identity fabric is not a product, it's a paradigm and that's what we always try to share. It provides a unified framework for managing all types of identities. So as you can see on the left side from human to non-human covering the same strategic consistency.
Maybe one example here, so one of our clients how they use it, a global manufacturer, a smooth partner and onboarding process but their non-human accounts, some space for improvement, no ownership, no life cycle, no governance and they use the identity fabric and also the reference architecture which will be shared the next slide by mapping capabilities to identities and the fabric help them to clean up here and rebuild and reuse existing things here.
I honestly don't want to jump too deep into the identity fabric as we have a lot of webinars and research covering this in detail, it will be referred in the slide deck as well. So Matthias and Philipp had a great workshop at the European identity cloud conference this year and Martin Kuppinger and Philipp Messerschmidt also did a great webinar by introducing the 2025 version in, I think it was January, it's linked. So that is the idea.
Short recap, nevertheless the identity fabric for those who don't know, it is there to have a central set on provided capabilities that are bundled into services and fulfilled by tools. So you come from the idea of what do I need and not talking about what kind of tool do I have and also having in mind that tools will change over time, new requirements will come up. Let's bring in the Kuppinger core reference architecture. This is our high-level capability blueprint that more or less self-registration, some kind of password reset and also constant handling is very common.
Partners need delegation, federated access for instance and very good auditing, strong auditing on what they do, what they are able to do. And the internal employee requires the traditional stuff we know, entitlements, approvals, role concepts and separation of duties in the best case. And then we have the non-human identities, they need life cycle management, also automation and added some secrets management. And by trying to solve all this with really one rigid architecture, this simply doesn't scale.
This is where this reference architecture allows us to modularize tailored capabilities per identity type. But that is not the whole truth. Let's jump, this will be the next slide. So how do we go from that framework to a more executive way? The identity fabric and reference architecture only really brings value if we understand what different identity types actually need and then implement accordingly. And the model guides us, but the architecture and the processes, but it's the architecture and processes that brings it to life.
And that's why we introduced already at the EIC in that mentioned workshop, the two-tier architecture. We need more than one layer for the reference architecture. The one layer is the identity fabric, more or less your overall view, your strategic umbrella, your approach. And then we have, we call it master identity management reference architecture, that was the slide I shared. And beneath this strategic layer, we have now more specific second level reference architectures that are really tailored to specific identity types.
And this layered approach ensures that we do not only maintain the unified strategic umbrella, but also address the different needs of employees, customers, partners, and the NHI in a dedicated architectural model. So, for example, your customers expect fast, seamless onboarding and data privacy, sure. And as mentioned, partners need delegated admin and federated login, and the employees require a structured provisioning approvals and analytics. And these demands aren't optional, they shape really the sub-architectures.
And the two layers help us to control on the top really while maintaining flexible below. And in the slide, you can see we have the, for partners and suppliers, I will share the one for customer-centric as an example, for privileged access management, and also for non-human identities.
So, here's what our CM reference architecture currently looks like. It's still in draft mode, and also we use it for customers. We work with a telecom provider that rolled out the structure for end-users and use this for self-service omni-channel login. Especially the data deletion, so the right-to-be-forgotten flows. And now compare that very specific CM reference architecture to partners or to the partner setup where the core identity flows really look different. You'll see capabilities like SAML federation role delegation and the very partner-specific audit.
And the architecture really adapts by identity type. That's the power of layering and something we developed over the past years by realizing we need to level deeper, we need to be focused more on identity-specific things.
So far, we've already covered why identity types matter and how to strategically translate this into a layered architecture. Now, a very important question is, okay, that's a great theory, a great framework, but how do I operationalize this? We will walk through in that methodology really from evaluating your current state, then seeing what is needed, whether it's internally or externally driven by companies like us that are working in trends topics, trend topics as well, to then identify the gaps and see how to close it by using reference architectures.
But before we move ahead, here's our second question to you. What is your biggest obstacle in turning your identity management strategy in action? Is it prioritization, ownership, architecture, complexity, or something else?
Again, share your thoughts. We will bring your answers into the discussion at the end of this webinar, so around about in 10 minutes.
Okay, let's jump into the methodology overview, the method. Already teased it a bit in the introduction.
Now, let's go through it. It's more or less following the plan and adapt approach, five steps that can be repeated once and again and again and again, because new requirements, new evaluation changes, things changes, and just need to be covered here. The first step is surprise, understand what you already have. Something like a baseline analysis of your capabilities. An important thing here, which is new to the approach we had in the last years, is really covered for different identity types to see what is going on.
And then, and that is the mixture of external experience, whether you learn something at EIC and other conferences and webinars and have internally or have internal business drivers. So, you build your desired future state. The idea of the identity fabric doesn't matter which identity type you take here, is that you are open for new requirements and, as mentioned, you come from what you need and what you potentially need to have in your mind. The tool doesn't matter at the beginning.
Nevertheless, for when then comparing it in the next step in the gap analysis, if you have a beautiful idea, whether it's marketing, sales driven, or really some security internal business need by taking your maturity assessment, you need to see as well, is the tool sufficient or not, or do I need another one? Especially if you go into NHI stuff and more modern things, agents, typical IGA solutions are not sufficient on that level here. They are just part of the whole story, if you think on the top level reference architecture.
The next step, you know what you want to have, you identified what is missing, now you need to break it down to, we call that action items, small ones, large ones, and map them to timelines, priorities, and responsible teams, and that is really, we will see an example, a very challenging part, because you need to ensure that this covers the business needs, security needs, regulatory needs, if mentioned as well, and must be operationalizable.
Otherwise, you just have a beautiful strategy, which you realize after four years, you haven't fulfilled 10% of it, and that is something that is really important. So, let's see an example. I took here again the high-level identity and access management reference architecture. Nevertheless, if you have, for instance, the CM1, it's working more or less the same way. You take this thing here, and assess capability by capability. Do I have it? Do I need it?
Is it in, or you start with, is it in-scope or out-of-scope? This is always the first thing, and then you evaluate capability by capability, what level of maturity is there? Is this more a manual approach? Is this more automated, and, or is it very modern, and things like that? And this identity type, for identity type, if you have the whole big picture in this view, in the top-level reference architecture, you more or less combine the underlying second layer, because challenges are also around responsibilities and departments, and, for instance, governance.
Maybe for your employee, it's perfectly green. For external partners, it's red, and for customers, or responsible person for customers, take insurance companies, it's maybe yellow, something like that. And that is the starting point. You get an overview of what is good, what is okay, and what is not okay. That always compared to, we use our baseline here, status quo, and as you can see in that example, this will be important for further slides, in the section authorization, we have a lot of orange, and red, and nothing's green.
So, that could be a topic, potentially. Next step, then, is to bring in context.
So, as mentioned, internal knowledge, internal needs, sure, but also experience from the market, from outside, what are the market drivers, I mean, LLM, chatbots, and all that stuff, and artificial intelligence, everyone is talking about, the reality in organizations is a bit mixed, is this a topic we need to cover, we need to consider, is there an identity access management issue, something like that.
I mean, for instance, passwordless authentication is this very, in many organizations, it's more or less state-of-the-art across CM architectures, but not for everyone, and maybe this is also covering for other identity types, as well.
And we use for this, we call this topic radar, to evaluate, we have the different trends, and see, coming from the internal requirements, the customer has, the teams have really, this, I love this, doing in real, because these are some kind of workshops, brainstorming, where you can really drive crazy ideas, sometimes, to evaluate, is this relevant for your organization, and not usually focused about one to five years, on average, that is something to use. The next step is something, we, as an analyst company, and also be an advisor, we love to do, build scattergrams, bring all together.
This covers, basically, what is in place, what is planned, what's needed, and visualizing this per identity type, we can use it to prioritize. On the graphic, you can see the two dimensions, we have maturity, and priority, both normalized to a value from zero to 10, and then we can build clusters.
In the red circle, you can see the things with high priority, and high need for action, compared to a very low maturity, and this is something you might consider to cover first, you might have the example, on the reference architecture, and maturity level in your mind, and on this slide, surprise, entitlement management is priority eight, and level of maturity is two.
Which means, we also then have a blue square, with potentially important topics, that are on the priority list, in the middle, but also already have an acceptable level of maturity, something you need to cover as well, and then the green square is more or less the sweet spot, the stuff you're good in, high maturity, low priority, and in total, having this for one identity type, building this for the whole company, this gives you really a good insight into what to do first, focus first, you can also use different dimensions here.
And then, we are jumping into very concrete action items, you identified what is important, based on identity type, which is covering the big picture, always layered approach, and need to describe it, and that is always an important stuff, because here, we are usually in that part, where we need senior management, budget approvals, we are talking about timelines, impact to the organization, to the security, and sometimes also enabling business, changing processes, so this is really an important part, and each action item should include, we use that approach, I mean, there are potentially also other methods, a description is important, an expected impact, a timeline, and very important in ownership, especially if you have a multi-layered architecture.
And in this example, this is again talking about entitlement management, we described, for instance, the challenge as only infrequent and decentralized access revenues exist today, and chaotic downstream processes, resulting in a lack of control. And this is obviously for the identity type employee, but can be approached similar for external partners and NHI as well.
The project goal of this action item, then, would be the development of a comprehensive authorization model, additionally, we described specific actions and impact, if not done all based on the idea of breaking down the requirements based on priority and maturity of different identity types, to get the best fitting strategy with the best risk mitigation approach, and hopefully, the least danger to fail. And then, we have slide 18, we will, now the next step is you have action items, you have dependencies and things like that, and you need to build a roadmap.
The operationalization of things here is really difficult, in the example you can see the entitlement management is not starting as a first project, even as it was rated as most important and least level of maturity, because there are dependencies to other projects, and this is then something you need to cover.
You need to discuss, align this on identity types, combining with a higher level of the specific tools and processes that are there, because usually, you know this from your enterprises, from your company, there are projects ongoing, people are working on things, teams are working on things, and this need to be covered, and that is also a very important part.
As we also all know, and that's why it's a repeating cycle on a certain level, if you now create a three years plan, new challenges will come up, and it needs to revise some, it needs to be checked whether it's still valid, or if you need to adjust this. And that's basically the summary of today's presentation, so let's jump into the final takeaways, and bring it all together with a few closing ideas about that. The first one is the identity types matter, and the structure wins.
You need to understand your identities in the first step, and manage them then with a structured approach is the second important thing. You have one fabric, one identity fabric, and many architectures. A single strategy here can support multiple implementations when designed intentionally. The third point is different journeys, and a shared foundation. Not every identity type needs the same path, but they should build on the same principles, and that is important. Capabilities over tool, and use cases over buzzwords.
So the success comes from solving real problems, not always by chasing trends. And then talking is fine, but action drives changes. What drives change? Don't wait for the perfect model, build momentum with tangible action items, and repeat that, check whether it's still valid or not, and roadmaps make it real. Strategic change happens step by step with the alignment, with clarity, and execution. And that's basically, honestly it took two minutes more than I planned, so sorry for that. Thank you very much for listening.
I hope you received a good insight into the topic of how to bridge the identity fabric strategy across identity types. And now, let's take a look at the poll results from earlier, as I used this new platform the first time. Let's see what's the result. I need to vote as well potentially.
Okay, so for the poll, what is your biggest obstacle in turning your identity and access management strategy into action is, and that's a very typical one, 71 percent lack of internal ownership or alignment. We have 29 percent, so the other people who voted, oh someone changed, now it's too late. We have 21 percent technical complexity and integration challenges, and the one who voted last was limited resources and budget. And for the next question, the question was, do you have a structured approach to managing all your identity and access management topics across different identity types?
And here's really an interesting result. We have 38 percent for partially. We follow a basic structure, but it is not consistent across identity types, so maybe the webinar today helped you to get an idea. We have 25 percent for yes, we have a well-defined and documented approach, and we have 25 percent also for no, our approach is mostly ad hoc and reactive. And one vote for not sure. Identity and access management responsibilities are handled by different teams. Then we have a question. Where do we have?
Okay, so let's have, what's the biggest mistake organizations make when designing identity and access management for multiple identity types? The biggest mistake is treating all identity types the same, I would say, or the complete opposite as well, like creating a disconnected solution for each group. We often see teams applying a single architecture across the board, I would say, and expecting it magically fit to customers, partners, employees, and bots, and I think this works.
So the solution is, I would say, in the middle, it's a unified strategy, the identity fabric paired with, as I said in the webinar, by using a tailored second layer reference architecture for specific identity types. But this is, and coming back to the poll, also a topic of responsibility within organizations and needs to be handled. I think this covers this here. What if different business units own different identity types, or how do we unify the approach? And that is honestly always the case.
I mean, in typical organizations, you have OT, potentially not really the idea of having an identity, you have the customer stuff, maybe you have a partner's department, and you have the employee. And usually it starts by bringing all the identity owners into a shared target vision, so the identity fabric and the top level reference architecture here, and then basically start to build an organization around it. So maybe what never helps or is a solution if you then make people responsible or take responsibility for specific identity types on the wrong level.
So the reference architecture, how we use it was a two-layered approach. The example was a telecom provider. The SIEM part is in, so the identity type and customer is in the responsibility of that reference architectures in that specific apartment, but they are also forced to communicate their thoughts into the top level architecture and build into the identity fabric. And I think with that, here also the slide, if you have any further questions, I'm happy to reach out.
I would say it took a minute longer than planned, but I wish you a beautiful rest of the day, enjoy the beautiful weather, and I'm happy if you have any kind of feedback, feel free to reach me out. Thank you.
See All Locations
See All Locations