Organizations managing access across hybrid IT landscapes increasingly find static entitlements insufficient for today’s dynamic and risk-aware requirements. Policy-Based Access Management (PBAM) offers real-time, attribute-driven access decisions based on user context, improving security and reducing complexity.
This webinar will explore how PBAM supports centralized policy control, and compliance alignment. While legacy integration remains an issue, PBAM is becoming essential in Zero Trust strategies and modern enterprise authorization frameworks.
Join us for an insightful webinar with Nitish Deshpande, Research Analyst at KuppingerCole Analysts, as he explores the most critical use cases, challenges, and must-have capabilities of modern authorization platforms. Discover the key differences between cloud-native and traditional policy models, and learn why a multi-speed approach is essential for success. Nitish will also share highlights from his latest Leadership Compass on Policy-Based Access Management, offering expert insights into the current market landscape.
Who should attend: CISOs, IAM architects, platform engineering teams, and compliance leaders
Okay. Hello, everyone. Welcome to today's KuppingerCole webinar, Modernizing Authorization, Dynamic Authorization Driven By Policies. My name is Nitish Deshpande, and I'm a research analyst at KuppingerCole Analysts. And this webinar follows a report which we did earlier this year, in fact, a couple of months back, when we released our leadership composed report on policy-based access management. So this webinar follows up on that one. Maybe quickly overview of what we will go through in today's webinar is, we will take a look at what we believe is the current and the future state of policies.
What are some of the challenges that we are seeing in the market? What is the anticipated direction of the market that we hope to see? And we'll also show you the results from this leadership composed on policy-based access management. So stay tuned. Before we begin, here's a quick housekeeping rules here for you. You all are centrally muted, so you don't need to mute or unmute yourself.
As always, we try to keep these webinars very interactive. So we'll be running a few polls during this webinar, and I would like to encourage everyone who is participating today to participate in these polls and provide your input. We will discuss the results of these polls during the final Q&A session towards the end of the webinar. If you have any questions, you can enter them at any time using the control panel, and we will address them towards the end.
And finally, we are also recording this webinar, so there is a recording and the slide deck will be made available for download in the coming days on our website, computergoal.com. Here's a quick agenda for today's webinar. So I'm going to start with giving an overview of our definition of policy-based access management, a background on where we see the traditional policy model and what's the future policy model.
Next, we'll take a look at our leadership compost methodology and some of the categories that we use for evaluating solutions. And finally, I'll show you the results from this policy-based access management leadership compost. So stay tuned towards the end. But before we begin, quickly, I want to start today's webinar by involving everyone who is participating here today, who is attending here, is the first question. So which authorization model describes your organization's current approach?
Is it A, attributes-based access control? Is it B, role-based access control?
C, policy-based access control? Or is it D, not sure, exploring options? You can enter your answers in the control panel. And I'm excited to see the answers for this one towards the end of the webinar. So thank you for taking part. So before I begin, I want to quickly go through what is the current and the future state of policies. What do we see in that space? And to start with, I would like to make a statement is that policies are everywhere. They will be everywhere.
They are in identity management, access management, as well as other domains, such as firewall, or even our normal day-to-day activities. And what do these policies contain? There are four components. You have the user, that is the subject. That is user requesting action, requesting access to a certain application, resource, database, that's the object. And the context. The context could be something like the location from where the user is trying to access, or the profile of the user, or the time or device of the user.
Context could be a range of attributes that could be taken into consideration. And what do the policies allow us? They allow us to do better roles and less certifications. So you can recertify a few policies instead of going around and recertifying, rubber-stamping manually roles. You can automate static entitlements, deriving static entitlements from policies, and keep them automatically up-to-date when policies change. You have adaptive authentication, which you are already using, for example, for recent context-based authentication. We are also using it in dynamic authorization.
We are enforcing policy-based access management. With runtime decisions about authorization, you have things like just-in-time as well. And finally, policies are the core of the Zero Trust, as found in the NIST document. So policies will remain the core and foundation of everything that we are doing in IAM. But that's not what we have right now. We have different access control models in space right now. And that includes this diagram on the right.
You have not just policy-based access control, but you have role-based access control, attribute-based access control, and also now token-based access control and relationship-based access control. But to enforce these access controls and systems, you need to transmit relevant data efficiently. And there are a few ways you can do that is transporting the authorization data and signals. And these ways are, you have direct queries where you send real-time queries to identity providers. Or it can be embedded token attributes, roles, and policies that are found in cryptographically signed tokens.
And also policy repositories. And you have API gateways for sending real-time signals, which are injected into request headers. And you have the external context providers as well. These signals are mainly related to static data from directories, databases that is used for making the decisions. So that leads us to having good data governance to reduce risk associated with these static roles. The policies will only work when the data is good enough.
However, if there are several weak signals pointing in the same direction, then the combined quality of these weak signals will provide a higher probability for better decision-making. So the complexity of authorization decision-making depends largely on the model that is applied, but also is a combination of different models.
For example, we do not have a right correct model that we have, but if we view these different access control models as complement components of each other in a unified access control architecture, then that makes much more sense instead of viewing them as competing models. Let's take a quick look at the traditional policy model. We know the traditional policy model has a few of the essential components. That is the policy administration point. That is for managing policies. Then you have the policy depository point for storing policies.
Policy information point for providing additional contextual information for policy-making decisions. Then you have the policy decision point. That is for making policy decisions at runtime. And then the policy enforcement point for enforcing the policies. For example, you have the users on the left side. That is requesting access to a resource. It could be an application, database. And the request is sent to the policy information point, where the policy decision point extracts information from the data sources. It is related back to the decision point and then to the enforcement point.
But the new normal is now having a cloud-native policy-based access control architecture. You have a resource component. There is also an API, which could be a service mesh type of situation that sends a JSON query to an open policy agent. We have a JSON data store and also the Rego policy store. The Rego code defines the policies we are using, while the OPA checks the policies and checks if the data access can be allowed or not.
These new approaches, like the open policy agent with Rego, externalize authorization for developers, while hyperscaler policy-based access management solutions integrate IAM, policy enforcement, logging, and auditing across various SaaS environments, PaaS environments. While we were doing this report on the policy-based access management, there are a few challenges as well as some trends that we came across that I would like to highlight here. The first one is about the challenges that we observe in the current authorization landscape.
There are several challenges, but I'll try to highlight four here. If time allows, I'll go through a few more as well. But the first one is the fragmented entitlement models. You have these static entitlement models that are operating in silos, which are rarely connected to overarching business logic or organizational policies. IAM platforms fall short of tracing changes made directly within the target systems, especially when application owners bypass centralized governance.
And when we have this kind of policy spread on our policy islands, that leads to a second challenge, that is the policy spread inconsistency. When discrete data rule sets are applied inconsistently across systems, applications, or teams, it leads to the creation of these policy islands which are not consistent with each other. Other is integration and signal consumption. Most applications that we know, especially legacy ones, were not designed to expose or consume these signals.
Even when signals are available, normalizing and holding them in usable form or policy-based engine requires a high level of technical maturity across the system. Finally, we have the runtime enforcement at scale.
Latency, network segmentation, and scaling challenges introduce friction, particularly in the cloud-native containerized environments where services are short-lived. There are also a few more which I would like to quickly mention here. For example, I mentioned about the legacy ones here. Legacy systems are among the hardest environments in which to implement policy-based access management. These systems are typically lacking interfaces for external authorization and were built around static permission models that assume predefined rules or access control lists.
Retrofitting them to support dynamic policies, whether through proxies or gateway enforcement, is being observed as expensive and technically fragile. Without viable strategies to include these systems as policy-based access management in our architecture, organizations are then faced to run parallel models. So this kind of undermines the consistency and also affects the overall effectiveness of policy-based access control. Another one is the part about governance and lifecycle management. Policy lifecycle management is a very crucial part of the entire PWAM landscape.
Policies must be created, reviewed, versioned, tested, and re-tagged regularly in a way that aligns with your business objectives. However, many organizations lack mature processes for policy lifecycle management. Ad-hoc changes such as unclear policy ownership and missing audit trails can create uncertain PM risks. The absence of intuitive tools for policy visualization and testing further complicates policy creation and evaluation across business units.
So these are some of the challenges that we have seen in the current market right now, but these could be overcome if the market heads in a certain direction, and that is evolution and adoption in these certain areas that we highlight as important for us. First is having centralized policy evaluation. As we mentioned earlier about different policy islands and policy inconsistencies, that could be minimized through having a centralized policy engine policy evaluation that replaces distributed entitlements embedded in applications or systems. Next is dynamic authorization, just-in-time.
Time-bound conditions with access to just-in-time mechanisms will address issues around static entitlements, and it will also address the need of the R right now is having authorization adjust in real-time based on the context. Integration with identity and security systems is the third one. It's integrating with your existing infrastructure. These integrations should support to ingest authoritative, user group memberships and access certifications. They can also incorporate real-time signals as well. And then you have the policy lifecycle and the governance aspect.
It is quite especially important because earlier we saw the traditional policy model, but that thing lacks policy governance aspects, so you need policy governance. You need to manage the lifecycle of these policies, which is critical to ensuring effective and auditable access control as well. And there are a few more as well, like, for example, supporting modern deployment models. And you have current form and enforcement across environments. So policy-based access management supports enforcement across API applications, cloud services, databases, and microservice architectures.
So enforcement points are deployed and access decisions need to be applied. This is either within the application itself, at the network perimeter, or as part of service mesh architecture. This will allow you, the organizations, to protect sensitive resources consistently, and regardless of where they reside or how they are accessed. Then you also have a part about standards and extensibility. Most policy-based access management platforms offer support for industry standards and open interfaces. This extensibility allows organizations to orchestrate access decisions across diverse systems.
And one more is about policy analysis and conflict resolution. This is, of course, quite important. As the number of policies grows, there is the risk of overlaps, redundancies, or conflict increases. Policy-based access management systems often include policy analysis tools, policy simulation tools to validate policy logic before deployment. So development and evolution in these certain areas will help tackle the challenges that we saw in the previous slide. But you also came across some very promising trends, particularly for policy-based access management. On the right side, you see a graph.
This graph is a result of an IAM survey that we conducted this year, as well as last year. In this survey, we reached out to several IAM architects, consultants, IAM company founders, owners, and we asked them a set of questions. One of the questions was, what is the most favorable IAM technology that you see in the next few years? You can see the answer in 2024, 6% of the respondents said policy-based access management. But that number has jumped to 14% this year, showing strong positive growth for policy-based access management in the coming years.
And rightfully so, because as organizations are moving towards policy-based access management, it provides them a more dynamic context-based access control that can adapt in real-time. And by combining AI and real-time signals, it will prove pivotal in maintaining responsive access control and compliances. We believe that in the next few years, policy-based access management will become a core pillar of a modern IAM infrastructure. But if you're going for a policy-based access management solution, what should be some of the drivers?
So these are some of the top drivers that we found that are quite high up the list when acquiring a policy-based access management solution. Typical bias for this policy-based access management products were spread across various industry verticals and also in the company sizes. But these are the top four ones that I would like to highlight here. The first is context-aware access control.
Again, organizations want access decisions that aren't just based on who someone is, but also how, where, and when they're accessing resources. PWAM enables this through its dynamic real-time decisions that adapt to contextual factors like device, security, network, risk, or user behavior. So this is a key evolution from the static models. Next is the zero-trust architecture. Zero-trust basically means always verify, never trust, which kind of plays into what PWAM also stands for.
PWAM plays a critical role here by externalizing and centralizing authorization logic, ensuring consistent policy enforcement. Then we have the multi-cloud infrastructure. Organizations are moving their workloads across hyperscalers for managing access control, and that is becoming increasingly complex. So policy-based access management will help unify these authorization policies across these different environments, and it will help in addressing issues such as policy sprawl and overall administrative burden as well. And finally is the microservices-based application design.
Modern applications are often composed of dozens or hundreds of microservices, each having their own granular access decisions. Policy-based access management supports this distributed model by enabling a centralized policy decision, and that's why more and more companies are moving towards PWAM, and we will see the trend increasing in the coming years. That brings me to my next poll. So do you expect your organization to adopt or expand on PWAM capabilities?
Is it A, yes? Is it B, no?
Or C, undecided? I would like to encourage everyone attending to please provide your input, and I look forward to seeing the results of both the polls towards the end of the session.
Next, I would like to then talk about our Leadership Compose process, the methodology that we use, before I move to showing the results of our 2025 Leadership Compose on policy-based access management. Now, Leadership Compose process is quite extensive. It is a four-step process.
First, it includes research, where we identify vendors, then we send invitations to these vendors to participate in the report. After the initial communication, we then conduct briefings, we conduct demonstration of the product, and then we also send them a questionnaire, which they send us back.
Now, after carrying out this activity with all the vendors that have agreed to participate, and sometimes the number of vendors can go above 30, so it can be an extensive process, we then go towards the next phase, that is analysis. Now, here we will take all the information that we have gathered, and then we will move towards writing the draft and creating the ratings as well. And this is based on several categories that we have, subcategories, and these categories vary based on the report that we are doing.
Once the report draft is ready, it will be sent to the vendor for fact-check, where the vendor has the possibility of going through the report and providing us with any updates that have taken place. For example, the timeline between research and fact-check could be somewhere around a couple of months to three months, and in that phase, the vendor has added a new capability that addresses certain challenges that we saw. And once we have aggregated this with all the vendors in the fact-check phase, we will then publish the report on our website, copylevel.com.
So, finally, now then, I think it takes us to the third phase, that is results. In this 2025, the research was on policy-based access management. It included several vendors, roughly around 10 vendors that we rated, and around 16 vendors that are in a separate vendors-to-watch section.
Now, the vendors that are in the vendors-to-watch section are equally important, and we believe they are part of this market, but through some certain conflicts around timeline issues, they could not be a part of this report, but we have still included them in this report, and you can check this report out, where we highlight one of the high capabilities of each vendor. But yeah, talking about the rated vendors, you have a good mix of vendors here.
Mainly, these are authorization specialists, but also you have some strong, big IAM vendors here, and also some upcoming authorization vendors as well. And it was a very interesting process. After going through with them for a couple of months, three months, we only ended up with a diagram which looks like this.
So, this is the moment, I guess, if you are waiting for seeing the results, this is now. The diagram you have in front of you is the overall leadership diagram. This is a combined view of three different diagrams that you will find in our report, that is the product leadership, market leadership, and the innovation leadership. Product leadership includes evaluation of the product's capabilities.
You have various capabilities around how the product is deployed, what are its interoperability features, and stuff like that, and then innovative leadership looks at the vendor's ability to introduce new and innovative capabilities at regular intervals. We also look at the roadmap and how they are deploying certain capabilities in their own way.
And then you have the market leadership where we take into account several things like the market presence of the vendor, how many partners they have, what's their standing in the market right now, in which geographical region they are based, what is their customer presence, how are they supplying their professional services as well. So, that brings us to this final overall leader diagram where on the right side, in the red mark, you have the overall leaders of this report. This includes authorization specialists as well as large IAM vendors.
In the middle, you have some, in the middle is a section about the challenges. So, these are the vendors which have good product capabilities, but they have some capabilities missing around, let's say, the market presence or the roadmap.
So, they're in the challenger phase, but with right efforts, we believe they will also be strong enough for being classified as an overall leader. And in the leftmost side, you have the followers. Fortunately, no followers in this segment, but followers are also sometimes in a report, but that's where we are right now. We go much more deeper into when we are analyzing a vendor, and that includes analyzing the vendor's products based on several core capabilities.
So, for example, here is a spider chart here that shows strength of a certain, this one vendor, based on these eight capabilities and how they are rated based on each axis. So, you have the, when you take this report, the core capabilities revolve around the policy decision points, enforcement points, information points, administration points, also the governance aspect, policy governance, which we believe is very important. That is also taken into consideration here. How is the product deployed? What is the architecture and deployment state of the product?
And also the interoperability and standard support in this particular market. I think that brings us towards the end of today's webinar. We have a couple of minutes left, but I would like to maybe go through what was the result of the poll.
So, let me check. All right.
So, yeah. First question was, do you expect your organization to adapt or extend on e-bank capabilities? 61% of you have said yes. That's great. 19% are still undecided, while 13% have said no. And the next question was, which authorization model describes your organization's current approach?
Again, with very strong majority, role-based access control has received around 63% votes. Attribute-based access control has around 16%. Not sure exploring a 16% while policy-based access control is only at 5%, which is, I would say, not surprising because policy-based access management is currently not at the level of widespread acceptance that it should be. But I'm confident in the next year or two years, this ratio will hopefully change, and we will see much more shift towards a more dynamic context authorization and moving away from static entitlements.
So, we have maybe over a minute left. I'll quickly check if we have any questions in here. Yes.
So, first is, what are some of the considerations to be taken into account when deploying policy-based access management? Oh, that's a good question.
And also, it includes a very long list of things that need to be taken into account. Like, for example, if I can quickly mention here is to understand when you're trying to approach a vendor is, how does the solution define and implement policy-based access control, basically?
So, because not all vendors define policy-based access management the same way. Some are more focused on centralized policy evaluation with full lifecycle governance, while others prioritize developer-first tooling and runtime authorization.
So, you need to be sure on what kind of approach that you want to take. You also need to be sure checking the vendor is what kind of deployment models are supported. The ones when we did the report, the e-mail platforms were in support for SaaS, on-premise, and containerized deployment.
So, based on your requirement, you need to check in there as well. The list is quite exhaustive. I will quickly share this. Yes.
Now, we also have one poll right now running in the background is, how would you rate the content of this webinar? We do really appreciate if you can vote in here. You can also vote here after the webinar ends.
So, please let us know. But regarding the questions that we have here, I think we are, unfortunately, just over time. But I have linked here some research on policy-based access management. If you go through these links, maybe, hopefully, you can find the answer to your solutions.
And also, I would like to highlight is that we have identity-centric cybersecurity impact day coming up in Frankfurt on 6th of November. So, I would encourage you to go on the website and check out the details on this event. But if you have any more questions, then I'm very happy to take them offline. You can connect me on LinkedIn or you can scan this QR code and reach out to me as well. I have my email ID.
So, I think that brings us towards the end of the webinar. So, I would like to thank you, everyone, for attending. And I look forward to our next webinar. Thank you so much.
See All Locations
See All Locations