Organizations’ IAM needs vary widely and are changing rapidly, moving from homegrown tools to commercial off-the-shelf products and now toward both SaaS consumption and tightly integrated IAM embedded in business processes. This integration-driven direction increases demand for “Identity Platforms” that can be customized and woven directly into consumer-facing applications and services, either on-premises or as cloud-run API platforms.
Two digital transformation forces drive this shift: closer interaction with consumers/customers and the need to manage consumer IoT devices. Standard COTS IAM tools often fail to address these scenarios well because customer journeys and device ecosystems require deep integration, consistent interfaces, flexible authentication, and coordinated management of identities and “things.” Compared to traditional enterprise IAM—optimized for complex processes in structured environments with limited application integration—consumer IAM and IoT identity demand integration as a core capability.
Key platform requirements include scalability (from tens/hundreds of thousands of enterprise identities to millions or tens of millions of consumer identities, potentially far more when counting connected devices), flexibility (baseline UI and standardized capabilities plus extensive APIs and customization), and strong standards support to enable interoperable authentication, integration, and rapid adaptation.
ForgeRock is positioned as a leading Identity Platform provider, evolving from Sun Microsystems’ open-source IAM foundations into the ForgeRock Identity Platform. It unifies traditional ForgeRock components—Access Management, Identity Management, Identity Gateway, and User Managed Access—on shared platform services such as directory services, a REST framework, common UI, high availability/scalability, DevOps-friendly deployment (including Docker and automation), common audit and scripting, and open standards. Strengths include proven scale, consumer and IoT support, and standards engagement. Challenges include the absence of a defined cloud service offering and missing Access Governance, alongside open-source dependency risk mitigated by a managed enterprise version and established vulnerability patching processes.
See All Locations
See All Locations