Digital identity underpins modern business but has become a high-risk battleground, frequently exploited through compromised credentials and overly broad access rights. Many major breaches have involved leaked usernames and passwords, and excessive permissions can amplify damage—enabling intellectual property theft, privacy loss, fraud, revenue impacts, reputational harm, and sabotage. Identity Governance and Administration (IGA), as part of Identity and Access Management (IAM), addresses the lifecycle of accounts, attributes, and entitlements across on-premises and cloud environments. Core IGA capabilities include provisioning and de-provisioning, access governance policies (periodic re-authorization, managerial attestations, privileged access rules), segregation of duties (SoD) controls, and comprehensive reporting, auditing, and dashboards. Role and entitlement modeling and lifecycle management are also central, with Data Access Governance (DAG) highlighted as an important extension for controlling access to unstructured data in repositories like SharePoint and file servers.
RSA Identity Governance and Lifecycle is positioned as a configurable, enterprise-grade IGA offering, deployable on-premises, in the cloud, or via managed service. RSA Identity Governance focuses on access certifications, automated policy compliance monitoring, anomaly detection for potential entitlement abuse, and risk analytics that can prioritize remediation actions. RSA Identity Lifecycle provides request and approval workflows, policy-driven enforcement (including auto-rejection of prohibited requests and “break the glass” overrides), and broad connector-based integration for collecting and provisioning identities and entitlements across many directories and SaaS/IaaS systems. Reporting includes dashboards with drill-down visibility and standard reports spanning logins, orphaned accounts, violations, and risk/cost analyses. Add-ons include RSA Data Access Governance for unstructured data and RSA Business Role Manager for role discovery and modeling. Strengths include scalability, connectors, compliance support, and ecosystem integration; challenges include limited ETL depth, reliance on third-party privileged access tools, and risks of over-provisioning from entitlement suggestions.
See All Locations
See All Locations