Identity and Access Management (IAM) has evolved from basic user accounts and group-based access into a specialized set of technologies for authenticating, authorizing, auditing, and protecting identities. Modern IAM typically includes provisioning, identity repositories, authentication, authorization, web access management (WAM), federation and Single Sign-On (SSO), identity governance, access reconciliation, and risk management, with extensive integration points to other security systems. Many IAM capabilities are standardized or commoditized, pushing products to support key standards such as SCIM (provisioning), LDAP (identity storage), Kerberos/RADIUS/PKI/FIDO (authentication), SAML/OAuth/OpenID Connect (federation), and XACML/UMA (authorization and user-managed consent). UMA, a Kantara Initiative standard, is positioned as increasingly important for obtaining user consent and supporting GDPR-related requirements.
ForgeRock Access Management is ForgeRock’s WAM and SSO component within the broader ForgeRock Identity Platform, integrating with Common Services, Identity Management, Identity Gateway (for federation), Directory Services, and UMA through a shared administrative UI. It supports major federation protocols (SAML, OAuth2, OpenID Connect) and a wide range of authentication mechanisms, including directories, certificates, OTP, mobile and social logins, and third-party (including biometric) authenticators. It enables adaptive authentication and risk-based decisions using contextual signals (device, location, time, history), and can incorporate external risk inputs via an XACML-aligned architecture. Policies can be imported/exported as XACML and/or JSON, though XACML support includes “Advice” but not “Obligations.”
The product targets enterprise B2E, B2B, and B2C use cases at large scale, runs across common OS and application servers, and integrates with many SaaS apps via SAML/OAuth/OIDC. It offers both stateful high-availability deployments and a stateless JWT approach to reduce synchronization overhead—useful for IoT and microservices. Strengths include scalability, broad authentication support, UMA integration, and even extensibility to physical access control, while challenges include lack of SaaS offering and operational complexity requiring command-line tooling for upgrades and environment promotion.
See All Locations
See All Locations