Identity and Access Management (IAM) has evolved from basic user accounts and group-based access control into a specialized, multi-component cybersecurity discipline covering provisioning, identity stores, authentication, authorization, governance, reconciliation, risk management, and integrations with other security systems. While many IAM capabilities are now standardized and partly commoditized, effective solutions must interoperate through common standards such as SCIM for provisioning, LDAP (and sometimes NoSQL for CIAM) for identity storage, Kerberos/RADIUS/PKI and modern FIDO/WebAuthn for authentication, OAuth/OIDC/SAML for federation, and JWT/UMA/XACML for authorization. IAM is commonly organized into Identity Management (lifecycle and governance/IGA), Access Management (SSO, federation, authentication, authorization), and Privileged Access Management (controls for privileged users and shared accounts).
Access Management must support both modern SaaS and legacy web applications, using federation standards where possible and fallback techniques like password injection or modified HTTPS headers when necessary. Deployment trends favor cloud delivery, but on-premises remains important for B2E/B2B and some B2C scenarios tied to enterprise backends, with scalability and high availability being mandatory—especially for peak-heavy B2C workloads.
Atos DirX Access is positioned as a mature, on-premises Access Management product enhanced with adaptive (risk/context-aware) authentication, integrated user behavior analytics, web access management, federation, and dynamic authorization based on XACML. It supports a wide range of authentication methods (including OTP, Windows Hello, WebAuthn, and FIDO2), flexible policy-driven factor combinations, session tracking and anomaly detection, and session state sharing across servers. Federation support includes SAML, OAuth 2.0, and OIDC, plus capabilities like SAML proxying, secure token transformation, and dynamic user provisioning (push and pull models). Strengths include breadth, flexibility, multi-tenancy, HA/failover, and deep integration options; challenges include lack of full IDaaS, low market visibility, and an outdated administrative UI requiring modernization, with some integrations requiring coding.
See All Locations
See All Locations