Identity and Access Management (IAM) has evolved from basic user accounts and group membership into a specialized set of capabilities for authenticating, authorizing, auditing, and protecting identities at scale. Modern IAM spans provisioning and lifecycle management, identity repositories, access governance, federation and Single Sign-On (SSO), web access management (WAM), risk management, and integrations with other security systems. Many IAM elements are now standardized, with common protocols including SCIM for provisioning, LDAP for identity storage, Kerberos/RADIUS/PKI/FIDO for authentication, OAuth/OpenID Connect/SAML for federation, and XACML/JSON/JWT for authorization and policy expression.
IAM is frequently organized into Identity Management/IGA, Access Management, and Privileged Access Management (PAM). Access Management focuses on enabling secure access to services and delivering SSO by authenticating users on behalf of applications. Integration can be standards-based (federation) or, for legacy web apps, achieved through techniques like password injection or modified HTTPS headers. Key requirements include broad application support (SaaS to legacy), deployment flexibility (cloud and on-premises), and high scalability and availability—especially for B2C peak loads.
ForgeRock Access Management is positioned as an enterprise access management component within the broader ForgeRock Identity Platform, providing authentication, authorization, federation, entitlements, OAuth2/OIDC, SSO, session management, and web services security, integrating through shared administrative tooling and APIs. It supports diverse authenticators (including social login, smart cards, x.509, OTP, and FIDO) and enables adaptive, risk-aware policies through GUI-based Authentication Trees and Registration Trees. Risk decisions can incorporate third-party intelligence via an XACML-aligned architecture, and policies can be imported/exported as XACML and/or JSON. It offers stateful high-availability options but also mitigates state overhead by storing identity/context as client-held JWTs, supporting IoT and microservices use cases. Strengths include scalability, extensibility, standards breadth, and even integration with physical access control; challenges include operational complexity for upgrades and configuration promotion, plus a Mobile SDK noted as beta in 4Q2019.
See All Locations
See All Locations