Digital identity is a dominant attack vector in major breaches, with attackers typically compromising user passwords first and then moving laterally to take over administrative or service accounts to exploit elevated privileges. Despite modern alternatives, passwords remain widely used across user, shared, administrative, and service accounts, making secure password handling and privileged access management (PAM) critical. Regulatory pressure also accelerates adoption of stronger controls, including incident reporting requirements for critical infrastructure in Germany and segregation of duties mandates in the US.
Traditional IAM focuses on provisioning, authentication, authorization, directories, SSO/WAM, federation, and governance, historically serving a single enterprise but increasingly extending to partners, suppliers, and customers via federations. Hybrid and multi-cloud needs drive API-based IAM capabilities to enable orchestration across environments and DevOps automation.
Hitachi ID Systems (founded 1992; acquired by Hitachi in 2008) offers an integrated IAM Suite: Identity Manager, Password Manager, and Privileged Access Manager. Identity Manager handles identity and entitlement lifecycles at scale (millions of identities), including group lifecycle management, workflows for approvals/audit/SoD (including nested entitlements), analytics for role optimization and orphan account remediation, and cluster-based role discovery. It supports extensive integrations via connectors and standards (e.g., SCIM/SPML), plus mobile access through a cloud proxy that avoids exposing on-premises systems publicly.
Password Manager provides password synchronization, self-service resets (including pre-boot scenarios), telephone-based resets with optional voice biometrics, enrollment workflows, credential and token/certificate management, and SAML-based federated access with MFA.
Privileged Access Manager secures privileged credentials in an encrypted vault, supports rotation and API-based password retrieval with application fingerprinting, offers multiple privileged access methods (disclosure, injection, proxies, elevation, command execution), automates endpoint onboarding, records sessions with enforcement, and integrates with ticketing and SIEM. Deployment supports on-prem, IaaS, or managed AWS SaaS with replicated, highly available architectures; strengths include integration depth and self-service cost reduction, while challenges include limited market visibility and no out-of-the-box FIDO/OIDC.
See All Locations
See All Locations