Identity and Access Management (IAM) is presented as a core cybersecurity foundation comprising provisioning, identity repositories, authentication and authorization, web access management (WAM), federation and Single Sign-On (SSO), governance and reconciliation, risk management, and integrations to other security systems. IAM is commonly divided into Identity Management/IGA (lifecycle management and governance), Access Management (authentication, federation, authorization), and Privileged Access Management (PAM) for highly privileged users and shared accounts, including password and session management. Because many IAM capabilities are now standardized or commoditized, successful products must interoperate via common standards such as SCIM, LDAP, Kerberos/RADIUS/PKI/FIDO/WebAuthn, OAuth/OpenID Connect/SAML, and authorization standards including JWT, UMA, and XACML.
Access Management focuses on delivering user access to services and SSO, either through federation standards or—when legacy web apps lack federation—through techniques like password injection or modified HTTPS headers. It must span SaaS and legacy apps across hybrid IT, and still often requires on-premises deployments for B2E/B2B and some B2C scenarios tied to enterprise backends. Scalability and high availability are emphasized, especially for B2C peaks.
Atos DirX Access is described as a mature Access Management solution offering adaptive (risk- and context-aware) authentication, WAM, and federation, plus integrated User Behavior Analytics (UBA) and Dynamic Authorization Management via XACML. It supports on-premises, managed service, and cloud deployments, including multi-tenancy. Authentication factors and standards support is broad (e.g., X.509, OTP, an authenticator app, Windows Hello, FIDO2/WebAuthn) with policy-driven combinations. Session management includes context sharing, correlation across browsers, optional full session tracking, anomaly detection, step-up authentication, and session state sharing across servers. Federation features include SAML/OAuth/OIDC, SAML proxying, dynamic user provisioning, preconfigured SaaS profiles (e.g., Microsoft Office 365), and secure token transformation. Strengths highlight scalability (including IIoT), flexibility via REST APIs, and uncommon depth in dynamic authorization; challenges include a dated administrative UI, limited full IDaaS positioning, and low market visibility, with a modern responsive UI planned.
See All Locations
See All Locations