Compliance and Audit in the Age of Dynamic Access
Combined Session
Wednesday, May 07, 2025 12:05—13:05
Location: A 03-04
Log in to download presentations
Wednesday, May 07, 2025 12:05—13:05
Location: A 03-04
Watch the video
Hybrid identity has been sold as an interim state, the place you go on your journey away from Active Directory and toward cloud-native, cloud-driven identity. Yet for most organizations with Active Directory, the limitations and gaps in the current landscape leave many unsure if hybrid identity is the final stop on their identity modernization journey.
In this session we’ll explore the current state of hybrid identity, assessing current real-world blockers and gaps for migration away from Active Directory. Additionally, we’ll explore the expanded challenges that organizations face in this hybrid identity world – stuck managing two large-scale identity providers. And for those who believe that cloud is an identity panacea, we’ll touch on gaps in security and organizational resiliency that are only really starting to surface with Entra. A session designed to spark conversation, questions, and thoughts among participants, we’ll explore the nuances of hybrid identity together.
Watch the video
In an era where dynamic access and evolving technologies redefine organizational boundaries, compliance and audit processes must adapt to meet new challenges. This panel will explore how organizations can ensure regulatory adherence, manage risks, and uphold data integrity in systems designed for fluid access. Experts will discuss innovative approaches to access control, real-time auditing strategies, and maintaining compliance in the face of shifting user roles and permissions. Attendees will gain actionable insights on balancing flexibility with accountability in their compliance frameworks.
Watch the video
Standing privileges are the “root cause of all bad in IAM”, so to speak. They are part of over-entitlement. They are the reason why organizations must spend a lot of time for recertifications. Etc. Time to change it. Change requires many players in different areas of IAM, including vendors (for sure), but also end users, auditors, and others. Martin Kuppinger, Principal Analyst at KuppingerCole Analyst, will share his perspective on where and how we could overcome standing privileges in IAM without breaking everything (specifically the legacy we can’t get rid off quickly) and which actions are needed here. He will unveil a vision of an IAM without standing privileges.
Standing privileges are, so to speak, the “root cause of all that’s wrong in IAM.” They contribute to over-entitlement and are a key reason why organizations must devote significant time to access recertifications—and much more. It’s time for a change.
However, real change requires the involvement of many stakeholders across different areas of IAM: vendors (certainly), but also end users, auditors, and others.
Matthas Reinwarth, IAM Practice Director at KuppingerCole Analysts, will share his perspective on where and how we can eliminate standing privileges in IAM—without breaking everything, especially the legacy systems we can’t quickly replace. He will present a vision of IAM without standing privileges and outline the concrete actions needed to achieve it.