Modernizing Legacy IAM Infrastructure
Combined Session
Thursday, May 08, 2025 15:35—16:35
Location: A 03-04
Log in to download presentations
Thursday, May 08, 2025 15:35—16:35
Location: A 03-04
Watch the video
In this presentation, Allan will explore the challenges of integrating access control with legacy applications and discuss techniques for implementing an access control layer while navigating various legacy constraints.
He will then examine how policy-based access control (PBAC) enables more granular control and explore strategies for integrating PBAC with applications that were not originally designed to support it.
Finally, he will demonstrate how concepts from federation, user mapping, and contextual signals can replicate much of the functionality found in native PBAC-aware applications.
This talk will not propose a specific solution but aims to spark discussions and inspire potential approaches to these challenges.
Watch the video
In the modern digital landscape, businesses are increasingly dependent on efficient and secure B2B interactions.
The challenge of managing and securing the identities of partners, customers and vendors has grown in complexity, often resulting in delayed operations and potential security risks.
This presentation explores the journey to achieve a concept of efficient and automated B2B Identity Management, a key enabler for businesses to enhance operational agility, reduce security vulnerabilities and accelerate growth.
Watch the video
As organizations modernize their operational technology (OT) environments, the segregation between IT and OT is a key strategy to reduce cyber risk and protect critical infrastructure. However, this separation also creates identity management challenges that must be addressed holistically. This presentation explores how Identity and Access Management (IAM) can provide a secure foundation for IT/OT segmentation, enabling strong access governance while allowing necessary interoperability.
We will examine how to design IAM architectures that support both IT and OT requirements, including identity federation, authentication for legacy OT systems, and the secure use of service and machine accounts across domains. Special focus will be placed on implementing Privileged Access Management (PAM) with tiering models (e.g., Tier 0/1/2 separation) to protect administrative credentials and limit the blast radius of potential attacks.
Attendees will gain strategic insights into reducing lateral movement risks, supporting compliance, and enabling scalable, secure operations across the IT/OT divide.