Operationalize and Optimize Identity Every Day
Combined Session
Thursday, September 18, 2025 14:40—16:00
Location: Ballroom
Thursday, September 18, 2025 14:40—16:00
Location: Ballroom
As identity ecosystems grow more complex, traditional IAM boundaries no longer hold. The rise of B2B networks, dynamic workforces, and non-human identities (NHI) like APIs, bots, and workloads demand a more adaptive, fabric-based approach. This panel explores how the Identity Fabric enables organizations to unify control, visibility, and lifecycle management across all identity types - without adding friction or fragmentation.
Key Themes:
- Implementing Identity Fabrics to span B2E, B2B, and NHI domains
- Dynamic lifecycle management beyond the human user model
- Designing for interoperability, scalability, and business agility
In today's fast-paced digital world, manually handling identity and access configurations is no longer sustainable. This approach often leads to inconsistencies, security vulnerabilities, and operational bottlenecks. This session will show you how to modernize your Identity and Access Management (IAM) by adopting a DevOps mindset and implementing Configuration as Code (CaC). By treating your IAM configurations like code, you can automate and streamline the entire process. This shift ensures your systems are not only more secure and consistent but also scalable and future-ready.
In today’s hybrid environment, every user and application represents a potential entry point for threats. Identity-based attacks are on the rise, and without a cohesive strategy, security gaps are inevitable. This session will provide insights into how to address some of these challenges head-on. We'll provide examples of different approaches to identity security that provides complete visibility into user access and behaviour. Attendees will learn how to reduce their risk profile, respond to threats more efficiently, and build a more defensible security posture that is a true accelerator for business, not a bottleneck.
Identity and Access Management is rarely a one-(wo)man show: End users request access, internal IAM teams manage roles and policies, and system integrators, MSPs, and IDaaS providers each play a part. But who owns what? And who ensures it all runs reliably - not just at go-live, but every day after?
One of the most overlooked (and underestimated) success factors in IAM is the Target Operating Model (TOM). Without one, even the most advanced IAM solutions can collapse under unclear responsibilities, fragmented operations, and overlapping roles.
This session presents a pragmatic approach to transforming the KuppingerCole IAM Reference Architecture into a living TOM. You’ll learn how to:
- Define clear responsibilities across the reference architecture
- Separate roles based on required skills and expertise
- Identify functional areas such as governance, application onboarding, and policy management
- Match the right internal and external teams to each area
- Avoid operational chaos by reducing friction and embedding accountability in contracts and processes
Whether you're preparing your first IDaaS rollout or navigating a complex, multi-party IAM environment, this talk will provide you with a structured path from architecture to execution. Because a good TOM doesn’t just define what needs to be done — it defines who actually does it.