Early-bird Discount
expires in
Register Now

Agenda

Identity Fabrics: Adaptive, Distributed, and Interconnected

Identity Fabrics: Adaptive, Distributed, and Interconnected

Combined Session
Wednesday, May 20, 2026 11:00—12:00
Location: A 05-06
Log in to download presentations

On Beyond OAuth: Adapting Security to a Dynamic World
11:00—11:20

Watch the video

 

When OAuth 1.0 was invented in the mid-2000's, a native application meant something running on a desktop and websites did not always have APIs. And when they did, you could just replay someone's password to authenticate with HTTP Basic like we always had from the web's early days. But OAuth came and showed the world a better way, and OAuth 2.0 refined that model and cemented the protocol family as the core delegation protocol for nearly everything online. Its core model of connecting one website to another for delegated access has served it well, and OAuth has been successfully extended into related fields like identity (with OpenID Connect) and high assurance (with FAPI).

But now we're 20 years past those early days and the has changed drastically along with every part of life that's now connected to it. Today, machine identities and AI agents are questioning the fundamental model of OAuth in ways we've never seen. OAuth has proven to be incredibly flexible in the past, and new extensions are being proposed to bring it into this new world. At the same time, alternatives have been proposed that have started to take root in some spaces. Are we on the verge of a new world?

Come to this talk to learn about how OAuth is changing, and how our views of security are forcing re-evaluation of contexts and assumptions that have served the internet well for decades.

Justin Richer
Senior Staff Engineer
MongoDB
Justin Richer is a security architect, software engineer, standards editor, and systems designer with over two decades of industry experience. He is the lead author of OAuth2 In Action and...
Make or Buy - Why just another software isn't the future of IAM at Schwarz
11:20—11:40

Watch the video

 

At Schwarz, we are used to large numbers. More than 150 billion revenue, more than 650.000 employees, 32 countries, different divisions, our own hyperscaler cloud and so on and so forth. For our workforce IAM, this means a lot of work. 850.000 identities to manage and govern, 25.000 off- and on-boardings every month, 5 million authentications per day and approximately 150 Million identity related events per day. For years we have been struggling with vendor software, adapting heavy customizing, huge investments into infrastructure and increasing complexity of simple tasks to unmanageable systems. So we asked ourselves - is the way forward just another software, or is a more radical approach needed. At Schwarz, our identities belong to us!

Patrick Messerschmidt
Domain Engineering Lead Identity & Authentication Platforms
Schwarz Digits IT KG
Patrick Messerschmidt is the Domain Engineering Lead for Identity & Access Management at Schwarz IT, the digital provider for the Schwarz Group (Europe’s largest retailer). With over 20...
Dorian Röck
Domain Product Owner Identity & Authentication Platforms
Schwarz Digits IT KG
Dorian serves as Director and Domain Product Owner Identity & Authentication Platforms at Schwarz Digits IT KG. He is responsible for the IAM strategy, architecture, and operations for the...
From SAP IDM to Identity Resilience: Modern Architecture and Governance in the Age of AI [Advanced]
11:40—12:00

Watch the video

 

As organisations phase out legacy platforms like SAP IDM, identity is shifting from operational administration to strategic resilience. In an era defined by cloud transformation, non-human identities, regulatory pressure, and AI-driven automation, identity architecture and governance must evolve.

This session explores how to modernise legacy IAM environments into resilient, future-ready identity ecosystems. We will discuss architectural decisions, governance models, and measurable outcomes that matter to both business and technical stakeholders — from reducing risk and improving compliance to enabling agility and innovation.

Attendees will gain practical insights into building identity resilience that supports security, regulatory requirements, and long-term digital strategy.

Thomas Müller-Martin
Partner Director & Field Strategist DACH
Omada
Thomas Müller-Martin is a Field Strategist at Omada and a veteran in Identity and Access Management (IAM) with more than 20 years of experience. He helps enterprises modernize identity...
Dr. Lisa Zimmermann
Senior Consultant IAM
Fressnapf Maxizoo Pet Retail
Lisa has two lovely dogs, a PhD in Astrophysics and over 11 years of experience in building and maintaining corporate IAM landscapes in different industry sectors. First hand experiences in the...
Almost Ready for EIC 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.