Early-bird Discount
expires in
Register Now

Agenda

Lifecycle, Privilege & Auditability

Lifecycle, Privilege & Auditability

Combined Session
Tuesday, October 06, 2026 14:40—16:00

PANEL: Can You Govern What You Can't See?
14:40—15:00
 

Most organizations have far more non-human identities than human users, yet many remain unmanaged or invisible. This panel explores how lifecycle management, privileged access, governance, and compliance must evolve to provide visibility and control across machines, workloads, services, and AI systems.

Arkadiusz Krowczynski
Principal Product Acceleration Specialist
Okta
With 25 years of IT experience, Arkadiusz is a product and security strategist at Okta. As a Principal Product Acceleration Specialist and veteran global speaker, he now focuses on the next...
Matthias Reinwarth
IAM Practice Director
KuppingerCole Analysts
Matthias is IAM Practice Director. Additionally he acts as lead advisor in various customer projects. As head of the IAM practice, Matthias coordinates communication and exchange within the...
A Reproducible GRC-to-ATT&CK Gap Analysis of Non-Human and AI-Agent Identity [Intermediate]
15:00—15:20
 

The procedures for limiting AI-agent delegation will be shipped by mid-2026. Microsoft Entra Agent ID is generally available as of April 2026, with Conditional Access policies for on-behalf-of and autonomous agents as of June 2026; OAuth 2.0 Token Exchange (RFC 8693), On-Behalf-Of flow, SPIFFE/SPIRE are all production-ready; NIST is launching an AI Agent Standards Initiative as of February 2026. Yet not one binding governance, risk, and compliance (GRC) frameworks   SOC 2, NIST CSF 2.0, ISO/IEC 27001:2022, NIST SP 800-53 Rev. 5, or the legally binding Digital Operational Resilience Act (DORA), requires bounded, time-limited, audited agent delegation. This paper makes that lag measurable: a stacked, control-by-control assessment of five frameworks across five NHI governance dimensions on a published Covered/Partial/Silent rubric, with every gap mapped to the MITRE ATT&CK technique it leaves exploitable. The analysis is anchored by two checkable findings. The NIST SP 800-53 IA-9 identity control was written for services, but it is assigned no baseline in SP 800-53B, so the right control is never required. The absence of agentic delegation in DORA rules out the claim that frameworks will simply mature into coverage. We characterize the transitive delegation gap for AI-agents as a primitive. We validate one RFC 8693 control that breaks a working kill-chain. We position the contribution against the mechanism and standards work that moved the field on in 2026. The gap is not what is possible; it is what is mandatory.

Darshangiri Goswami
Student
Gisma University of Applied Science
Darshangiri Goswami is an independent cybersecurity researcher working at the intersection of identity governance, AI-agent security, and GRC. His current research maps binding compliance...
PANEL: Standing Privilege for Machines: The Habit We Can't Break
15:40—16:00
 

Least-privilege has been enterprise doctrine for machine identities for years, yet standing, static privilege remains the default almost everywhere it's checked. This panel pushes past the usual "just fix it" advice to ask what would actually force the change - and why technical feasibility alone hasn't been enough.

Dr. Phillip Messerschmidt
Lead Advisor
KuppingerCole Analysts
Dr. Phillip Messerschmidt joined KuppingerCole in January 2021 as Advisor & Analyst. Prior to this, he worked for various management consultancies, primarily advising major banks on challenges...
Matthias Reinwarth
IAM Practice Director
KuppingerCole Analysts
Matthias is IAM Practice Director. Additionally he acts as lead advisor in various customer projects. As head of the IAM practice, Matthias coordinates communication and exchange within the...
Almost Ready for the AI & NHI Impact Day 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.