Access Management has transformed from a siloed set of controls into a critical enabler of digital business. This webinar explores how organizations can modernize their access strategies to support hybrid IT, secure machine identities, and meet growing compliance and user experience demands. We will examine trends such as IDaaS adoption, AI integration, and zero-trust architectures, while offering guidance on choosing the right solution for your enterprise.
Alejandro Leal will unpack key insights from KuppingerCole's latest Leadership Compass on Access Management — giving you a clear view of the top vendors, emerging architectures, and what’s next for the industry. He’ll explore how organizations are modernizing authentication, securing AI agents and non-human identities, and connecting legacy with cloud systems. From ITDR to passwordless adoption and hybrid deployment models, Alejandro will provide practical strategies to strengthen security, ensure compliance, and keep organizations ahead of the curve.
Jay Reddy, Head of Growth at ManageEngine, will share his experience driving global adoption of IAM and SIEM solutions. He’ll discuss aligning access management with broader business goals and provide insights into scaling these initiatives across complex enterprise environments. Jay will offer real-world examples and actionable advice for security and IT teams navigating today’s evolving identity landscape.
Who should attend?
IT and security leaders, IAM architects, compliance pros, and digital transformation drivers who want to level up their access management. This live webinar dives into Zero Trust, passwordless strategies, hybrid IT, and securing machine identities — giving you the insights to keep your business secure, agile, and future‑ready.
Welcome to the webinar, Navigating the Future of Access Management. My name is Alejandro Leal. I'm a Senior Analyst at KuppingerCole, and today I will be joined with this webinar. I'll be joined by Jay Reddy. He's the Head of Growth at ManageEngine. He will jump in after my part of the webinar, so you will stick with me for some time, and then he will be joining me for a panel discussion, and at the end, as always, we will have some time for Q&A. Maybe just a quick warning.
I recently recovered from COVID, so I'm going to try to speak slow, and if I get a sudden attack of coughs or sneezes, just bear with me, okay? So a brief reminder of some of the things to keep in mind. So all of you are muted centrally. There's no need to mute or unmute yourself. We will also be conducting a few poll questions, so I would appreciate if you can participate on those, and yes, we will be recording the webinar. In the coming days, you will be able to see the recording as well as download the slides that we used for the webinar, so just keep that in mind.
So yes, this is the agenda for today. So as I said, I will be digging into this topic of access management. Then I will be joined by Jay, and then we will have time for Q&A. But before, here's the first question, and the first question is, where are you in your access management journey? Are you just starting now, or are you actively implementing your access management strategy? Are you struggling or trying to deal with managing a hybrid environment, or are you already fully cloud native? At the end, we will see the results of the questions, so we can also have some time to talk about those.
So the term access management, this quote comes from the leadership compass on access management that was published in May of this year. The report was one of the largest, with over 30 vendors participating. It was one of the largest in my time here at Kupinger Call, and I will show you later the overall leadership category, so you can see the results of the report. And this webinar will be getting some information from that report, especially in the part of recent developments and market trends.
But of course, May is already a long time ago, and I think we all know that in our industry, things are moving fast and things are changing. So I hope to do a report soon in the next year. So if we look at our identity fabrics concept, if you're familiar with Kupinger Call, you've seen that we've published multiple reports on this topic. There was a leadership compass report published also in the spring. And if we look at this, we understand that access management is no longer just about logging in or role-based permissions, right?
It's a dynamic integrated service that is embedded across the entire identity ecosystem. It's supposed to provide context-aware, policy-driven access controls based on user behavior, device posture, risk signals, and business context. So rather than being just, let's say, a standalone system, within these identity fabrics, access management becomes a capability. And it's supposed to ensure a consistent, intelligent authorization for every identity, human and non-human, across all applications and environments.
So if we move on to the next slide, we see that certain capabilities have evolved, and especially, let's say, the perceived importance of certain capabilities across the present and future. And it's important to know that the features listed on the left side, they're not necessarily obsolete or old, but they simply became foundational. They became, we can say, expected. So advances in technology, shifting market demands, and rising customer expectations have transformed these once-innovative capabilities into basic requirements.
So for example, if we look at dashboards and reports, we see that although they are still relevant today, and they remain essential, they are no longer something that makes it different to other features or other vendors that do the same. It's more of an expected feature.
And today, attention is shifting toward more complex and forward-looking concerns, such as NHIs and the rise of decentralized identity. And in this slide, you can see that authentication is a clear example of this evolution. We moved from basic password systems, password-based systems, to MFA of passkeys and passwordless.
Here, I was just talking about the capabilities that we used in the Leadership Compass to evaluate different vendors. And as I mentioned, I expect that some of these features will no longer be innovative, let's say. They will be expected. It will be more of a basic requirement. So I'm looking forward to the next report so we can see how these things are changing. But let's just move on to the next slide. But before, here we have another poll question. So the poll is, which of the following trends are you most interested in exploring further?
IDAS and hybrid, AI and machine learning in access management, securing NHIs, or decentralized identity and verifiable credentials? So please, we would like to see what you guys are thinking. It can help us on our research to see how you guys are doing. Okay. So as I've been alluding so far in the presentation, there have been few areas that have transformed how we do access management. If we look at, for example, digital transformation, I think that the term is a little bit tricky because it assumes that an organization's state is transformed from one state to the other.
But in reality, digital transformation is an ongoing process, an ongoing journey. Organizations are constantly changing, adapting, and adopting new technologies. And access management varies by context, right? But it follows the same goal.
Securing, securely controlling who can access what. So if we look at internal workforce, it typically relies on centralized directories, policies, and tools like SSO and MFA, right, to ensure that employees have the right access based on their jobs. When we look at B2B, it supports secure collaboration with external partners through federal identity, delegated admin, and other things. And for SIAM, the shift is more towards seamless user experience, scalability, and privacy.
In an identity fabric, as we discussed earlier, all of these three are in a way supposed to be managed as interconnected capabilities, right? The goal is to deliver consistent policy enforcement and observability across diverse identity types and use cases. And in the next slide, I will show you the results of the leadership compass. But before, just a quick, let's say, introduction on how we do research.
Basically, we first identify vendors on a given topic. We reach out to them, and we send them invitations. If they decide to tell us all about that later, but with hundreds or even thousands of questions that are very technical. And then based on that, then we analyze the vendors. We have briefings with them. We have demos with them. And then we write all these chapters. We create a report, and then we have a fact-check stage where we have a second round with some vendors, and then we publish the report. It takes around three to four months, but it really depends on how big the report is.
So here's the overall leadership in the Access Management Leadership Compass. As I said, it was published in May 2025. The chart is linear, so followers appear on the left side, challengers in the center, and the leaders on the right. The rating provides, let's say, like a consolidated view of functionality, innovation, market presence, financial security. All of these vendors are different. They have a different background, different way of doing access management. So we recommend organizations to evaluate each of them to see which one is more suitable for their own needs.
But if we look at the overall leaders, we find that here vendors demonstrate a strong partner ecosystem, strong market position, and they have presence in various regions around the world. For the challenges, we see vendors that offer strong solutions, but maybe they have yet to achieve leadership status due to gaps in execution, or limited market presence, or maybe they miss critical features, or maybe they don't have any compliance with some of the standards that we believe are important.
Some may excel in specific areas, in like a niche industry, or in a region, but perhaps they lack the scalability or the breadth of integrations that define the leaders. But again, they all do a very good job at doing access management, and ultimately it really depends on what your organization needs. So that's why we encourage readers to look at all of these different vendors and to see which one is better for them. So based on our latest research, we can see the market trends. But before, the last poll question, which is, are you managing machine identities within your IAM program?
Yes, partially, not yet, or not a current focus. Okay, so if we move on to the next slide. Here are some of the latest trends that we see in the access management space, passwordless, decentralized identities, NHIs, feedback.
Luckily, we have leadership compasses on each of these topics. So if you have a membership on our website, you can check the leadership compasses on our research section. My colleague, Matias, he recently has a good report to take a look at. And I'm aware of the time, so I will have to speed up a little bit, and we will talk about each of these in the next coming slides.
So first, passwordless. Passwordless is still trending, right? But there was a lot of noise, I feel, around this market segment two to three years ago. But I think that now many vendors realize that organizations still struggle to fully transition to passwordless due to different reasons, such as lack of interoperability, maybe budget deficits, and also because many organizations still have legacy systems, and it's really difficult for that full transition in a fast way, let's say. So it's going to be difficult to completely get rid of passwords.
So I expect passwordless to become foundational in the future. It's going to be an expected capability, but I'm afraid that passwords are here to stay for some time. And we also see that passkeys are gaining a lot of attention these days. So in this graph, we see that almost all of the vendors in the report offer passkeys. There was just one or two vendors that didn't support passkeys, but it was on the roadmap to have passkeys by the end of this year. So I expect that they all will do it already.
So we can see that most vendors support passkeys, but from my conversations with them, they say that uptake has been a little bit slow in some industries. But it's important to remember that passkeys are not a monolith. They come in different shapes. So we have device-bound, synced, platform-native, third-party managed, and each of them carry different, let's say, implications for security, usability, and manageability. Device-bound passkeys, they could more, let's say, appropriate for high-assurance scenarios, but maybe they do not scale well across multiple endpoints.
And on the other hand, if we look at synced passkeys, they may offer better convenience, but the security guarantees, I guess, depends on the implementation. And many organizations in highly regulated industries have a lot of questions when it shows that passkeys have different benefits and different challenges depending where the adoption is taking place, if it's in the enterprise or if it's in the consumer space.
I also recently published a report on passkeys, and one of the areas that I talked about was that the current generation of passkeys relies on cryptographic algorithms that are not quantum-resistant. So quantum computers, we know that they're still developing, and every now and then we see some news articles saying that there has been some breakthrough, but Q-Day hasn't happened yet. And quantum computers, by using the Shor algorithm, they could break these encryption algorithms like RSA and ECC. And long-term, this poses a major risk to traditional dedication and public key cryptography.
So I believe that cryptogility is not just a best practice, but it's a strategic necessity because, as I mentioned earlier, things are moving so fast and every day we wake up and there's something new happening in the world. So it's better for organizations to start preparing now for Q-Day than regret it later. If we look at the developments by NIST, they already prepared a transition plan for organizations to follow. So if you check the report that I wrote on passkeys, there's more information on that transition timeline.
So this slide has some elements on governance, but I think it's still relevant to talk about some of these. So we know that agentic AI has been on the news. These are self-learning AI that can make real decisions in real time. They can reduce workload and boost security in identity and access management. These agents can help manage access faster and more accurately.
However, there are some critical challenges, particularly around data privacy, the interoperability of the systems, the transparency, the explainability that the do when they talk to their customers. It's important that customers ask the real questions because I think that many customers are becoming more skeptical of AI marketing claims. They don't really ask for AI for AI's sake, but they're just asking for solutions to their problems. And if AI can help solve some of their problems, then great.
But I think many vendors have this notion that just having AI there is going to make your product more appealing. What it really needs to do is to fully demonstrate the tangible benefits and the real value that these new features can add to your existing product. And I think that this practical approach is shaping how AI is being integrated today in identity security. If you're more interested in this topic, we had a lot of sessions on on agentic AI during our EIC conference in May in Berlin. And I had a session on Immanuel Kant and epistemology in the age of AI.
It was a bit more philosophical, but it explored how there's a fundamental difference between human knowledge and machine knowledge. But there are more topics to cover here today. So let's look at another area that has been trending. And many of the vendors that I had in the report, they are from the United States. And many of them were asking questions about the EU IDAS and the European wallet and all these developments that we see here in Europe.
So reusable verified identities are unique in that once issued, they can be reused between organizations and across borders with a see that that can work very well here in Europe, in the EU, lots of different countries within one union, lots of cross border services, students, workers moving from place to place. But for this to succeed, I think there are some factors. So the breadth of services, the reusable identity allows access to is one element. Also the amount of effort in adding support for a reusable verified identity to a service. We need to make that smooth and easy.
And also the interoperability with existing standards. And that's the tricky part because many of the regulations and standards that we see take a long time to conclude. And by the time they conclude, there's already some new challenge that technology is introducing. But essentially, reusability builds off the concept of a verified identity, which is a digital identity that has been verified to describe a real world identity, but in digital form. So identity verification is a fundamental part of establishing reusability.
We will be having a webinar on our latest identity verification leadership compass on October 1st, where we will be talking more about this. Another area here is the adoption of feedback. And it's increasingly being driven by the need for more dynamic, more granular and context aware access control across different environments. So as organizations start to embrace zero trust architectures, as they start to shift to multi-cloud infrastructures and adopt microservices, the, let's say the limitations of static role-based access models have become quite evident.
My colleague Nitish recently published a leadership compass on this topic just a couple months ago. So there's another reason for you to to check our website and see what's the latest in this area. So here is the last slide because we also have a panel discussion with Jay and we also already have some questions. And I'm really sorry about the interruption. It's the first time it happens, but just to conclude, to leverage and extend your existing access management towards a more future proof. The key is not to just rip and replace, but it's important to integrate, orchestrate and evolve.
So you can begin by mapping all your current access management capabilities and identifying integration points. And I think that this evolution can be achieved through the identity fabric paradigm because an identity fabric paradigm can whip together all of these different existing tools that you already have. So an identity fabrics is not based on a single technology or a single solution, but it's more of a mesh of different capabilities that you already have.
So you can have a more modular AP driven architecture that provides consistency across all channels and all identities that can enable observability and future scalability without having to start from scratch. So in summary, your current access management can become part of a broader adaptive identity layer and that can prepare you for the future. We're talking about AI or decentralized identities or whatever comes next. I think that's a good approach. So here's some related research that we've done, the access management reports, as well as some advisory notes and blog posts.
We will be having our impact day. One of them is taking place tomorrow in Munich and the next one will be in November in Frankfurt. And here's just a list of the different things that we do a grouping a call. So you can always reach out to me, reach out to anyone that you know from the company, and we can try our best to help you. And if you have any questions, please reach out to me. And now I would like to invite Jay. Maybe you can briefly introduce yourself.
Jay, how are you? Fantastic, Alejandro. Thank you so much for the opportunity. It's always good to be talking to the Kupinger folks and the audience of Kupinger.
Alejandro, I'm good, all good here. I'm logging in from Japan today. It's about 11.30 p.m. here. So it's a nice opportunity to talk to you all. It's a brilliant time to exist. I believe crazy things happening, all the things that you follow in news, AI here, there, everywhere. We've been working closely. We've been discussing on how AI is impacting on the identity security layer. That's predominantly the research that we've been working on more recently. So that's where we are right now. I personally handle business for ManageEngine globally, the growth and business for ManageEngine.
I work on the identity access route of management products. So we work very closely with customers across the world. We help implementations. We help the firefighters fight fire. So that's where we are.
Good, good. I know we already have some questions in the chat. I'm really happy that you were able to join us from where you are now.
It's late, but happy to have you on board. We have some questions that I remember last time I spoke to you, maybe a couple months ago, we had a briefing on ITDR, and we had a very exciting conversation. I wanted to ask you, from your perspective, do you think that identity and access management is more of a security enabler, or is more of a business agility enabler? Or is it both? What do you think? Brilliant.
Okay, the straight answer is it's both. Without thinking twice, I think it's both.
I mean, if you go back in history, identity access management has been around for quite some time. All the way, you go back to the Alibaba and the Forty Thieves times, you say open CSAM, there's passwords right there, right? It's been out there for quite some time.
I mean, a few years back, when we were talking to people, it was more about identity and access management being more like a bouncer, figuring out who has to get the entry, if they're the right guy or the wrong guy, and then letting people in. The last five, six years, we've seen that shift, that take more center stage. I would attribute that to how the whole world has evolved.
I think, thanks to things that have changed, like the way how people work now more remotely, and the explosion of identities that we see, how people want accessibility on the go, right? It's as simple as them wanting access to a quick food delivery app. It's just like that. They want to have access to apps in their office environment as well. They're expecting seamless digital experience. So all of that coming into play, we are seeing that the identities on the whole have just exploded.
Now, we keep hearing people saying that security operations team, SOC team, NOC team are also looking into how can I integrate identity elementary right into my data when I take things forward. So like I mentioned, access management and identity as a space is pivoting more to get into identity security, trying to be not just securing or being preventive, but also being able to react to instances. Can I defend against some mishap that's happening? It's not just about safe passwords anymore. It's much more than that. That's the movement that we're looking at.
Also, so to say, when it comes to the business agility standpoint, back in the day, it was just about provisioning an account in one platform. Today, users are provisioned across platforms on-prem, on cloud, 100 applications get provisioned on day different licenses and different applications. So it becomes important that we evolve to do that bit as well. Everybody wants a great first day experience. So business agility is something that identity access is contributing to today. So it's a mix of both and it turns out we are at a point where it's converging.
We see thanks to what's happening in the AI space, it's no longer if you have security, you're going to have a bad experience. It's not like that anymore. And we are seeing business and security go hand in hand thanks to whatever is happening in the domain.
Yes, that's a good answer. I think, as you said, this dual role is no contradictory, but it's complementary. And I think that's why I wanted to ask you this question because it resonates a lot with the conversation we had on ITDR. And I think ITDR is this sort of discipline that is incorporating both the business agility enabler and also the security aspect. We see that now the sub team and the identity people are talking to each other. So it's a very, very interesting and cool development. Very much. And I guess my next question would be around AI.
So during the presentation, I said that many customers and end users, they just want their problems to be solved, that many of them see that a lot of vendors are talking about AI and maybe just because the competition is doing it, everyone else is doing it. But what do you think? Where do you see AI making the biggest impact in access management in the next few years? Right. Big disclaimer, there's a lot of marketing fluff out there. So people got to be very careful. Everybody wants to slap AI in everything that they say.
You talk about a toothbrush, there's AI in a toothbrush, there's AI everywhere. People want that. But more realistically, the way how we are looking at it, we don't want to get carried away with this whole AI hype cycle. We are very mindful about it.
In fact, when we are thinking about AI, we've been doing it for almost about 10 years now. However, we've been thinking about AI. We have this internal joke called ABCD of AI, where we say it's artificial intelligence plus business intelligence plus contextual intelligence helps you have the decision intelligence. So that's the way how we are structuring AI when we think, especially in the identity space, it makes a lot of sense to have business intelligence as well. It makes a lot of sense to have contextual understanding of what's happening as well.
When we look at real implementation of what's happening in AI and identity access management, you start somewhere simple. You start with something that is prescriptive.
You say, hey, these are your policies today. It doesn't look right because there are certain users in your organization who seem to have been over provisioned because the policy is like this. This is an alternate suggestion that we give you for a or so to say, at a user experience level, if you're looking at it, we were talking about how security is no longer an impediment for good user experience.
So my AI can look into who is accessing from where, which area, what Wi-Fi, what IP, what device, what endpoint, all of that telemetry gets taken into account, all of that biometrics gets taken into account. Maybe you can give them a seamless access right there. And as you go a little forward, now the reactive bit is where all the action happens, right? If something goes wrong, can I firefight? Can I respond immediately? Because we're trying to solve a very hard problem right there. Now it's no longer just attackers who are human beings who are just trying to code with a hoodie.
It's also bots helping them initiate attacks. And as we talk to a lot of customers, we do keep hearing that the number of attacks that are happening on a given day, simple attacks. We're not talking about some complex attacks by some external attacker. We're talking about folks inside the organization, they go to chat, GPT, ask for a script and try to do something, do a takeover or whatnot, right? They're just curious. A lot of them are curious. So a lot of this is happening. And when AI comes from the picture from the attacker side, it makes sense for the defenders also to have it.
So we see that customers across the world, they expect something that is realistic, practical, from an intelligence standpoint for access, from intelligence standpoint for something like access certification. Can I be proactive and start an access certification campaign when it's about time? And probably from an intelligence standpoint in automating provisioning and the general mundane management that we see.
So AI comes in multiple forms and capacities, both in the business side of enabling it, being an enabler or a logistics driver, or from a security standpoint where I can look, find out and what happens after that. So the point that you made about ITDR, that's pretty interesting for us because when we look at it, identity is at the center of a lot of other technologies today. It's at the perimeter. It's more like the first line of defense. If it gets compromised, it's a free pass for the attackers. So AI right there in that layer really helps.
Detection and response is something that we are looking at, having playbooks, mainstream attacks, password spray, pass the hash, Kerberos, all of those are available out there. Just first level, AI has to have a playbook to stop, detect and respond immediately. So such a sort of direction is what we see the market taking and people asking us about as well.
Yes, of course, it's hard to know where AI is going to take us in the next few years. It's almost, I guess, impossible to answer that, surprising us every time. And I think that there's some areas where I see AI having an impact would be in analytics, in observability, so being able to see what's going on all across your systems. And one of the audience, members is asking a question around PBAM solutions. How does AI help to manage attributes? Do you have a take on that? Absolutely, absolutely.
So when it comes to attributes, it makes sense for AI to draw a baseline for your existing organization on who what privileges on what level and use that to model and suggest when a new user is getting onboarded. Let's say in a joiner, mover, lever case, it works out really well. At the right time when a privileged user is added to a group, you tell them this is what has to be the privilege or are they over-provisioned or is there a privilege creep.
Similarly, if there's a movement in the normal case as well, somebody is moving between departments, you take off the access. So at an attribute level, who has to have what level of access to attributes, it does really help. From there, you take inspiration and then model your policies as well, role-based access or how you want to do that. How would you look at it, Alejandro? I think you on point what you said, I think it makes a lot of sense.
And yeah, I guess being able to have this context awareness in real time, it really helps formulate the right policies. And it brings me to another question here. I think it's a very good question because it's asking how to sell IAM investment to top management who sees it only as a cost. How to link this investment to business benefits which they understand. If I could maybe start with that question, I'd say that there's like a sort of stereotype that maybe very technical people are not very good at communicating things.
It's a stereotype, it's not always true, but I think that there's some truth in the sense that management perhaps they don't see the need for identity and access management. But if you speak to them in terms of money, in terms of profit, in terms of how the organization can suffer financially or in terms of reputation, if an incident occurs, I think that they will start to pay more attention into that. But what do you think?
True, I think I would start with locking everybody out and get their attention. So it makes sense, whatever you're saying, it makes sense. I think associating a dollar value usually helps get the buy-in. Most of the times when we work with customers, when we are talking to the boards, it is very difficult for them to look at IAM as something that can add straight business value. It's more of a cost center for them. But today when we look at it, we are talking about how we help people log in from a simple place, single place. A lot of people across organizations, they have trouble logging in.
We make the experience seamless. It might look like a simple thing, but the number of password reset calls that the admin gets, it's just mind-blowing. I used to be an IT admin long ago in another life. So if you think about it, the way how identity access management, the way how it's positioned today, it really does help have some intelligence there and make it easy for them to access, give them right away. Self-service is a great example. Users don't need to IAM tools that have self-service. Nobody needs to wait. They can get things done going.
And also, there's connectivity that the businesses are expecting. How am I able to put my work everywhere? Can I access it while I'm remote, while I'm here, while I'm there, on the go? So all of that is a great way to add value. Another way is also to do the fear-mongering. Tell them that, hey, if we don't have this, these are the compliance regulations that we might be violating. These are the huge fines that we might be incurring. The cyber insurance premium is going to go up because we did not have this MFA solution in place. We are prone to an attack if this happens.
So there are both ways of doing it. Show them the good side of that doesn't work. I think always this one works. Show them what's going to happen, what's going to go wrong if you don't do that. Absolutely. My next question is about machine identities and genetic AI. The question is, with the rise of NHIs and agents, how should enterprises rethink their access governance models? What's your take on that? Okay. It's a very controversial take. I personally am a big believer in how people are working and it's just human beings at the center of everything.
The way how we read everywhere, it's some AI agent that is coming and how AI is going to replace people's jobs. We do see spurts of all of that happening every day. It's scary as we proceed.
Two, three years ago, when we were talking to customers, not many of them were really considering today. Everybody wants a piece of pipe probably to convince their management or sound cool. I don't know what. It's not just the IT folks. I'm talking about actual business folks in other lines of business, the HR, the finance, the marketing. Everybody wants to do something. We just did an internal audit in our company to find out how many people have created their own agents. It'd be surprised almost about 80, 85 people have their agents that they've created. Everybody does not have one agent.
It just costs them a $20 subscription of charge to create an agent or any other of these agentic AI tools that let you do that. It's going to be very difficult for us to any longer keep track of who is in the driver's seat to create identities. You're forgetting that these agents come with the ability to make actions in your actual system and your organization can access your data, can manipulate your data, can do whatnot.
We've given everybody a free pass to create their own agents in most organizations when we talk to them because they do have a subscription to these chat ZPTs of the world and whatnot. I think it starts with just taking into account that machine identities that existed long ago, they were all around, have become more popular thanks to their brother AI. Machine identities, you talk about the mainstream API or containers or any other machine identity right there. It needs monitoring because attacks, when we talk to people, it's no longer on identities that are human identities.
They're on these new age identities. We hear about model inversion attack names that I can't remember, like how somebody can take over your AI model that you have in your enterprise and try to make that model work against you, never really know what's happening. So monitoring and having observability over machine identities, I think, is personally very, very critical.
Just like the policies that you apply for human identity management, the principle of least privilege or analyzing user behavior or having principles of governance, I think a parallel version of that has to apply for machine identities as well. Because now when it's an attack by an insider who's gone rogue, you can at least triangulate, do something about it. If it's an AI agent that's gone rogue, even before you can blink, I think enough damage is done. So the best way to counter AI is with another AI is what we feel.
So having AI tools that can observe changes that happen to machine identities is quite critical or identity tools that do observability on AI agents or, for that matter, non-human identities is pretty critical. From a governance standpoint, quickly summing up, it makes sense for us to have every non-human identity associated with a human being. Somebody who is accountable out there, it makes sense is what we feel. That's what we recommend people if you're going out there creating that, it makes sense to tie it back to somebody.
And I think just like how we have access reviews for human identities, access reviews for the APIs that they use or the microservices that DevOps teams build or any other agent somebody builds, that also needs to happen is what I feel. And from another standpoint, being able to think about the credentials that you give away to these machine identities is also quite critical. Rather than mainstream possible rotation or vaulting and giving and doing that, I think a token-based system would make more sense, something that comes with an expiry date, especially when it's AI.
So you think about just enough access, just in time access. So the classic principles of zero trust, my favorite philosophy in identity access management, apply in identity access management, apply in life, my in-laws, zero trust. So I think it works. I think it really works out in your favor if you apply all those concepts of IAM that you already know, time-tested concepts for AI as well. We just need to be able to extrapolate to that is what we feel. So it's a crazy time because we're not able to keep count of how many non-human identities are out there.
So I personally think it starts with very good auditing and observability of what all is there and what all has what access, and a system to revoke if you think something's going out of control. Yes, yes, you brought up really good points. Enforcing least privilege at machine scale, extending identity lifecycle management to include NHIs, monitoring behavior to see and detect anomalies by ideally with ITDR. Another one that I would add would be to adopt this identity fabric concept to, let's say, enable consistent policies and observability.
I think observability across all identities is crucial and many vendors in this space are emphasizing this area. They want to make sure that they can get data from all different tools, from the IEAs, from PAMs, from SOAR, from SEAMs, but at the same time to have a nice way of showing all of these things visually so we can ensure observability.
But yeah, you brought really interesting things there because I've heard different perspectives. Some people say that keeping the human in the loop is not really necessary. Some of them say that, yeah, it's crucial. So it's good to hear from different people. Next question would be, so what practical steps do you think organizations can take to deliver a consistent and secure access experience across different applications and systems? Is there anything that, any questions that you get from your customers around this?
Okay, this is a classic problem when we speak to people. I think we all know, all IT folks who join understand that the weakest link is users. They still write passwords on a piece of paper, sticky note and whatnot. So for us to be able to give them like a seamless access, you take out all the places or instances where they end up doing mistakes. I think it starts with very simple things that we already know. Identity hygiene is a great place to start.
You give them like good MFA settings and then have a tool in place that understands context, that understands user behavior, that does risk scoring and determines whether or not a user requires access. So the one part of it is giving secure access. The other part of it is giving seamless and smooth access. If I am who I am, so I'm Jay, I'm supposed to be logging in from India, but I'm here in Japan in the middle of the night at 12 trying to log in, that's a deviation, I get blocked. But Alejandro is at home probably and logging in at the right time, so you give him seamless access.
So that's the sort of user experience that we should be thinking about, especially when it comes to applications, right? We are not able to keep track of how many applications anybody has. I would suggest, please do not give anybody a login screen ever. If possible, take away all the login screens, but I don't know if that's possible. So the alternate is to have a single sign-on system in place. You have an enterprise SSO solution in place, where you have all of that work done. Everybody has the right amount of access on the right applications.
You also are able to track who is logging in, when, what are they doing, which application are they using. That really works. So adaptive MFA and SSO are like very practical steps. And I also feel since this is like a very dispersed area right now that we are navigating, and users have identities on different identity providers, somebody has identity on-prem on AD or maybe Azure AD or M365 or Slack or Salesforce. And if they are disconnected, that brings a lot of problems to IT teams, especially in terms of policy disbursement, who gets what level of policy on what. It's a big problem.
So personally, I feel it makes sense for us to unify. That's what we recommend. A lot of clients to who we spoke to, they are very glad that they're able to have one central source of truth, like a unified identity platform where it could be anything of your choice, just one place where you're able to plug all of your dispersed identities in one place and give them that seamless experience. It's not just about the end user experience from an access management standpoint. For admins as well, it saves a lot of trouble because there are many use cases that you can fork from there.
You talk about access visualization, how much access who has, where do they have, how is it all interconnected. If you're talking about some account being compromised, you can actually backtrack because all of your system has a single source of truth. Another easy thing to solve for user experience or seamless access would be a self-service portal, really saves the day.
End users able to reset their own passwords, able to enroll for MFA themselves, able to do basic things, maybe subscriptions or access to applications, requests for apps, all of that from a self-service portal, I think it makes sense. From an admin standpoint, I think a centralized policy dashboard is quite essential. It's pretty dispersed. You're talking about cloud identities, on-prem identities, entitlement management on the cloud, DevOps team having provisions to create applications or microservices on the cloud.
If you're able to bring all of that together in one place, a centralized policy engine also would save us. So from both an end-user experience and an admin experience, the overall access management experience, I think these are one or two ways you can make it a little better.
Amazing, I think you covered very well. I think now it's time to look at the poll questions and maybe we can comment on those. I know we just have a few minutes left. Are you able to see them, Jay? I'm trying to find out.
The Q&A, I'm able to see one or two. One of the polls? Okay.
Well, I can tell you maybe the results. So the first poll was, how would you rate... I would like to know that as well at the end, maybe.
Yeah, exactly. The first question is, what are you in your access management journey? And most people answered, 59% answered that they're managing a hybrid environment. 21% are actively implementing one. Only 17% are fully cloud and 3% are just starting to assess solutions.
Okay, okay. Three percent high.
Yes, there you go. Yeah, I think it's... I'm not completely surprised by that. The next question is...
Yeah, we're gonna say something. Okay, so the next question is around managing machine identities within your IAM program. Are you currently doing it? And the answer is 52%. They're partially doing it, but not consistently. 21% answer yes, we dedicated tools and processes.
17%, not yet, but planning to. And 10%, not a current focus. So that's around 27% of people haven't really begun, which is, I guess, why we are hearing a lot about this topic. And let's look at the last poll question. So which of the following trends are you most interested in exploring?
31%, it's tied. Sorry, 33% said they're mostly interested in decentralized identity and verifiable credentials. 30% in AI and machine learning. 18% in IDAS and hybrid IAM architectures. And 18% securing NHIs. Looks like so decentralized identity, verifiable credentials and AI. Pretty interesting. I think we have a smart crowd. They're talking about decentralized identity and many of them are looking at it. Can you tell us if in India, is that like a common topic of conversation these days? I would say not yet. We are definitely talking about it.
So in India, we have something called as the India tech stack. So we are a very massive country, right? I think 1.6 or 1.7 billion people right here in India. We built our own tech stack that powers our payment gateway. It's called UPI. It's built by the government. It democratizes access to banking, basically. Anybody can just scan a QR code and do it. So that's one place where we are actually thinking about decentralized identity. If that really comes to be, that would be one of the largest experiments of decentralized identities in the world.
But we hear a lot of people talking about it, but in terms of actual movement in implementations, we don't see that yet, I think. Here and there in fringes, we keep hearing people have experimented, but in actual implementation, we haven't seen that yet. What's your take on that? I was asking because I think that the case of the EU is an interesting example because it's also covering different countries with different languages, different culture, different expectations, different citizen-government relationship.
So I thought that India would be an interesting case as well because you have so many languages. I thought that maybe there were more developments, maybe that the EU was a sort of interesting framework that could be also followed in other regions of the globe.
But yeah, I'm just curious to know. Yeah, and I think that we are now finalizing this webinar. I really thank you, Jay, for joining me today. And apologies for the interruption and for my throat. I'm still recovering here, but thank you so much for your attention.
And Jay, if you have any final words, I think I just have one final word. Just be nice to AI or your chat GPT, say thank you, say good morning, say hello, say hi. You never know when AI is going to take over. You don't want to be the target, right? So just be kind to it and nice to it, just like anybody else. That's pretty much it, Alejandro. It was really nice talking to you. Love talking to the Coupling World audience. So thank you, guys. Thank you so much.
Thank you, Jay. I appreciate it. And thank you, everyone. Have a great day.
Bye, guys. Bye, Alejandro.
See All Locations
See All Locations