Hello everyone. Welcome to the next session, IAM Survey 2025. My name is Nitish Deshpande, Research Analyst, KuppingerCole Analysts, and in this session we will take a look at some of the findings that we had from the survey which we carried out in the early part of the year. So if you love graphs, if you love numbers, you're going to love this next few minutes.
And yeah, let's start with that. Before we jump towards the findings, I would like to just quickly give an idea about the methodology and the demographics. So we surveyed over 1,000 IAM professionals all over the world, and the majority of them are from the European Union, and they represented organizations ranging from small and medium enterprises to large enterprises. And these respondents included profiles such as IAM consultants, IAM heads, CSO professionals, and cybersecurity advisors, as well as some owners and founders of IAM companies.
And they were all from different parts of industrial sectors like software vendor, CSP, IT consulting, and services, also finance, manufacturing, and public sector. Okay, so first up is the IAM infrastructure, and we asked that how is your IAM infrastructure implemented? And nearly half of the respondents said that they have loosely coupled or uncoupled IAM tools. I'll just take this here. Hello? Can you please turn it on?
Yeah, okay. Sorry for the interruption. Yeah. And 34% of the respondents said that they have an orchestration of multiple solutions, while only 19% have a converged IAM suite. And so what should we do next? And I think some of the recommendation is that organizations should move towards an orchestration, building a fabric through best-of-breed tools and policy layers and APIs. And the next question we asked is how many IAM solutions have you deployed in your organizations? And more than half of the respondents replied they have one to three IAM solutions, so suggesting a bit low maturity.
This could also be from the respondents who are from maybe SME sector. And 31% said they have four to six IAM solutions in place. Now we are going towards more complex deployments. And then the large enterprises replied they have a bit more than seven and more IAM solutions. It gets even more complex than if you go towards that. And as cloud entitlements and identity threads grow, so you need to then integrate CIEM, ITDR for real-time risk assessment and dynamic approach.
And some of the prediction is that over 50% of the enterprises in the next couple of years will manage IAM through an identity fabric. They will move away from the loosely coupled and uncoupled IAM tools. And the vendor ecosystem that supports pluggable standards-based IAM modules will dominate the markets. Now it gets more interesting. Now we go towards the adoption rate of IAM technologies in 2025. And we have these six technologies here.
You have IGA, access management, PAM, and the graph on the right says that 94% of the respondents, and they have an access management solution in place, with IGA coming falling closely at 87%. PAM is also at 80%, but I'm here to I'm hearing some discussions in the last two days that PAM might converge with IGA and NHI, so let's see how it develops.
CIEM, CIAM, and ITDR are at fairly half adoption rate. But I think if you want to transition towards some more modern deployments, then you need to have more AI-driven context-aware governance models.
And ITDR, again, important buzzword. Last year, this was one of the key topics in EIC. Integrating ITDR will definitely help your IAM technology solution. In three years, CIEM will exceed 75% of adoption rate as organizations are moving more towards multi-cloud environments. And in the next couple of years, AI-based identity governance will also become the norm. But now I think it's more interesting is now we will dive more deeper into these implementations. So you're seeing 94%, 87%, but what kind of implementations are these? Are these on-premise, I-dash, what kind of they are?
And then that's what picture we get is IGA and PAM are still predominantly deployed on-premises, with more than 60% of the solution respondents saying they have on-premise deployments. Access management is at 45%. So I think what IGA and PAM kind of shows is that there's a bit of slower adoption towards more cloud-based solutions, I-dash solutions. And I think we will discuss a bit later into why some of these challenges organizations are facing in the next few slides.
The recommendation would be then for these legacy-heavy deployments in highly regulated industries, the companies in those industries should gradually move towards a more hybrid model. And enterprises adopting multi-cloud should invest early in the cloud infrastructure internal management to gain visibility and control. Prediction, again, these are all based on our analysis.
So again, I have to give a disclaimer that I don't take this as legal, financial advice. So I-dash adoption will exceed more than 60% in the next two, three years, especially in IGA. We are looking at that. And vendors offering a more modular API-driven components. Now let's dive quickly, the overview of a couple of the deployments. If we take access management and IGA, for example, in the last, we did analysis for the last three years and the picture for access management is promising. People are moving towards more I-dash, but also at the same time, it's a bit more towards on-premise as well.
So it shows their hybrid deployment models are reducing and people are preferring either a fully I-dash model or a complete on-premise deployment. While with IGA, it's a bit, it looked promising in 2024. The I-dash model increased, deployment increased, but it has again gone down in 2025, maybe suggesting there were some issues in implementing and projects failing. So company organizations went back to on-premise deployments. And so if you want to maintain on-premise access management, recommendation would be it should be backed by strong business justification.
And prediction-wise, enterprises with modern I-dash-driven IAM strikes, we'll see improved agility. And we expect IGA to again come back towards more on the I-dash deployments. We are seeing it from the vendor's perspective, customers as well want more I-dash deployments of IGA. But there's one big issue in moving to IGA, into I-dash, we will take a look in the next slides. The budget, what's happening in the budget. It continues to be one of the main challenges. Considering right now the economic turmoil situation, everything, budget has remained stable for the last couple of years.
But it has really shown like a decrease. So the bottom line, it shows that the organizations which have reduced their IAM budget, which has grown but still not as much you would expect. Major change has been in organizations increasing their budget by more than 20%. It has gone down drastically from 22% last year to 11%. So this could be again due to various market conditions. Recommendation is for organizations with budget challenges to focus on first critical components, critical assets, and addressing the existing challenges.
And I think our prediction is that budget will continue to be an issue for the next few years. But AI and machine learning supported functionalities will attract a bit of spending on the IAM technologies. Now let's talk about some of the challenges. So we have divided that into two challenges. One is the non-technical challenges and then we will take a look at the technical challenges. And stakeholder management continues to be the biggest challenge for IAM projects, stalling or failing.
I think there was a very nice session yesterday in the same room where they were telling about IAM implementation and the recommendation was that involve the stakeholders from the beginning, don't involve them at the later stage. So once you can address that maybe there will be some progress. Requirements gathering, that is again stated as a big second most important factor for project stalling and failing. There seems to be some misalignment with the requirements gathering and the implementation.
So I think the skill shortages organizations got back to us saying that they do not have significant IAM professionals in their organization who can carry out this task. So they have a skill shortage issue and that can be easily managed by developing skills of these employees. So you can address that challenge and the prediction is having a more structured IAM model, having a better IAM strategy could maybe help in addressing these non-technical factors like the trial and approach.
That also turns out to be quite a significant challenge when your organizations go for a trial with one IGA or access fundament solution and then they realize that was not the correct approach. So then the project stalls or fails for quite a long time. And then the next part is about technical factors. So the most significant challenge is excessive customizations and this is mainly driven by the companies who have several customizations on-premise and they want to move to iDesk. But being having so many customizations, vendors can sometimes struggle with addressing these changes.
Next is the role management. So designing and maintaining appropriate roles continues to be complex. It also continues to be the most sought-after feature of several customers who want better role management. And then having a more consistent authorization and application onboarding continues to be another challenge for organizations trying to implement IAM projects. Recommendation is having a much more easier maybe IAM low-code, low-code extensibility so you can produce some customizations and make it easier for IAM projects to progress.
And defining centralized reusable access policies using tools like ABAC, PBAC. Now we have REBAC, TBAC as well to maintain coherence across cloud and on-premise systems. Prediction. Organizations that adopt first IAM solutions will experience 50% upgrade cycles. Same thing is if you can minimize the customizations address the issue, then you can go ahead. Mix of deployment is again a bit of an issue. And I had an interesting conversation yesterday. Mix of deployment remains a challenge based on geographical presence of the company.
North American companies are more open to moving to iDesk while companies in Asia-Pacific tend to be having a bit more on-premise systems and using the IA infrastructure, on-premise infrastructure. Next topic is now authentication. And we asked the respondents that what is their approach for workforce authentication. The trend is promising. Organizations are moving away from the legacy traditional models of username and password and going towards MFA including passwords. But we would expect a bit more investment going into passwordless authentication as the next step.
There's definitely growing interest on passwordless authentications, but it still has not as improved as we would have expected in this current year. But we are only in May, so hopefully in the next seven months this rate improves. I think the recommendation would be investing in these passwordless systems, evolving MFA by adopting contextual and adaptive approaches. And prediction, we will take a look at the prediction in the next slides. We expect passwordless authentication to grow significantly based on the responses that we have received. And that's just the slide, that one.
So we asked which technology will be most adopted in the next three years. And passwordless authentication came as the number one priority for everyone at 22%. I think it's driven by the ability to improve security. Next is decentralized identity, IGA, are also expected to be the most sought-after technologies, IAM technologies, and non-human identity management as well. That's definitely taken off this year, so maybe that number will change. And as organizations scale cloud and automation, managing these non-human identities is going to be crucial moving forward.
Recommendation is exchanging IGA policies to include API keys, implementing more identity-centric CIEM or user behavior analytics, solutions that integrate IAM, that address the identity security issues. Prediction, passwordless authentication will definitely be more sought-after in the next couple of years. ITDR will again be quite important. It will require a module in enterprise IAM platforms and it becomes the primary attack vector. Now this is a comparison. We asked the same question last year, what do you think will be the most sought-after technology in 2024?
So here's a bit of a comparison between a few selected technologies, and password authentication was popular last year and it continues to be popular this year. But there has been some fluctuations down the line, like policy-based access management has gained a big surge. I think it's driven by more requirement for having a more dynamic, contextual approach for all the organizations in authorizations. And then you have ITDR as well that has grown up. CIEM has slightly fallen down, but that is maybe hope to change in the next couple of years.
Recommendation for MFA, password authentication, is having a more phishing-resistant MFA. PBAM can be challenging, so the recommendation is starting with a multi-speed approach and have some pilot programs. Password authentication should become a default expectation in the next three years, and policy-based access management also become a core pillar in the IAM technology space.
Now, the fun words, AI machine learning. We asked which current IAM functionality is leveraging AI and machine learning, and risk-based authentication is the most commonly deployed AI-supported IAM function. It clearly shows maybe we want some more context-aware, dynamic authentication model. But 13% said they have no AI or ML-supported functionality, which shows there's a big gap which can be taken advantage of, and AI and machine learning has still not penetrated that much. Then you also have privileged identity security posture.
AI-based ITDR is also gaining traction, access and role analytics. So this is showing growth, but there's no dominant trend in between these below four or five functionalities. Recommendation is AI-based ITDR, we expect to be growing quite significantly to identify outliers, anomalies, and behavior. Expanding risk-based authentication as well. Prediction AI is the talk of the town. It will enable everywhere. There are several use cases which justify that, and IAM workflows like access requests, certifications, user provisioning will also increasingly start incorporating agentic AIs.
We also ask that what do you expect in the next years to have the biggest impact from AI and ML? Privileged identity security posture comes at the top, at 12%, where it shows the requirement for monitoring and evaluating high accounts risks. Risk-based authentication and access and role analytics have also been predicted to gain a lot of traction, but I think we are just over one minute left, so I'll go through my slides quickly.
Recommendation is integrating behavioral data, applying AI to monitor privileged behavior, identify dominant accounts, toxic combinations, unused accounts, and detecting privileged escalation. And as data quality improves in the next few years, then AI-governed and schema features and AI-supported functionalities also gain traction in the next few years.
Finally, I would like to summarize it with some of the findings from this survey is cloud-first IAM is now a reality. Like we saw in access management, the shift is happening towards iDust implementations. Budget continues to be the main biggest challenge as well for organizations, and it will continue to be a challenge in the next few years, so you'll have to identify and have a very good IAM strategy to navigate around this challenge. AI and ML-driven capabilities are emerging.
They will gain even more traction in the next few years, especially AI-based ITDR, risk-based authentication, behavioral analytics, and password authentication is expected to be the most, I think highest, expected to have a highest adoption next three years. And challenges, we just saw there were two types of challenges, technical and non-technical challenges. So technical includes customizations, role management, while non-technical includes stakeholder management and other organizational efficiency issues.
And I think we are right on time, so I will just take it from here, and I think thank you so much. If you have any questions, you can connect with me on LinkedIn, and I would like to now invite the next speaker. It's Mark. Thank you so much.