Hello everyone, my name is Nitish Deshpande. I'm a Research Analyst at KuppingerCole Analysts.
Hello, my name is Alejandro Leal. I'm also here at KuppingerCole and happy to be here.
Today, thank you for joining us for this session. It's Leveraging Gen AI for Modernizing IAM. In today's session, we will look at some of the use cases of AI in IAM and we will also assess some of these use cases. But before we begin, here's the agenda for today's session.
First, we will quickly have a brief introduction about Gen AI, some of the characteristics of a successful AI ML in use cases. Then we will assess the use cases and finally we will conclude with a statement. Before we begin, I would like to quickly go back to the evolution of IAM and the trends that are driving modernization in IAM. Traditionally, IAM has been focused on static principles, role-based access models, where access is defined based on predefined roles. While it's effective, it can get complex if there is over-provisioning, entitlement creep, and if the organizations are scaling.
Then we have the processes of provisioning, deprovisioning, access certifications, which were largely to an extent done manually. And this can not only increase the risk of error because of human intervention, but it also creates an administrative overhead for managing all these actions manually. And finally is the limited scalability. Traditional models were not, I think, supporting more scalability as they are mainly working on the static principles. So some of the trends which are driving modernization are remote work and digital-first enterprises.
During the traditional IAM models, we had a very simple structure of one office, one internet connection, all the devices connected to the same office. But now with remote work, we have much more complex and hybrid environments, and securing that is where some traditional IAM has limitations. Then is the zero-trust architecture. The concept of always verify, never trust does not work with the traditional IAM model.
You need continuous verification, and finally the need for automation, intelligence, and making decisions based on contextual real-time signals is one of the trends which is driving modernization in IAM. And Gen-AI has been a vision for many decades. It's no more a tool for just content creation, but it's also now a tool that can support in various tasks like powering the chatbots and virtual assistants. These are conversational interfaces which can do simple IAM tasks like access requests, password reset, or just user provisioning and onboarding.
And finally, next is enabling, adapting policies and access controls dynamically. Gen-AI has access to tons of data, contextual data. It can adapt policies dynamically based on the changing landscape. It also helps in interpreting complexity of complex data sets, and another aspect is enhancing identity verification. It supports in various security measures like detecting deep fakes, identifying user behavior anomalies. And finally, it continuously just overall architects trust with continuously adapting and realigning itself with the changing landscape and ensuring the security of the system.
Now we will go a bit more deeper into the specific use cases of AI in the next few slides, but here is a bit of a highlight of that. What can AI enable organizations with? First is making accelerated decisions with contextual awareness.
AI, again, has access to tons of data. It can help in making the simple, repetitive task and provide insights on that. Next is enabling intelligent policy creation and risk assessment. It can identify, leverage the data, and adapt the policies based on the changing environment. Then you have, again, enhancing the user experience through conversational interfaces like the chatbots, virtual assistants, and one of the main challenges is correlating identity data across siloed systems and across hybrid environments.
So AI can streamline that data and provide map entitlements across these kinds of hybrid systems. And from a security point of view, it can detect unused access, excessive permissions, toxic combinations, also detect orphaned accounts, and take measures in real time to ensure security. So what is different? When does AI really work? There are three phases. First is having a codified experience. We can call it a training where you train the AI model on the data for the task which it is supposed to perform.
And what you can do is getting the AI model continuously exposed to this kind of data so it can adapt and learn and perform the repetitive tasks. Next is, it's not just about performing tasks, but it's about performing the narrow, specified task, and that's where narrow AI and machine learning comes in place, which can define the correct task and provide the solution.
Finally, it's about providing the desired effects, the business value, for your organization. If you're implementing AI and automation, it should result in cost savings and allow higher customization in the process. Here are some of the few characteristics of a successful AI and machine learning use case.
First is, you need to have access to historical data. Learning from historical data, it can identify patterns and make decisions. Next is a constant flow of real-time data. So not just having access to historical data, but it also needs access to the real-time data to perform tasks in the present world. And finally, the repetitive task needs to be completed. But we have spoken a lot about data until now, historical data, real-time data, but what you really need is trustworthy data, and lots of it, which is the foundation.
In the case of roles and entitlements, data is often limited to a single organization. A normal access behavior for one organization could be completely different for another organization. So AI and machine learning is kind of limited in that sense, so it can only make decisions based on the data that is provided. Then low quality and insufficient data is basically useless, it's a no-go. It's kind of like policy-based access control, so policies are only going to perform as expected if the data on which they are based is the correct data.
And finally, it's about continuously training the machine learning model, AI model, and keeping it up to date with the behavioral patterns. And for this, you need to ask the question to yourself, do you have this data for your favorite use case? And talking about use case, now Alejandro will take over.
Thank you, Nitish. I'm aware that some of these use cases, some of you guys probably are familiar with them. I'm sure that the audience is very smart, so you probably know these use cases. But I think we just want to show you the scope of the use cases that can happen if we leverage Gen-AI in IAM and IGA. So if you look at the first use cases, I think if we take a step back, if we look at the title of this session, it's how to modernize your IAM.
And I think it's important to mention that each organization has different context, different needs, so it's important to look at that before completely, let's say, modernizing your systems. You have to really be sure that whatever you're going to do is really going to be providing value to your business. So if we look at identity analytics, let's say a global insurance company, they can use machine learning to determine whether a user logged into the system from, let's say, Germany, and then 20 minutes later, again, from another country.
Then that will be a sign that something is wrong, so that could really potentially help address this challenge. The same thing with adaptive access. Let's say there's an online banking platform, and the user is usually logging in with their phone, so the experience should be seamless, everything is fine. But if all of a sudden the user is accessing that from another device, then that will trigger there's something wrong there. And then we see the use of risk-based authentication.
So we can look at how, let's say, a SaaS provider can use Risk Engine to look at different areas such as the geolocation, the device health, the time of access, and then based on that, it can determine whether the user can authenticate or not. So here if we look at, for example, password management, we've been talking for passwordless over the past few years here at EIC, and we know that some organizations are still relying on passwords. Some vendors are still using password managers because they know that the trend to completely remove passwords is going to take some time.
So if you want to modernize your password management system, and you haven't really incorporated any passwordless option or FIDO2, you can leverage this to determine whether some employee in your organization has been using a password that, let's say, appears in a having pond, so you can have an integration with that to reassess that and flag that. The same thing with identity verification. So we can see that if a user is taking a selfie, then the system will look at national ID database to confirm that this is, in fact, a real person. And the same thing with predictive identity.
If we look at these other use cases, Nitish already mentioned about entitlements, and in the previous session we talked about it. So let's say that you're a global company, you have thousands of employees, then the system can analyze hundreds of thousands of employees, of entitlements, and then determine if one of the employees may have more access than it needs, or it's been, let's say, not using a system for a few months. Then that could be a potential way to deal with that. Same with access certifications.
So especially in highly regulated industries, let's say that you are a healthcare company and you're going to have some HIPAA certification reviews, then you can look at who is accessing what, who is doing what, and if there's anyone that should have their access revoked based on that organization's needs. So if we look at the use cases for GenAI, I'm sure all of us have seen that many websites have these chatbots, and you can always talk to them for customer support, but in many cases, at least from my experience, I always have to talk to someone, like a human.
So sometimes I see that some companies, they just want to have this chatbot because everyone else does, but is it really providing value? How about the data that it's trained on? That's some of the questions that I have. Nitish already talked about intelligent onboarding and how it can relate with IGA and how it can improve the process. And the same thing with detection and response. I've been doing some research on SOAR.
So what I see is that many of the SOAR vendors have incorporated GenAI features to summarize cases or events, as well as to help, let's say, a young stock analyst that may not have lots of experience in the platform, and that person can leverage and use GenAI to address specific challenges or requests. But again, as we've been saying, it's important to really look at the business, what you need, and what's going to be the value of having these things in place. So can machine learning cure inherited problems of static authorization?
Well, it's important to not only focus on the symptoms, but to eliminate the root cause. So AI and machine learning has limited ability to tackle static authorization model challenges, but if you focus on reducing entitlements and implementing policy-based access, then that can really help you be more effective and have more security. I'm aware of the time, so I'm going to go really fast with the remaining slides so we can have some time for questions.
So again, yeah, it's important to have a balance between what the business needs, what the data that you have, and the emerging technologies, not only today, but as we move forward, because we know things are happening very fast, so it's important to have that in mind. So there are many areas where if you leverage these features, it can help you in terms of compliance, in terms of security, user experience, risk mitigation.
But again, it always kind of depends on what's your main need and what you really need to modernize, rather than just implementing these technologies just because everyone else is doing it, right? And if we look at the use cases, I mean, we can see that some of them are using AI, some a little bit more than the other, but what should be the takeaway here is the value, right? The functionality and how that's going to really change the way that you do your operations. Just maybe Nitish will conclude with this. I think I agree with all the use cases which you just mentioned.
We carried out a survey last year and this year as well, and the results completely validated the use case which he has said. We'll present the findings of that survey later in the afternoon. The session is called IAMs in 2025. But to summarize it, the final thought is you need to look inside the box and your auditors and resources will ask you this set of questions. How was the risk calculated? What authentication methods were used? And so trusting machine learning is only possible if there is enough transparency, and you need to then control this big black box.
So I think we are just right on time. Thank you. We have a few seconds left, so maybe just a short question. Anything online? Okay.
Thanks, guys. Thank you. Thank you.