This webinar presents a first look at the findings of KuppingerCole's Leadership Compass on B2B Identity and Access Management, a rigorous, vendor-neutral evaluation of platforms built to manage authenticated and authorized interactions across organizational boundaries.
Attendees will get a preview of the Leader chart along with analyst commentary on methodology, market structure, and the capabilities that define high performers. Whether you are building a B2B IAM strategy, evaluating solutions, or benchmarking your own platform, this session delivers structured insight grounded in primary research.
John Tolbert, Director of Research and Lead Analyst at KuppingerCole, has enterprise practitioner experience and deep analyst expertise to this topic. Before joining KuppingerCole, John worked as a security specialist at Fortune 500 companies and tech startups — giving him firsthand exposure to the operational realities that B2B IAM solutions must address. He will walk through the Leader chart, explain the evaluation methodology, and share candid observations on what the market is getting right and where gaps remain. Participants will leave with a sharper analytical lens for evaluating solutions in this space.
Who Should Attend
This webinar is ideal for enterprise architects and identity professionals who are evaluating or modernizing B2B IAM environments, as well as CISOs and IT leaders responsible for managing partner, supplier, or third‑party identities. It will also be valuable for product and strategy teams at IAM vendors looking for an analyst perspective on market positioning, and for procurement professionals involved in IAM platform selection decisions.
Welcome, everyone. Good morning, good afternoon, wherever you are in the world. I'm John Tolbert, Principal Analyst and Director of Cybersecurity Research here at KuppingerCole, and today I wanted to talk about the results from Leadership Compass I recently published on B2B IAM. So a little bit of logistics info before we begin. Everybody's muted centrally, so there's no need to try to mute or unmute yourself. I have a couple of poll questions in the middle. I'd like to have everybody give their answers to that, and then we will take a look at the results at the end.
You have an opportunity to ask questions. There's a question tab in the Livestorm interface. Feel free to drop questions in as we go along, and I'll take those at the end. And then lastly, we're recording this. So both the recording and the slides will be available in a few days. So I'm going to start off talking about B2B IAM, some of the threats, the definitions that we need to agree upon, an overview of B2B IAM solutions, and some of the trends that we're seeing. Then I'll talk about the Leadership Compass research process and show you the results.
So first up, why are we talking about B2B IAM anyway? Well, I think this is a pretty good illustration of the problem. In the last year, over 320 companies have hired North Korean workers, probably unknowingly, So let's drill down on that a little bit. The threat is already inside, and you've probably heard various news stories about this over the last year or two.
CrowdStrike reports that 320 companies have been infiltrated, and that's more than a 200% increase in the number of people that have been infiltrated, and that's a pretty big increase in the number of people that have been infiltrated. CrowdStrike reports that 320 companies have been infiltrated, and that's more than a 200% increase over the previous year. They have generated at least $88 million in revenue for a sanction regime, and that's where this can get companies into trouble.
Another report shows that up to 8400 remote workers from North Korea are coming in ostensibly from up to 40 different countries around the world. How are they doing this?
Well, they're creating identities, they're using gen AI powered tools, they're using deep fakes during identity verification processes and video interviews using virtual cameras. They work with individuals inside target countries like the US and other Western countries. They send them laptops. Some of the people who have been caught in these illegal activities have laptop farms, you know, maybe 20 or more laptops in their houses or apartments. The remote workers VPN into them, and then it looks like they're coming from inside a legal country, but they're not.
So a little bit about IAM, workforce IAM versus CIM versus B2B IAM. And you know, we've been covering identity management at Cooper & Cole for 20 plus years now.
We have, you know, much coverage on workforce IAM, access management, IGA, things like that. I've been covering CIM as a separate discipline for 10 years now. But really noticing what customers and vendors are doing, the B2B IAM market has emerged as its own segment now. And where we see similarities and differences are in areas like, where do the accounts come from? On the workforce side, the systems of record are often HR systems. HR has processes for vetting individuals before allowing them to become employees and getting access.
On the consumer side, and I did define consumer IAM as CIM the last time around in that report in January, to differentiate it between B2B customer IAM and consumer IAM. So for consumer IAM, the accounts are coming from self-registration processes, oftentimes social logins, and a lot of what you have to do in order to protect those accounts is guided by privacy regulations from different places in the world. So B2B IAM sort of sits in the middle and has a few characteristics of each. Both workforce and B2B IAM need access to shared resources.
But on the other side, you know, both need customer portals and self-service features between B2B and CIM. B2B, in many cases, if you have a good federation hub, you're relying on your business partners or contractors to do the authentication and then SSO into your prime work environments to get access to those shared resources. But there are also other ways to do that. So you can see there's a lot of nuance and a lot of opportunities for both overlap and differences in how B2B IAM systems get implemented. So there are a variety of identity types that we might encounter in B2B IAM solutions.
First up, I thought we would look at identity types. First up, I thought we would look at customer organizations. These are external companies that might be purchasing goods or services in, you know, sort of a large extended supply chain. And then you have a variety of identity types. So there are a variety of identity types that we might encounter in B2B IAM solutions.
First up, I thought we would look at customer organizations. These are external companies that might be purchasing goods or services in, you know, sort of a large extended supply chain. And they may be there for fixed-term, you know, long-term contracts or they might be just working with you on particular projects. But either way, think of it as a business-to-business, you know, going in and purchasing widgets to help build your larger widget sort of organization.
And for situations like this, as we'll drill down into in more detail, this will require federation and a host of other actual technical capabilities. But there are also contractors and freelancers, and these can take many different forms. You may have vendors or system integrators. I often like to think about critical infrastructure or operational technology environments. In this case, where maybe you're running a power plant or, you know, some type of large factory, and you're using very specialized equipment in those environments.
And in many of those cases, the vendors of those equipment might need direct access. Maybe they're the ones that do firmware updates, or maybe they have systems integrators that are responsible for doing firmware updates and maintenance. So those people need to be able to get the appropriate level of access to resources inside those kinds of organizations. You might also have resellers or service provider agents. And here I'm thinking of maybe insurance companies. Brokers need to be able to get access to resources inside the insurance company to make quotes, help facilitate claims.
But again, they're not directly working for the insurance company, but need a federated relationship for that. Another case might be drivers. Think about logistics organizations where you're transporting goods from one place to another. Drivers need to get access to a portal so they can see where they pick something up or they drop it off at. It's likely app based, so their access rights are going to be constrained to a much narrower set of resources and probably strictly time limited as well. The last case here are supply chain partners.
And this I like to think of as really advanced companies that maybe the prime has hundreds or even thousands of supply chain partners. Maybe they're doing things like basic R&D, the prime that is, and then they depend on their suppliers to come in, look at those specifications, further develop them. So you need a shared collaboration space for advanced product development. But some of these partners might also be your competitors in other situations. So you absolutely have to very strictly control what resources they get access to.
And these might be for the duration of a large program or it could simply be a shorter duration project. But you can see already there's going to be need for pretty detailed subject resource attribute authorization. So the top use cases that we see in B2B IM.
Well, first of all, there's onboarding. How do you get not only individuals, but organizations into your ecosystem? When you have to consider things like sanction screening, because this is a large and complex and ever changing environment in and of itself. And that applies both at the individual and the organization level. But once you, let's say, decide to onboard an organization, you may still need to do background checks on the individuals that the organization is proposing for access.
So you also need to do originating domain verification, figure out if this is a legitimate business because there are lots of businesses that are not legitimate. So for that we have know your business processes. Often that involves using legal entity identifier lookups. Like through the GLEIF or other authoritative sources of information there. And then also you may have need of multi-step approval processes whereby you delegate, and I'll get more into delegation in a minute, but delegate some aspects of administration to your supply chain partners.
But then before they, their individuals get access, you may want a manager inside your own organization to actually sign off on that. So delegated administration and multi-step approvals are both very important use cases for B2B IM. A little example on fine-grained access control. I just thought I would sort of list out here some attributes that we have seen for those highly complex, let's say, government type or defense types of use cases where you need to know the affiliated organization of an individual. You also need to know what their relationship is to that organization.
In this case, this example I'm showing employee. In order to get access to a specific project or program documentation, there probably needs to be a specific work agreement ID that it can reference. Then there's also the notion of groups and roles that we've been familiar with for many years and workforce IM systems, they still apply here.
You know, at the top level, you may have to worry about clearance and classification. And I may dive into this a bit more later too, but some organizations have training requirements or certification requirements for being able to get access to specific kinds of data too. So you may want to know, has a given individual completed their mandatory training? And are they certified to work on this product? And then lastly, I'm showing, you know, is this a person who has administrative access?
So these are just some of the examples that you might see for fine-grained access control in B2B IM situations. So top use cases, federation, governance, and due diligence. I think it almost goes without saying that in most cases, you're going to need to be a SAM or OIDC hub. So top use cases, federation, governance, and due diligence. I think it almost goes without saying that in most cases, you're going to need to be a SAM or OIDC hub. And it needs to be easy to set up those federated relationships.
But just because you have attribute information from multiple sources doesn't mean that it always lines up easily. That's where things like claims normalization comes into play. Claims normalization might be taking an attribute that one company calls, the classic example is a fire truck as a resource, and others call it a fire engine. So you need a way to map those claims so that you can then write conditional access policies based on that. You probably want to compromise credential checks, especially in cases where you are hosting in your own identity repository the identities of freelancers.
So being able to do compromised credential checks in real time as people log in can help reduce the risk of account takeover and subsequent data breaches. There's also a need for periodic access recertification.
And, you know, in the workforce world, this has always been the case where like a manager gets a spreadsheet or maybe they've got a better system in place for IGA. But how does this work in an extended B2B scenario?
Well, a manager inside the prime may not be the best person suited for knowing exactly who in the supplier should still have access. So you need a way to do delegated access recertification. And lastly, audit. Audit evidence for regulators and the ability to produce compliance reports depending on which industry and which jurisdictions you're operating in. So looking at the technical requirements, you'll see how all these kind of fold together. If you are hosting identities in your own identity repositories, then you need ways to import them by bulk or maybe synchronize them.
That's where LDAP and SCIM support can be helpful. Many organizations rely on just-in-time provisioning today. That's where you might take a SAML assertion, for example, and use the data within the assertion to build an account and place that account maybe in a different branch of your LDAP directory where you can apply different kinds of rules and policies. You may want to have policies that require identity verification upon first usage. You might want to put account restrictions into place that say, you know, it's time limited. This account will be valid for a week or a month or six months.
Or it should be limited to certain times of the day or even certain geographic areas. So there's lots of different account type restrictions that could and should be put into place, depending on your business use cases. You can also use it as a way to enforce multi-factor authentication policies and other kinds of access controls based on subject and resource attributes. So authentication and federation. In many cases, you know, you might be relying on the B2B partner to provide passwordless or MFA. Passwordless is definitely desirable in terms of both the user experience and security.
It can help reduce the occurrences of phishing and account takeover. Risk adaptive step-off authentication is sort of an ongoing, you know, as risk levels change, being able to require a different form factor for authentication or maybe even go so far as to require some limited IDV to get access to really, really sensitive sources, resources. Many vendors provide SDKs that can collect information about device intelligence and behavioral biometrics. Device intelligence in this case might be, you know, IP address, what type of device it is, what operating system it is.
Maybe do device posture checks, you know, looking to see if it's patched appropriately, if it's running anti-malware, if there are any signs of malware infection. Just so you have an accurate picture of the risk that that particular device has if you grant it access. Behavioral biometrics is the use of metrics around how people interact with their devices. So on a computer, it could be keystroke analysis, mouse analysis. On a mobile or tablet, it could be touchscreen pressure or accelerometer or gyroscopic information.
All of that can be used to build a baseline of what a normal user looks like on that device. Really thorough implementations of behavioral biometrics actually allow you to distinguish between different users on the same device. Authorization. Authorization has always been probably the hardest part in the IA world. We are familiar with RBAC. It's been around since the 80s. We're still using it in many places. But often we find that it doesn't have the granularity needed. And we've seen role explosions where you've had more roles than actual people inside an organization.
So it doesn't always work out as well as it should. Fortunately, we have ABAC and or PBAC, which we have based access control, policy-based access control. This allows the level of granularity necessary to do fine-grained authorization inside these complex environments. RBAC is another related term. It's about relationships. I think it's suited for complex delegated administration requirements. And delegated administration, of course, is an important requirement here as well. I hinted at the subject and resource attribute evaluation and showed some examples of that.
I think you can see that those types of attributes are necessary, especially in complex or highly sensitive environments. But, you know, we also need an intuitive policy authoring interface. And we'll do a little bit more about that in a minute. Trust screening and compliance. I mentioned sanctions and watchlist screening, being able to do know your business processes and HR and background check connectors. Most of the vendors in the field don't have this built in.
So if you're looking for these kinds of features, then you need to look for vendors that support the appropriate standards or have nice out-of-the-box connectors for these kinds of services. Account lifecycle management. Duplicate account or orphan account detection. Both of these are pretty important, especially think of a case like where you're hiring a bunch of freelancers, maybe for the short term. Maybe they work for your organization for a month or two, and then you may not see them for a while, and then they come back.
Rather than having them re-register, there's occasionally good vendor solutions that allow you to detect duplicates and merge them or reactivate them. But, yeah, if you're an organization that employs thousands or millions of freelancers, then knowing when orphan accounts are out there and getting rid of them can pretty significantly reduce your attack circles. You also need secure account recovery procedures.
Of course, this does not mean knowledge-based authentication or security questions. Nobody should use that. But here you can do account linking or, in some cases, even blend identity verification into the secure account recovery process. So there are some solutions that support that today. Contract-driven expiration.
Again, if you're in an organization and you have a contract with a supplier that lasts for six months, at the end of six months, you need to make sure that they get off-boarded appropriately, including deregistering devices. Delegated access recertification. I kind of mentioned that already. Organizations that you are doing business with are probably in a better position to know who, on their side, should have access or should have their access revoked. Lastly here, talk for a minute about the operator user experience.
For many years, we've had rather complex policy authoring mechanisms that require long lists of dropdowns for account types and attribute types. Then you use various logical operators, and you can sort of concatenate lots and lots of conditions that can be very difficult to understand what the net result of that is going to be.
But in the last few years, it's been nice to see a lot of the vendors here start moving toward no-code, low-code flow builders that might use a flowchart style where you can drag and drop elements, put them in order, and have policy and rule testing mechanisms so you can simulate the results of what would happen if you made a change to a policy. I think that can be far more intuitive than long lists of attributes and name value pairs that you have to construct with logical operators, and then figure out in which order each one of those rules needs to fire.
So I would definitely say look for an interface that supports that, especially if you want to be able to push the authorization policy development and maintenance down to the business and the delegated administrators who might not have a deep understanding of authorization policy creation and maintenance techniques. Multi-step workflows, I've mentioned that already. I think that's going to be increasingly important. If you're a big organization and you've got lots of suppliers, let's say you'll want per-tenant activity dashboards.
If you've got 100 different organizations that you're working with, you have a good reason to see what's going on with particular organizations there. You need to be able to stream this out to your SEM solutions, and from there likely into SOAR, and then maybe have some bidirectional connectivity from SOAR back to your B2B IM solutions so that if there is any nefarious activity detected, it can shut it down. Audits are always important.
One innovative thing here, we're starting to see a little bit of generative AI usage for policy authoring and also sometimes natural language interfaces for getting more information out of the audit logs. I've been mentioning third-party integrations already.
CIM, HR background check, the different screening services, IGA and ITDR. Some of the B2B IM solutions have light versions of those in already, but you may want to integrate that with your full IGA or ITDR solution.
Lastly, it would be great if you could automatically provision users from your B2B IM solution into your enterprise line of business apps. That might include ERP or PLM systems, depending on what kind of business you're running. Some of the key findings. Orchestration is really key. I've talked about lots of different potential integrations, and you need a way to make that flow very easily and get all the steps in so that you're meeting all of your legal and security policy requirements.
MFA, you might be depending on partners, or you might have to provide that yourself if you've got a very large pool of freelancers that reside in your own identity repository. RBAC is not quite good enough.
ABAC, PBAC or REBAC is really what we need here. Even though I've talked a bit about Know Your Business and LEI lookups, I didn't find that that's very well supported in the market yet. There are some solutions that have out-of-the-box integrations with a few providers. Most of them will allow you to do that, but it's going to require some coding and use of their APIs. Not all the vendors do IDV and sanction screening.
Again, that's an area where they're probably going to have to integrate third-party service providers. On the lifecycle side, orphan account detection is not present in all the solutions that are out there, whereas delegated administration in one form or another is present in most. But not all of them support these complex hierarchies where you could do delegation to a single responsible member in another organization and then allow them to delegate to other, let's say, workgroup managers.
If you have a complex environment where very granular delegation administration is necessary, you're going to have to dive into the details on what exactly can you do in terms of delegated administration, and then also look at what controls can be put in place to prevent further inappropriate delegation. Device posture management and geofencing capabilities are not quite there. I thought they would be pretty common, but they are not. The account restrictions that I talked about in relation to just-in-time account creation.
Many of these solutions will allow you to do that, but it's going to take a bit of work to get that right. And I guess that's not surprising because the particular environments and attributes that you're going to want to create policies on will probably vary considerably. But a few of the solutions that I looked at, two or three, have some pretty robust abilities to define both subject and resource attributes so that you can make policies that go down to the level that you need.
And then lastly here, ML-driven threat detection is present in many of the solutions, but only a few have these Gen-AI features yet. And that's probably not surprising. It's still developing. So now a couple of questions for you. Which best describes your organization's current approach to B2B IAM? We use our workforce IAM for partners and contractors or we use a CIM platform that's not really built for complex B2B use cases. We do have a dedicated B2B IAM solution in place.
Or lastly, we're still figuring out how to handle it. So feel free to take a moment and choose the answer that best describes your situation. And the next one is, which B2B IAM capability gap concerns you the most? The first one is, well, we can't really verify who our contractors and partners really are. Maybe you don't have identity verification or know your business capabilities in place yet. Number two, we don't have any visibility into what external users are doing once they get inside. Or number three, off-boarding.
We don't have any reliable way of deprovisioning them when contracts end or when they just disappear, for example. Or number four, access control is too coarse. Partners can see way more than they need to. So feel free to answer those and we'll look at the results at the end.
So now, a little bit about the process and then I'll show you the results. So we will identify all the vendors that we think are in a given functional area. We will invite them to participate. We create a long questionnaire, sometimes 1,000 questions. So it's kind of like running an RFP. We get briefings and demos from them. We analyze that information. We write up a draft. We run it through a fact-check process. And when that is complete, we publish it. Here are our nine standard categories that we always rate companies on, regardless of what the subject is.
I won't read through them all, but you can see that many of them are tied to how the product works. Then there's also innovation. And there are three over here that are related to market position. So the results.
Well, first of all, here are the vendors that participated this time. And this is the first time I've done a B2B IAM report. I think it's the first time anybody has done a report that's dedicated to B2B IAM. So I'm really pleased that we had these 23 vendors that joined us for this report.
And yes, we will be updating it probably in about another 15 to 18 months. This is what the overall leader chart looks like. Overall leader is a combination of product, market, and innovation leadership. And the spread is kind of what I would have expected, kind of going from upper right to mid to lower left. The market position is indicated by the size of the bubbles. So you see a lot of strong vendors. The vendors you see over in the overall leaders area are both strong in traditional workforce access management, IGA, and CIM.
There's only really one who specializes in B2B IAM, but most of these companies are quite strong in all the other areas of workforce IAM and CIM. I'll show you one sample SPIRE chart. We do a SPIRE chart for every one of the vendors that we write. So you can see our standard categories, security, deployment, interop, and usability, along with these special B2B IAM categories that I've called. So let's go take a look at the poll results. And just a reminder, feel free to ask questions if you have any. So the first question, which B2B IAM capability gap concerns you the most?
It's kind of evenly split. We can't verify who our contractors or partners are. Offboarding, no reliable deep provisioning, but then also just around 20% each, no visibility into what external users are doing, and access control is too coarse. So that's a pretty good spread. I think that, in my mind, indicates that all of us are experiencing each one of these to one degree or another. So next question, which best describes your organization's approach to B2B IAM?
Well, nearly a third say we have a dedicated B2B IAM solution in place already. Excellent. That's great. And then about a quarter each say we extend workforce and we are still trying to figure out how to handle B2B IAM. And about 16% say we're using a CIAM platform for complex B2B IAM. So thank you for participating. Let's see. We'll take questions. Do you recommend a dedicated IDP hub for B2B partners, which then federates with the workforce IDP? Let's see. We'll take questions. Do you recommend a dedicated IDP hub for B2B partners, which then federates with the workforce IDP?
I would say, yeah, I definitely would recommend a dedicated IDP for B2B partners. Whether or not you want to federate with your own IDP probably depends on the specifics of your organization. Do you have a need to federate directly with your own IDP?
Of course, it probably makes it easier for setting up access control policies, but there may be situations in which you want to directly assign entitlements to the users that are coming in from the remote federated IDP rather than granting them similar privileges within your own. So I think it would really depend on your own particulars of your environment and if you're comfortable with that. Let's see.
Next one, non-human and agentic identities are reshaping B2B IAM. How well is the market handling this overall and what should buyers be asking vendors?
Well, yeah, that's not surprising. We were just at EIC last month and there was an awful lot of discussion about both non-human identities and agentic AI. I think we're still in the discovery phase, trying to figure out what this all means. We have done other reports on NHI management. I guess I would refer you to that for the NHI question itself for agentic AI identity. I think there's still a lot of work that's ongoing there. I think we're in the beginning stages. In many ways, I think we're depending on the agents to properly identify themselves and I'm not convinced that they're doing that.
The vendors here in B2B IAM, a few of them indicate that they're doing some leading edge work on this and I think that's great. I think there's a lot more work that needs to be done. I think there are standards that need to be completed around agent intent, agent communication protocols. But I think there's a long way to go. B2B IAM vendors are not quite there yet in terms of maturity, but that's probably to be expected because a lot of this is still in a state of flux at the moment. One last question here.
Delegated admin and organization level lifecycle have always been the hard problems in B2B. How mature is the market on these today and where are buyers still having to fill gaps with custom development?
Yeah, like I said, delegated administration is present in most of the solutions that I looked at, but how deep you can go with it really depends on the particular product. I'd say, please check out the report. I'm happy to have you read that and send me questions, but I think there is a fair amount of custom development that has to happen. In order to get the delegated administration depth that you might need.
And again, it really depends on the type of organization you're in, the regulations that you're subject to, how big your supply chain is, do you trust a specific individual within these outboard, and how much you're willing to pay for it. How big your supply chain is, do you trust a specific individual within these outboard organizations or do they actually need to delegate further to other individuals within their own organizations?
And if so, how do you trust that? And then what kind of interface is available? That's where you might need to do some custom development. But this is an established but still emerging, still evolving field, and I think we're going to see a lot more emphasis placed on this by these vendors in the years ahead.
So, with that, these are links to the relevant reports. The B2B IAM Leadership Compass has been published.
So, with CIM, Access Management is in work right now. ITDR, we touched on. And there's a Buyer's Compass for B2B IAM that kind of helps set you up for conducting your own RFP.
So, with that, since there are no further questions, I would like to thank everyone for attending today. And again, feel free to reach out to me if you have any questions or comments. Look forward to seeing you in our next event. Thank you.
See All Locations
See All Locations