Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts. My guests today, yes, it's two, Nitish Deshpande, he's a research analyst with KuppingerCole and Martin Kuppinger, he's the principal analyst at KuppingerCole and one of the founders. To start with Nitish, hi Nitish, good to have you. Hi Matthias, good to be here on this podcast. I'm excited to speak about today's topic. I'm really looking forward to that. And first of all, hi Martin, good to have you back.
Hi, welcome. Good being here again. On one of my favorite topics.
Yes, talking about favorite topics, we want to talk about modern authorization, as this is a topic that we will cover at EIC, so that was a hint for later. But first of all, if you are starting that podcast episode and think, oh, should I stay there or should I go? You want to stay because we really want to look at the state of affairs regarding modern authorization, what has changed, because this is a topic for quite a while. And where are we right now and where does it really make sense? And it's really something for live performance, you can use that.
That's really something where we are right now. But first of all, we go back into the ancient times of KuppingerCole, times when I was not with the company. So I'm here for 11 years or so now, but I tried to find early blog posts by Martin regarding modern authorization. And I have two quotes, and then I say from where it is. First of all, as Martin says, the world of authorization is changing and organizations have to define new authorization strategies. That's from 2009.
Externalized authorization significantly improves your ability to react to changes in your business or compliance requirements. And that is a quote that dates back to 2013. So that means, Martin, you already highlighted dynamic authorization very early. Why has it taken so long or why are we still talking about that and what has changed since then?
Yeah, I think you spared a third quote, which was around me saying XACML is something really great, which it was, I think, in some respect and wasn't in some other respect. I think it was great as saying we need the standard for externalizing authorization out of applications. And there needs to be a standard. The challenge was, I think, there never was a good answer for the SS or the legacy. So for all the applications that exist, and it was, as the name indicates, XACML, it was XML. So it was rather heavyweight. And also from the way it was provided, not always user-friendly.
So the expectations on both the people defining policies and the developers consuming definitely were slightly over the top. So I think the idea remains right. We still need it. We probably need even more. Because back in some 15 years ago, we were still living in relatively static IT environments.
Nowadays, we are talking about very dynamic, volatile environments. We talk about a high degree of automation. And what is, I think, very, very clear, we can't manage large, volatile environments and automation with traditional static concepts in the entitlement and authorization world. But in some areas, especially when you are regulated, you still find very static entitlements because they are easy to understand, they are easy to audit, they are easy to document, not necessarily appropriate, but they work in that area. I doubt that they are easy to create. Every role project gets in trouble.
They are not easy to define. They are not easy to understand. You need specialized tools to analyze how your entitlements look in your Active Directory and in all the other environments. You need a team to understand how your entitlements look in these environments. They are not easy at all. We are used to it, but only because we didn't give a proper try to do it better.
And yes, we will probably touch the governance aspects of dynamic, policy-based authorization models. It is different. It will be very different, yes, but it's doable. Absolutely. Point taken. Taking one step back, we have invited Mitesh because it's his area of expertise. He's working actually right now at research documents around that topic of modern authorization. But to take that one step back, Mitesh, what does make authorization modern? What needs to be the case to speak about modern authorization in contrast to old authorization?
Yeah, thanks Mitesh. I think, first of all, as you mentioned about the research topic, it will come out soon about leadership composed on policy-based access management. And if you talk a bit about what makes authorization modern is, I think I agree first with what Martin said earlier about standardization. We need a standardization for handling the policies so that you have more interoperable systems, so policy enforcement and can talk to any policy decision point.
But if you talk about modern systems, having a more dynamic context-aware authorization system is much more the need of the hour than a standard traditional model. So that's where I think we are right now. Taking into account more signals apart from assignments that have been made at admin time, so really understanding all these dynamic aspects that come with a session, with a context, with a situation where the actual actor is located. I think that is one of the key aspects.
And I think the real-time aspect, really reacting at runtime towards these changing signals and maybe changing authorization at runtime, that is also an aspect of modern authorization. Anything to add from your side, Martin? I think this is what exactly makes the difference to what we discussed some 10 to 15 years ago.
Because back then the focus was basically when we looked at the world of policy information points, as they were called back in the days, then basically there was a list of relatively static information or a set of relatively static information in directory services and databases, etc. And I think with all the signals we can consume, but also the emerging standards around sharing signals, we have the opportunity to work fundamentally different here by bringing in way more context. So that means we create adaptiveness.
We do it, by the way, in certain areas when we look at authentication, which is policy-based, which consumes signals. We already do it, but we can do it beyond that, sort of every aspect of authorization. And so I think this is really probably that paradigm shift that we have a different, broader, and way more powerful spectrum of information to make decisions or the system to make decisions. Right. And when you look at the market on the one hand and at real-time deployments, Nitish, what is the current state of modern authorization in enterprise environments? Are there enough vendors?
Are there enough projects? Are there enough companies just using that as a standard authorization scheme? Has that arrived in real life?
Yeah, right now there are several vendors around providing modern authorization systems and also enterprises are moving towards a more dynamic, context-based, real-time authorization systems. The second is also externalizing authorization, which is, again, quite important. There's another quite important, fascinating aspect which I came across is having an air gap architecture where the authorization systems are managed locally, but also globally as well.
So they can be run in offline environments, but of course you need to be connected to the main system once in a while for regular updates, but that's where the current train is more important. Right, but that's also something that is done for, on the one hand, for autonomy of the systems, but also just for performance, right?
Yeah, for performance as well. Even without in this offline environment, the latency is quite low, so decisions are made in seconds, milliseconds, so there's not much difference. It's not entirely new, as I saw, but very important because also back in the days the question was always, where's the policy enforcement point versus the policy decision point located, PDP versus PDP? There were different models.
Usually it was a mix because there's not a single right answer and I think this will be the same, but again a bit on steroids in a way more complex landscape than what we discussed a longer time ago. When we just think about policy-based authorizations, we grant to autonomously acting AI agents. Then I think it becomes clear when we just let this sink a bit in our brain and start to think about it, then it becomes very clear, okay, that is an area where it really is way more complex to solve than the traditional challenges.
Right, and I think this modern authorization is, from my perspective, an enabler technology. It's nothing that, of course, it has worth in itself, but it's a tool, it's an enabler that allows for the implementation of all these elephants in the room that are around for quite a while. For example, the Elephant Zero Trust that demands for a modern, for dynamic, for adaptive authorization, apart from adaptive authentication, but this is really an enabling technology. Is Zero Trust driving modern authorization, Martin? Is Zero Trust driving modern authorization?
I think Zero Trust definitely benefits from it. Is it driving modern authorization? I don't know. I think it got a bit calm, quiet around Zero Trust. So the driving is a big term here, but I would say it is needed for a Zero Trust architecture. It is needed.
And also, when you look at this core picture from this about Zero Trust architectures, policy-based controls are at the very center of Zero Trust. In that sense, yes, you can say it definitely is one of the drivers for that.
And it, again, sort of reinforces the need for it. I fully agree. And Nitish, you've mentioned already that you are focusing your research currently on the PBAM, policy-based access management side of things, and that has gained significant traction recently. So how does PBAM address current issues, weaknesses of traditional authorization models, and how can that improve the situation here?
Yeah, so we're working on this new research topic, and one of the things which PBAM does is it's quite flexible, and it provides access controls in real-time, which you just mentioned, and it combines the best of the traditional models, like role-based access control, attribute access control, where you get more broader policies that can ingest not just roles but also attributes and make decisions based on those. So right now, I think these are some of the strong points of policy-based access management.
Of course, there's another aspect is you need good data, and data has to be the core foundation for ingesting all these contextual attributes. So I think data governance is another aspect that is quite closely related to policy-based access management.
Okay, if we talk about real-time data, if we talk about the governance, and Martin, you've mentioned that already, so how to govern policies that react on dynamic data, how to audit, how to trace back access management decisions that have been done based on volatile data. You've mentioned already this is something very different from what you do when you are used to role-based access control, but do you think that is an issue, that is a challenge that is already addressed in these solutions, and that just demands for a new way of dealing governance and compliance?
I would say it's partially addressed, but I'd like to go for a twofold answer. The first one, so to speak, directly responding to what you said, the second being more the advocatus diaboli. So the good thing is policy governance is way simpler than traditional access governance for a couple of reasons. Policies are easy to understand. Policy always has a structure of a subject, an action, an object, and maybe a constraint, but however you phrase it, the structure always will be the same, whether it's a firewall rule or whether it's something you use in your daily life.
Child, don't touch the hot oven, same structure. So that is easy, and people understand it. We can construct it easy, we can review it easy. It's not artificial as a role. A role is an artifact, it's artificial. A policy is something which we understand, we use daily. The point is the policy is related to data, the signals, the static data from directories, from databases, et cetera, that is used for making a decision.
If a user is in the role of an admin, so if Nitish is in this role, then he's allowed to do certain things or whatever else, surely not necessarily a role, but we depend on the quality of the data. So what we need is we need to have a data governance concept approach in place for the data we consume for decision making. So now to the Advocatus Diaboli. Nitish rightfully mentioned the signals.
So yes, we can consume roles if you still have roles, because they're just a sort of attribute. We can use every other type of attributes that signals factually are, in that sense, also attributes. You also could say everything is a signal. However we phrase it, I don't care much about that. The interesting point is if we move from very few attributes, one to very few, to maybe a very large number of signals, then the quality challenge goes down.
Because if you have many signals or really many signals that are on average relatively weak, but if they are all pointing in the same direction, and there are mathematical models you can use for visualizing this and for analyzing this. So what is the combined quality of the signals? If you have 50 or 100 signals, then even weak signals will provide you with a very high probability.
And then we may face over time, this is probably more for the discussion, the addition of this podcast we do in 2040 or so, we may then see that some of these problems are just done by having way more signals than we ever envisioned. And then that would be the advocates, they probably pointed, we may even sort of get rid of most or of parts of the data governance challenge. But on the other hand, hey, we need data governance anyway. We need good data quality everywhere. So it's not that we just need it for policy-based access.
I think maybe I would like to add one more thing is that there's one way of kind of ensuring we have good data is through good identity lifecycle management. And not just a few ones, but current time also about non-human identities with the NHI is growing at an exponential rate. So that could also be included in this aspect.
Yeah, I think what Martin also mentioned is if we have more signals that need to be, of course, evaluated and then assessed and then in combination leading to entitlements decisions, that also stresses the usual way of how we do decision-making processes because it may be just too challenging. I did podcast episodes with Alexei, our colleague around CIM and SOAR. And the part where technology comes into play is really in reducing the noise and filtering and in analyzing the data that's actually relevant. And the more data you have, that's a long question, I know.
And the more data you have, the more you need support in getting to the right access management decision based on all these signals. Now the question, how important is the aspect of machine learning AI in the solutions that you're currently looking at? Are they already supported by AI mechanisms to ensure that even a large number of signals are taken into account? Yeah. So right now you see all these current pretty well augmented generation systems. We have the generative AI where you put in a query and you get the response and enterprises are one more using it.
So let's say a user requests a question and then the system needs to then verify if this user can access this information. Can he access a certain aspect of this information, certain documents? So there needs to be certain authorization systems in place which can ensure this happens. So the modern authorization solutions are focusing more on this aspect as well, as they're providing more fine grained authorization systems, even in these AI and machine learning models. And there's another thing is the use of AI and machine learning, how they can use it in policy-based access solutions.
And it is, I think one example I can say is making AI-based access decisions. So policy-based access solutions are leveraging something such as user behavior pattern or prescriptive analytics to adjust these policies in real time without any intervention. So that is something which we are seeing right now. And also in general, automating the policy process. So the policy lifecycle management is a huge process that deals with creation, testing, simulation, modification, updating, and also decommissioning. And so automating this entire process will save a lot of effort as well.
Anything to add from yourself, Martin? I think that the point where the solutions will benefit is by utilizing AI even more for sort of verifying, justifying the decision making. Because I think what AI can add is an angle. And in that sense, you can also say it's just another signal, which is the behavioral analysis. So far we talked about someone has certain attributes that are static in certain systems. There are additional signals that are more from the current situation. What AI can add is the behavioral aspect. So is this something Matthias usually does, ever has done?
Or is this a really unusual behavior which needs specific attention? And that is, I think, an angle. I have to admit I haven't really thought about it before. But I believe we should spend some thinking around that. Because this is, in that sense, a third dimension of, let's call it signals or attributes we have on hand for improving decision making.
And again, the charming aspect is that, that goes back to my Advocatus Diaboli point before. That will help us reducing the dependency on excellence in data governance. So we need data governance, no doubt. But we have a thing that helps us addressing this. And to be honest, with that we will be endlessly, infinitely better than with traditional access control concepts. Because traditional concepts look at just what someone is entitled to do. They don't really consider the context. They don't consider the behavior.
And so compared to the static models, this is also from a, I would say at the end, enforcing a least privilege principle, which is the main focus of an auditor. It's the way, way better approach. And we can make it work everywhere, including for legacy applications.
Really, really interesting. And I think to go back full circle to our initial statements, what has changed? Maybe one additional thought since 2009. I think if somebody wanted to try out modern authorization schemes way back then, yeah, they needed to choose one of these few solutions that were available. These were commercial. There was a high entry barrier that needed to be jumped over to try modern authorization.
Today, such a person as well, I always want to try these things out before I believe they work. But everybody can now use very fundamental and very capable solutions like open policy agent, OPA, which is available. And you can just try it and use it and implement it in your solutions and see how it works. So no high entry level barrier there apart from you need to do it. But I think that is also really an interesting point. And then you can really either stay with that solution or move over to all these solutions that Nitish is looking at in his leadership compass.
I think so making it more accessible, making it more at your fingertips for these modern authorization schemes, that is also really something that can drive things forward. Before we close down, quick question, Nitish, anything to add? And I think you want to hint at some events.
And yes, definitely. I think just in over one month's time we will be in Berlin for the EIC conference. So looking forward to being at the conference and meeting all our peers and colleagues in this sector.
Yes, and modern authorization will be an important topic there as well. Of course, the relevant analysts are there.
Of course, the relevant vendors are there and practitioners are there. So if you have questions around that, you might want to raise them towards us.
If so, please leave a comment below that video and we will answer that question. But if you want to talk to people in real life, just join us in Berlin from the 6th to the 9th of May at Berlin Alexanderplatz and let's talk about, among others, modern authorization schemes and everything that we just covered in that episode. With that said, thank you very much, Nitish. Thank you very much, Martin, for being my guests today. I'm really looking forward to continue that discussion.
We know it's a long running and it will come back, but it's in real life and we can use it right now and it really improves our decision-making processes. Thanks again, Martin and Nitish. Goodbye.
Thank you, Matthias.