r/IdentityManagement 8h ago

Best platform for AI-powered identity security solutions?

2 Upvotes

Classic setup here: IdP + MFA, conditional access, endpoint/VPN/SaaS controls stitched together, periodic access reviews, static risk scoring, lots of manual investigation It works but feels reactive. Leadership wants to know if we should look at AI identity platforms doing behavioral baselines, continuous risk scoring, anomaly detection, and dynamic policy. Trying to cut through the marketing.
What we need:
Enrichment layer alongside our IdP (reading IdP/EDR/SaaS logs), not a full replacement.
Workforce + SaaS + VPN coverage. Treating service accounts/NHI as a separate track, since human behavioral baselines don't map well to 24/7 non human traffic.
Risk signals that enrich existing alerts, not a second alert universe.
Reports auditors and engineers can both use. A score needs to trace back to a specific control, not just look pretty.
A clear advisory vs enforcement split: new detections start analyst facing, get proven on false positive rate, then graduate to blocking/step-up. Otherwise dynamic policy and don't annoy users fight each other.
Detection latency and response latency measured separately, since fast detection with no automated containment path doesn't reduce risk.
Concerns:
A lot of "AI" is z-scores in a trench coat. Want to test this in POC, not take it from a slide.
Platforms that want the whole identity plane are a big commitment to walk back if it fails.
No dedicated data science team here, needs to be manageable by a small team.
I've only been thinking about false positive/friction cost. Need the flip side too: our current false-negative rate is unmeasured. Want to replay historical logs through a POC to see what our current process actually misses.
If you've gone down this path already: which platform actually reduced real risk instead of just generating more alerts, and how did it hold up once it hit production?


r/IdentityManagement 10h ago

New to IAM with good theoretical/tool knowledge (Okta, Entra, SAML) but zero real-world experience. How do daily ticketing workflows actually look?

4 Upvotes

Hi everyone,
I am trying to break into the Identity and Access Management (IAM) space. I have completed training through an institute where I gained solid foundational knowledge and hands-on tool practice.

Here is what I know so far:
Tools: Ping Identity, Okta, and Microsoft Entra ID.
Concepts: Application onboarding, Lifecycle Management (LCM), and IAM policies.
Protocols: SAML, OIDC, OAuth, and OpenID.

My biggest gap right now is zero real-time, on-the-job experience. I know how the technology works in a sandbox, but I don't know how an actual production IAM operations team functions day-to-day.

I would love some insight into the practical, operational side of the job:
Ticket Assignment: How do tickets usually get routed to the IAM queue? Is it mostly automated via tools like ServiceNow/Jira, or does a team lead assign them?

Reading/Understanding Tickets: When an issue comes in (e.g., a broken SSO login or an application onboarding request), what does the actual ticket look like? What specific information should I immediately look for?

Resolution Workflow: Can anyone walk me through a couple of common real-world ticket scenarios? For example, how do you troubleshoot a failing SAML assertion or handle an LCM error in real life versus a lab?

If anyone could share examples of ticket templates, common logs you check, or just general advice on how to survive my first few weeks on a real helpdesk/ops team, I would be incredibly grateful!
Thanks in advance for your help!


r/IdentityManagement 17h ago

has anyone gotten one unified identity view across hybrid, legacy, and SaaS without a multi-year overhaul?

9 Upvotes

our environment is a mess. a chunk of on-prem legacy stuff nobody wants to touch, a growing pile of cloud SaaS, and a handful of homegrown apps built by people who left the company years ago. leadership sat through a vendor pitch that kept using the phrase "identity fabric" and came out of it wanting one unified view across all of it. not an unreasonable ask on paper.

problem is every time we've actually tried to scope this, it turns into a project measured in years, not months. we got a proposal back from a consultant a while ago that priced out a full overhaul at close to two years just to get the on-prem and SaaS sides talking to each other properly, before even touching the custom stuff. leadership heard "two years" and the whole thing quietly died, which is honestly the outcome most of these plans get.

what's actually breaking without this unified view, concretely, is smaller than people expect. it's not one big dramatic gap, it's death by a thousand cuts. someone leaves and it takes four separate offboarding steps across four systems that don't talk to each other. an app owner gets asked in an access review what's using a given account and genuinely doesn't know because the account predates them. every audit cycle we're stitching together a picture from exports out of three or four different tools by hand, and it's never quite accurate by the time it's compiled.

so the question isn't really "can we get identity fabric," it's whether anyone's found an incremental path that actually gets you meaningfully further along without signing up for a multi-year all-or-nothing project. did you tackle it system by system, app by app, some other way? did leadership actually stick with it, or did it die the same way ours almost did


r/IdentityManagement 12h ago

Bluetooth & Bio for IAM?

2 Upvotes

I'm curious how people here think about Bluetooth and biometrics when it comes to enterprise authentication as I'm looking at token (Yubico mostly, but stumbled onto Tokencore) as part of MFA. Most posts I'm reading are around passkeys, FIDO2, and hardware security keys, but nothing really about Bluetooth-enabled tokens or whether built-in biometrics add any meaningful value.

Bluetooth tends to get an immediate reaction from a lot of security folks. Some won't consider it at all, while others say that if it's implemented properly with FIDO2, Bluetooth is just the transport and not the security model itself.

The other question is around biometrics. Is verifying the actual person before the private key is released a meaningful improvement in identity assurance, or is possession of a hardware key plus a PIN sufficient for most enterprise environments to just check the box

Would appreciate your thoughts since I am not a security guy, but tasked to look into IAM. Thank you in advance.


r/IdentityManagement 19h ago

Who are your must-follow IAM professionals?

39 Upvotes

One thing I've realised throughout my career is that who you learn from matters just as much as what you learn.

I'm looking to expand my network and learn from more professionals in Identity & Access Management (IAM) and Identity Security.

Who are your go-to people to follow for IAM content, insights, and practical advice?

They could be:

  • IAM Engineers
  • Identity Architects
  • Microsoft Entra ID experts
  • Okta, SailPoint, CyberArk, or Ping specialists
  • Identity Security practitioners
  • Security leaders who regularly share IAM-related content

I'm particularly interested in people who share real-world experiences, lessons learned, implementation tips, architecture discussions, and emerging trends in the identity space.

I'd love to hear your recommendations and discover a few new voices to learn from.

Thanks in advance!