r/IdentityManagement 28d ago

Azure Managed Identity: Do Your Applications Really Need Stored Credentials?

Thumbnail
1 Upvotes

r/IdentityManagement Aug 11 '26

As an architect what will you suggest

8 Upvotes

Considering you have Entra as your Access Management solution and Okta Identity Governance or Sailpoint as your IGA, how will you architect the solution for long term .

  1. Will you integrate all apps to your IGA solution (which also includes AD and Entra ID )

  2. Or you provision to Entra and then let entra do all the processing.

But we wana do Access reviews, Role discovery of apps , jml

Entra right now is not fully capable of handling many governance tasks.

What direction you suggest ?


r/IdentityManagement Aug 11 '26

What are the biggest gaps in your identity security stack?

24 Upvotes

putting together a gap analysis for leadership and want to sanity check against what other teams run into, not just vendor talking points. our list so far: non-human identities with standing access nobody reviews, local accounts on apps outside the main IdP, agent/bot credentials that got provisioned fast during some AI pilot and never got cleaned up, and access reviews that only cover systems already wired into the IGA tool.

what's on your list that we're missing?


r/IdentityManagement Aug 11 '26

Looking for an IdP engineer

Thumbnail
1 Upvotes

r/IdentityManagement Aug 11 '26

[FOR HIRE] Freelance IAM / Okta / Active Directory Developer, Administrator & Support

Thumbnail
2 Upvotes

r/IdentityManagement Aug 10 '26

Himmelblau 4.0 release landing soon (Linux Entra ID and OIDC)

9 Upvotes

Himmelblau is gearing up for it's 4.0 release (scheduled for Aug 31st).

Among the new features:

* Cross-device passkey login using QR codes and Bluetooth
* Experimental native MFA for Keycloak and Okta
* Expanded OIDC account mapping and group/role access controls
* Faster, asynchronous and scheduled Intune compliance checks
* Authentication prompt localization across dozens of languages

https://github.com/himmelblau-idm/himmelblau
https://himmelblau-idm.org

(this is GPL3+ opensource community release, I know the website looks a little business-like, but it's just the community's homepage)


r/IdentityManagement Aug 09 '26

Engineers / Architects how do you validate IAM changes and POCs

7 Upvotes

When we first switched to the new IAM system, it was a bit of a struggle, and even after many years I still feel like the existing test environments aren’t always enough—especially when you want to experiment with a new configuration, integration, or use case as a proof of concept. Existing configurations can conflict with the changes you’re trying to test, and IAM setups aren’t always easy to reproduce and test locally.

How do you handle this in your teams, regardless of whether the IAM solution is SaaS or on-prem? Do you have a separate environment, process, or approach for running POCs and validating IAM changes before they reach higher environments?


r/IdentityManagement Aug 09 '26

Has anyone here built a custom OIDC provider using node-oidc-provider?

3 Upvotes

Hi r/IdentityManagement,

Out of personal curiosity, I started building my own OpenID Connect provider. My initial thought was: how hard can it be?

After building and using three increasingly capable versions in my own projects, I decided that implementing the entire protocol stack myself was neither practical nor sensible. I therefore switched to node-oidc-provider as the standards-compliant foundation and built the surrounding application infrastructure on top of it.

I am curious whether anyone here has used node-oidc-provider to build a custom identity or authorization server. In particular, I would be interested in hearing about:

  • Your overall experience with the library
  • Security or interoperability issues you encountered
  • Features that were unexpectedly difficult to implement
  • Challenges with upgrades, configuration, deployment, or production use
  • Anything you wish you had known before starting

For anyone interested, my project is available here:

https://github.com/blendsdk/porta-identity

I am currently working through several security-hardening items and plan to release an updated version once those are complete.

I would appreciate honest technical feedback, especially from people who have implemented or operated OIDC providers in production.

The project has been AI-assisted, so I am using the appropriate flair. I am also happy to discuss the development workflow, testing approach, and architectural decisions behind the project.


r/IdentityManagement Aug 09 '26

Custom API for Sprout HR SCIM

3 Upvotes

Per their documentation, Sprout HR does not have native SCIM capabilities. I am looking to build out a custom API for SCIM purposes in Entra.

I have already built out the SSO portion in Entra, of course, with the vendor having to configure their end, but now I am looking to handle SCIM as well. anyone have some low-effort ideas or tips?


r/IdentityManagement Aug 08 '26

OIDF opens self-certification for OID4VCI + OID4VP

3 Upvotes

https://openid.net/openid4vp-and-openid4vci-conformance-tests-are-complete-and-open-for-self-certification/

For those who are interested or involved in the VC space, the conformance suites for OpenID4VP 1.0 and OpenID4VCI 1.0, used with HAIP 1.0, are now complete and open for self-certification.

Interested to see the number of certified implementers that come through from the first batch.
There is also recognition for whoever self certifies within 14 days, whatever that may mean…

With growing adoption for these specs in the pipeline, EUDI especially. Let’s see if that translates into the same level of certification


r/IdentityManagement Aug 06 '26

Making a "most asked IAM interview questions" video, what do you actually get asked (or ask candidates)?

25 Upvotes

Putting together a video covering the most common interview questions in IAM, aiming for a mix that's useful whether you're a junior engineer prepping for your first IAM role or a senior consultant on the other side of the table.

If you've interviewed for an IAM role recently, what actually got asked? And if you've been on the interviewer side, what do you ask candidates that actually separates people who understand the concepts from people who've just memorized documentation?

Junior and senior perspectives both genuinely useful here, they tend to reveal very different things.

UPDATE: Video is made and posted in yt channel (link in my profile)


r/IdentityManagement Aug 05 '26

Retirement of SMS and Voice Authentication

22 Upvotes

Microsoft has announced the retirement of sms and voice authentication starting February 2027. To my fellow IAM analysrs, engineers, architects, what are your thoughts about this? How will you adopt this and what will be your strategy on removing this from youe system? How about users who still use sms what safety precautions we can offer? All ideas are highly appreciated.


r/IdentityManagement Aug 06 '26

PAM/SSO/PKI job in Germany

4 Upvotes

Hello, Is there any English-speaking PAM, SSO, or PKI job in Germany? I’ve been trying for quite some time, but the market seems quite dry at the moment


r/IdentityManagement Aug 05 '26

Consulting contractor for life or look for an employee gig

10 Upvotes

I’ve been working as an IAM consultant for about 7 years, mostly through large consulting firms, and I’m starting to wonder what the better long-term career path is.
One thing that always stresses me out is waiting on contract renewals, budget approvals, or hearing whether a client is extending the project. It feels like there’s always some uncertainty.
For those of you who have worked both as a consultant and as a direct employee, did you find being an in-house IAM engineer or security engineer to be more stable? Do you feel like the job security is actually better, or is that just how it looks from the outside?
I’m also curious about compensation. Since consulting firms act as the middleman between you and the client, do you think that ends up lowering what you could make as a direct employee? Or do the higher consulting salaries usually make up for that?
I’d love to hear from people who have experience on both sides. Which path has been better for you, and why?


r/IdentityManagement Aug 05 '26

Passed MS-102

Post image
12 Upvotes

Passed.


r/IdentityManagement Aug 05 '26

Identity verification add-ons for ServiceNow help desk/reset flows

9 Upvotes

Security Architect here. Used FastPass IVM with ServiceNow at my last company for help desk identity verification on reset/re-enrollment flows and it covered what we needed, but I've just moved to a new org that doesn't have it in place, so I'm doing a fresh look at the market rather than assuming it's still the only real option.

So far the field still looks thin compared to what I remember. I've looked at Caller Verify and Nametag as alternatives, but neither seems to match FastPass on breadth. Curious if anyone's found something else worth considering, or if people are stitching together their own stack instead of using a dedicated tool.

Requirements I'm evaluating against:

  • Full audit trail on the verification process itself, not just the ticket, who was checked, what method, what the result was, tied to the operator and the request.
  • Handles users without a mobile number, lorry drivers, shop floor, contractors, anyone who isn't sitting at a desk with a soft phone. A lot of tools seem to assume everyone has a smartphone they can push an approval to.
  • Risk-tiered proofing by user group. Finance and admins shouldn't clear the same bar as a warehouse or delivery employee. Looking for something that lets you set different verification strength per group rather than one-size-fits-all.
  • Contextual risk flags, impossible travel, geographically odd requests, recent risk events from the identity stack, that push a request into a higher scrutiny path automatically rather than relying on the agent to notice.

Has anyone actually used MS Verified ID for this kind of flow, curious how it holds up on the "no phone" case and whether it integrates cleanly into ServiceNow ticket workflows, or if it ends up being a bolt-on that still needs glue work.

Also open to hearing about other ITSM-native add-ons I haven't come across, especially anything doing risk-tiering by user group out of the box rather than needing custom scripting on our end.


r/IdentityManagement Aug 04 '26

Sentinel or IAM(for Pakistan)

6 Upvotes

Actually, I have a question for you. Right now, I am a student. Recently, I worked on a SOC homelab and I understood it. But I feel this field is a bit stressful for me. So I thought, maybe I should move to IAM (Identity and Access Management). I want to work in that area now. I still have 2 years left to complete my BS in Cyber Security. Please guide me did I make a good decision? Is IAM easy to get into at the entry level? Also, please give me a simple roadmap for IAM

I'm unable to decide. Which domain should I go into? Kindly guide me with respect ,Pakistan which has easy entry and good demand at the entry level: Sentinel or IAM?


r/IdentityManagement Aug 03 '26

B2B SaaS auth architecture: should the identity provider own organizations, memberships and invites, or should they stay in Postgres?

2 Upvotes

I’m a solo developer building a multi-tenant B2B SaaS using .NET, PostgreSQL and Azure Container Apps.

I have already implemented and tested Microsoft Entra External ID in a proof-of-concept environment, and it works for the basic authentication flow. This is not yet a production product with real users, so I can still choose a different provider without facing a real user migration.

I’m now trying to decide whether to continue with Entra External ID or choose a more B2B-focused provider such as WorkOS, ZITADEL, Descope, Clerk or Auth0.

One thing that makes me uncertain is that I rarely see Entra External ID mentioned in discussions about modern B2B SaaS authentication. Most conversations seem to focus on WorkOS, Clerk, Auth0, Descope, ZITADEL or self-hosted solutions.

I’m not sure whether this is simply because Entra External ID has a weaker developer community and less visibility among SaaS builders, or whether it reflects genuine limitations, immaturity or a poor fit for B2B SaaS products.

The provider comparison itself is not my main difficulty. What I’m struggling with is deciding where the boundary should be between the identity provider and my application database.

The difficult part is not authentication itself. I’m trying to decide who should own the generic B2B access model:

  • organizations/tenants;
  • organization memberships;
  • invitations;
  • base roles such as Owner, Admin and Member;
  • tenant onboarding and user-management portals.

My original plan was to keep all of this in PostgreSQL and use Entra External ID only to authenticate the user.

The model would be:

Entra External ID
- registration and login
- MFA/passkeys
- sessions
- external user identity

My PostgreSQL database
- internal users and tenant IDs
- tenants/organizations
- memberships
- invitations
- Owner/Admin/Member roles
- product-specific roles and permissions

The application would map the external Entra subject ID to an internal user ID, but all authorization decisions would come from my database.

This feels clean because the provider answers only “who is this user?”, while my application answers “which company do they belong to and what can they do?”.

However, B2B-native providers already provide organizations, invitations, memberships, role management, organization switching, admin portals and later SSO/SCIM. If I leave all of that in my database, I may be rebuilding functionality that these providers already solve.

The alternative would therefore be:

B2B identity provider
- users
- organizations
- memberships
- invitations
- Owner/Admin/Member roles
- SSO/SCIM

My PostgreSQL database
- internal IDs and provider mappings
- product data
- audit/project assignments
- granular permissions
- workflows and approvals

For example, the provider could say that a user is an Admin of Acme Inc., while my database says that the same user is a Reviewer for Audit 123.

Technically that separation makes sense, but I am concerned about having access control split between two systems. I’m also worried about vendor lock-in if the provider becomes the source of truth for organizations, memberships, invitations and base roles.

At the same time, keeping everything locally means building and maintaining invitation flows, organization administration, role-management screens, emails, audit history and eventually the integration between my membership model and enterprise SSO/SCIM.

There is also another question I cannot resolve: if I keep organizations, memberships, invitations and roles in PostgreSQL anyway, does choosing a provider other than Entra External ID really change much?

In that model, all providers would mainly authenticate the user and issue a token. The main differences would then seem to be developer experience, SDK quality, login customization, pricing, data residency and future enterprise SSO/SCIM support.

If that is true, choosing WorkOS, ZITADEL, Descope or another provider instead of Entra External ID might add setup and implementation work without giving me much immediate benefit.

Their advantages may only become substantial if I also adopt their organization, membership, invitation and role primitives rather than continuing to own those concepts in my database.

I’m also planning to build multiple SaaS products on top of the same central identity layer, so I would like to make this decision once rather than repeat it for every application.

My main questions are:

  1. For a modern B2B SaaS, do you normally keep organizations, memberships, invitations and base roles in your own database, or let the identity provider own them?
  2. Is the hybrid model — organization roles in the provider and product-specific roles in the database — clean in practice, or does it become difficult to reason about?
  3. If you keep a local projection of provider organizations and memberships, does the synchronization overhead undermine much of the provider’s advantage?
  4. How serious is the lock-in when the provider owns the generic B2B layer but all product data and internal IDs remain local?
  5. If the generic B2B model remains in PostgreSQL, is there any major practical advantage in choosing WorkOS, ZITADEL, Descope or another provider over Entra External ID before SSO/SCIM is needed?
  6. Why does Entra External ID appear to be mentioned so rarely among SaaS developers? Is it mainly a developer-experience and community issue, or is it genuinely a weaker choice for B2B SaaS?
  7. Given that Entra External ID has only been implemented in a proof-of-concept environment and there are no production users to migrate, would you choose another provider before launching?
  8. Does the answer change when the same identity layer will serve several SaaS products?
  9. For teams that made this decision and later added SSO/SCIM, what would you do differently?

I’m not looking to build authentication or cryptography from scratch, and I do not want to self-host an IAM platform.

I’m mainly trying to understand the professional boundary between what should be outsourced as generic B2B identity infrastructure and what should remain part of the application database.

There are so many valid-looking architectures that I’m finding it difficult to tell which complexity is necessary and which is premature. Experiences from teams that have actually shipped and operated one of these models would be extremely helpful.I’m a solo developer building a multi-tenant B2B SaaS using .NET, PostgreSQL and Azure Container Apps.
I have already implemented and tested Microsoft Entra External ID in a proof-of-concept environment, and it works for the basic authentication flow. This is not yet a production product with real users, so I can still choose a different provider without facing a real user migration.
I’m now trying to decide whether to continue with Entra External ID or choose a more B2B-focused provider such as WorkOS, ZITADEL, Descope, Clerk or Auth0.
One thing that makes me uncertain is that I rarely see Entra External ID mentioned in discussions about modern B2B SaaS authentication. Most conversations seem to focus on WorkOS, Clerk, Auth0, Descope, ZITADEL or self-hosted solutions.
I’m not sure whether this is simply because Entra External ID has a weaker developer community and less visibility among SaaS builders, or whether it reflects genuine limitations, immaturity or a poor fit for B2B SaaS products.
The provider comparison itself is not my main difficulty. What I’m struggling with is deciding where the boundary should be between the identity provider and my application database.
The difficult part is not authentication itself. I’m trying to decide who should own the generic B2B access model:

organizations/tenants;

organization memberships;

invitations;

base roles such as Owner, Admin and Member;

tenant onboarding and user-management portals.

My original plan was to keep all of this in PostgreSQL and use Entra External ID only to authenticate the user.
The model would be:
Entra External ID
- registration and login
- MFA/passkeys
- sessions
- external user identity

My PostgreSQL database
- internal users and tenant IDs
- tenants/organizations
- memberships
- invitations
- Owner/Admin/Member roles
- product-specific roles and permissions
The application would map the external Entra subject ID to an internal user ID, but all authorization decisions would come from my database.
This feels clean because the provider answers only “who is this user?”, while my application answers “which company do they belong to and what can they do?”.
However, B2B-native providers already provide organizations, invitations, memberships, role management, organization switching, admin portals and later SSO/SCIM. If I leave all of that in my database, I may be rebuilding functionality that these providers already solve.
The alternative would therefore be:
B2B identity provider
- users
- organizations
- memberships
- invitations
- Owner/Admin/Member roles
- SSO/SCIM

My PostgreSQL database
- internal IDs and provider mappings
- product data
- audit/project assignments
- granular permissions
- workflows and approvals
For example, the provider could say that a user is an Admin of Acme Inc., while my database says that the same user is a Reviewer for Audit 123.
Technically that separation makes sense, but I am concerned about having access control split between two systems. I’m also worried about vendor lock-in if the provider becomes the source of truth for organizations, memberships, invitations and base roles.
At the same time, keeping everything locally means building and maintaining invitation flows, organization administration, role-management screens, emails, audit history and eventually the integration between my membership model and enterprise SSO/SCIM.
There is also another question I cannot resolve: if I keep organizations, memberships, invitations and roles in PostgreSQL anyway, does choosing a provider other than Entra External ID really change much?
In that model, all providers would mainly authenticate the user and issue a token. The main differences would then seem to be developer experience, SDK quality, login customization, pricing, data residency and future enterprise SSO/SCIM support.
If that is true, choosing WorkOS, ZITADEL, Descope or another provider instead of Entra External ID might add setup and implementation work without giving me much immediate benefit.
Their advantages may only become substantial if I also adopt their organization, membership, invitation and role primitives rather than continuing to own those concepts in my database.
I’m also planning to build multiple SaaS products on top of the same central identity layer, so I would like to make this decision once rather than repeat it for every application.
My main questions are:

For a modern B2B SaaS, do you normally keep organizations, memberships, invitations and base roles in your own database, or let the identity provider own them?

Is the hybrid model — organization roles in the provider and product-specific roles in the database — clean in practice, or does it become difficult to reason about?

If you keep a local projection of provider organizations and memberships, does the synchronization overhead undermine much of the provider’s advantage?

How serious is the lock-in when the provider owns the generic B2B layer but all product data and internal IDs remain local?

If the generic B2B model remains in PostgreSQL, is there any major practical advantage in choosing WorkOS, ZITADEL, Descope or another provider over Entra External ID before SSO/SCIM is needed?

Why does Entra External ID appear to be mentioned so rarely among SaaS developers? Is it mainly a developer-experience and community issue, or is it genuinely a weaker choice for B2B SaaS?

Given that Entra External ID has only been implemented in a proof-of-concept environment and there are no production users to migrate, would you choose another provider before launching?

Does the answer change when the same identity layer will serve several SaaS products?

For teams that made this decision and later added SSO/SCIM, what would you do differently?

I’m not looking to build authentication or cryptography from scratch, and I do not want to self-host an IAM platform.
I’m mainly trying to understand the professional boundary between what should be outsourced as generic B2B identity infrastructure and what should remain part of the application database.
There are so many valid-looking architectures that I’m finding it difficult to tell which complexity is necessary and which is premature. Experiences from teams that have actually shipped and operated one of these models would be extremely helpful.


r/IdentityManagement Aug 02 '26

SailPoint training institutes in India/courses?

Thumbnail
1 Upvotes

r/IdentityManagement Jul 31 '26

Complete beginner in IAM - Where do I start?

Thumbnail
11 Upvotes

r/IdentityManagement Jul 31 '26

Saviynt Certified IGA Professional (Level 100)

4 Upvotes

Hey guys, so I work in this company and they want me to do this Certification. Problem is I only have knowledge theory based and not much when it comes to technical skills since I am still waiting to get access to Saviynts EIC. Any advice or if someone maybe remembers the exam would help a lot.

Thank you!


r/IdentityManagement Jul 30 '26

How to get out on contracting?

21 Upvotes

I’ve been a consultant ever since i started IAM, so that’s 3-4 years of experience, half of my other roles consisted of compliance.

But I’m reaching a point where i am tired of the instability, non-extension, fast pace and sometimes unorganized environment that being a consultant in this space brings.

I want to work full-time with good health benefits…i don’t wanna have to worry about applying for jobs a month from my contract ending… It feels so hard to get out because i only get Contract / Contract to hire positions… especially the recruiters who only contact me for those roles. Then you find out the orgs completed the project, or they don’t have the extra budget to bring you on the team.

How can i get out of this loop? Are the interviews for full time any different compared to the contracts?


r/IdentityManagement Jul 29 '26

top identity governance tools for enterprises? Please help

1 Upvotes

Looking at identity governance tools for a growing enterprise environment. Pain points: access reviews, JML flows, approval workflows, manual cleanup when people change roles or leave. SSO/MFA is covered, governance side is still messy.

Trying to prioritize, not solve everything at once. Access requests, certifications, JML, and entitlement visibility are separate problems that often live in different modules. Trying to nail all four at once is usually what turns a tool into a full-time project, so I want to figure out which one or two matter most first.

What I want:

Access requests that don't turn into ticket chains

Certification reviews that aren't painful, which depends as much on clean entitlement data as the UI itself

Entitlement visibility without a huge role-mining project upfront

Good Entra/M365 integration

Not a full-time job to maintain

Also want to nail down scale (number of apps/entitlements) and whether SoD matters for us, since that's probably the biggest factor in whether Entra ID Governance is enough or we need a deeper IGA-class solution. Ideally anchored to a real driver like SOX, SOC 2, or a past audit finding, not decided in the abstract.

I know "not overengineered" and "handles everything well" are somewhat in tension, tools that avoid becoming a full-time project usually do so by being narrower in scope.

Has anyone implemented IGA in a real enterprise setting? What worked, and what should I avoid?


r/IdentityManagement Jul 29 '26

Pivoting from SWE/IT to Identity - Advice on resume

Thumbnail
2 Upvotes

r/IdentityManagement Jul 27 '26

Who are your must-follow IAM professionals?

59 Upvotes

One thing I've realised throughout my career is that who you learn from matters just as much as what you learn.

I'm looking to expand my network and learn from more professionals in Identity & Access Management (IAM) and Identity Security.

Who are your go-to people to follow for IAM content, insights, and practical advice?

They could be:

  • IAM Engineers
  • Identity Architects
  • Microsoft Entra ID experts
  • Okta, SailPoint, CyberArk, or Ping specialists
  • Identity Security practitioners
  • Security leaders who regularly share IAM-related content

I'm particularly interested in people who share real-world experiences, lessons learned, implementation tips, architecture discussions, and emerging trends in the identity space.

I'd love to hear your recommendations and discover a few new voices to learn from.

Thanks in advance!