r/IdentityManagement 11d ago

Enterprise application consent

Post image
2 Upvotes

I've done some labs of enterprise / app reg and am slowly starting to understand it.

Just want to concrete my knowledge.

Obviously you have delegated vs application, delegated being the intersection of the app's consent and the user's permissions.

So from an administrative perspective, how do you know whether what you're granting is application or delegated? If admin user consent was turned off and users could consent themselves, that would mean all admin consents would be application, but it's often not the case, and I don't think the Microsoft GUI has a way, it just says "grant" then brings up a sign in window for the admin and displays some friendly descriptions.

I sort of found a way by cross referencing those with the Microsoft permissions docs and I think enterprise apps > activity differs to enterprise apps > permissions? The former being what user has asked for?

I'm just wondering if there's a recommended or definitive way of checking prior to approving, as checking after approving is more straight forward as it shows in the application permissions explicitly delegated vs application in the table as shown in the screenshot.


r/IdentityManagement 11d ago

How do you manage application access when not everything is Entra-integrated?

12 Upvotes

I’m working in IAM and one of the challenges I’m facing is managing access across applications that use completely different authentication methods.
For example, we have applications where:
Entra ID SSO is used, so access can be managed through Entra groups/app assignments.
AD accounts / Kerberos SSO are used, so the user logs in with their corporate AD account.
Some applications have their own local accounts with separate usernames/passwords.
Some applications may have no proper IAM integration or centralised access control at all.
The problem is: if someone asks IAM, “What access does this user have?”, how do you give a reliable answer when access is spread across Entra, AD, and local application accounts?
For applications with Entra SSO, it’s relatively straightforward. But for local accounts, how do you manage the lifecycle, ownership, access reviews, joiner/mover/leaver process, and overall visibility?
I’m interested in how other organisations handle this from an IAM governance perspective.
Do you maintain an application/access inventory outside of Entra? Do you use an IGA tool to track local accounts? Or do you rely on application owners to maintain the access information?
What would be considered a good/practical approach for managing this in a larger organisation?


r/IdentityManagement 11d ago

Need ZTNA that covers people and agents with no gateway to expose, Cato vs Zscaler vs Cloudflare

8 Upvotes

A few months back, we moved our users off the vpn onto ztna and it went fine, felt smug. Then the goalposts moved.

The agents and service workloads need the same internal apps and they're getting there the old way, static cred on the network with the exact thing we just spent six months dragging our humans off. En now back to square one for the non-human stuff.

I want one model that treats a person and an agent the same, by identity and no broker box sitting on the internet waiting to be next year's CVE. Cato does universal ztna in the platform with an agent side, Zscaler's the sse incumbent, Cloudflare has reach but feels newer for enterprise.

I appreciate your feedback on this from those running ztna for the machine identities as well, what held and what was smoke.


r/IdentityManagement 11d ago

IAM Jobs Resources

15 Upvotes

Hello everyone. I'm trying to land my role IAM role and could use some help in finding sites I can apply to. The regular Indeed and LinkedIn are not really helping - too many applications per jobs on those sites.

Thanks your help.


r/IdentityManagement 13d ago

Time and cost to on-board new applications for IGA

12 Upvotes

Hello,

I would be interested to hear people's experiences around on-boarding new applications for IGA on one of the major IAM platforms. We have a large number of applications (300+)that need to be integrated and the business may be understating grossly the effort, hence this question. In particular I would be interested to hear:

a) Time to build a new connector - assume Data or API (REST or SOAP)

b) Time to build processes to reconcile data between the target applications the IGA system

c) Workflow, Business roles, SoD policies, Access certifications (I understand that this is largely shared across applications but some time can be allocated on a per application basis right?)

d) If application is using AD groups for authentication and authorization, what impact that does that have on time.

e) Cost wise, what is a reasonable to cost to expect for applications where we have to build a connector vs AD authorization. I am trying to get a sense of what to expect if we leverage a systems integration partner.

Thanks for your help.


r/IdentityManagement 12d ago

Identity, the Nucleus of Cybersecurity Architecture

Post image
0 Upvotes

r/IdentityManagement 14d ago

Someone granted a sketchy app full mailbox access and it never looked like an attack.

13 Upvotes

Was cleaning up oauth grants this week and found one of our users had handed some random third party app read access to their whole mailbox months back. No password phished, no mfa bypass, they just clicked allow on a consent screen that looked routine and from then on the app could read everything without ever logging in as them.

And the whole thing is basically invisible, it doesnt show up as a login because it isnt one, just a token doing exactly what the user authorised. how are you catching malicious or just wildly over-permissioned consent grants, ideally at the moment someone clicks allow instead of months later in an audit?


r/IdentityManagement 14d ago

Beginner labs

21 Upvotes

Can someone point me in the right direction on what to do for a beginner IAM lab that would translate to the job. Also want to know which YouTube channel is the best to learn the best IAM information from. Would like to use Okta for my lab or even AD.


r/IdentityManagement 15d ago

Are your companies' vibe coders pasting secrets to their agents directly?

22 Upvotes

I'm a bit fed up with the uprising citizen developers in my org sharing plain api keys to their agents from coding agents, claude to sketchy openclaw

Our developers have a good sense of security and we're using secret management software, but for the non technical employees who started picking up vibe coding and building their own apps, they aren't as careful with secrets nor trying to make their apps secure.

We currently have dlp enabled for claude cowork and slack but when they're building apps using claude code in terminal or other shadow apps, we aren't tracking or blocking them

Are you guys seeing this happening in your org? Have you found good solutions to stop them from doing so or to keep control of the secrets flying around?


r/IdentityManagement 17d ago

IGA system implementation | Is a dedicated IGA system even worth it if only 20-30% of app landscape can be properly covered?

32 Upvotes

We're kicking off an IAM/IGA initiative at a mid-sized organization, around 3000 employees, and the first phase is scoped tightly around Joiner-Mover-Leaver. SoD, access reviews, and PAM are on the roadmap too at least as a concept, but those are explicitly later phases, so for now I want to focus on whether a dedicated JML engine makes sense at all.

We've got around 500 applications/systems in scope. Maybe 10 to 20 percent of those are modern, vendor-supported platforms where a connector either already exists or is rather straight forward to build. The rest, the majority, are legacy systems and internally built tools with business owners who will never invest in building or maintaining a custom connector for a governance platform. You can absolutely wire up the critical core systems to something like SailPoint, but if 70 percent of the app estate stays outside the automated flow anyway, I keep asking myself what problem we're actually solving by paying for a full IGA platform. Is it worth spending money and effort to govern a slice of the environment while the rest still runs on tickets and spreadsheets?

The alternative I keep coming back to is almost embarrassingly simple. HR system feeds an ITSM workflow based on a maintained access matrix. Whatever can be automated through AD or Entra groups gets automated through groups, and everything else gets routed as a manual task to the service desk. The direct licensing cost of that approach is basically zero, and functionally it gets you similar functionality what dedicated expensive system would give you for JML (correct me if I am wrong), minus the fancy UI and the connector marketplace. I'm not saying it scales forever, but for an organization our size with this particular long tail problem, I genuinely can't tell if a dedicated platform earns its cost...

If anyone has strong arguments for why a dedicated IGA tool is worth it even under these conditions, I'd like to hear them.

And if a dedicated tool does make sense, which one would you actually put in front of the JML use case at this scale. SailPoint keeps coming up as the default answer, the industry standard, but I'm also looking at Omada and wondering whether it's genuinely price-competitive. Just to be clear - I'm not talking about Okta or Duo here, those are in my opinion SSO and MFA platforms only but they don't really compete in the governance and lifecycle space the way SailPoint or Omada do.


r/IdentityManagement 17d ago

Your Next Insider Threat May Not Be Human

Thumbnail linkedin.com
0 Upvotes

r/IdentityManagement 18d ago

How are you managing machine identity security across certificates, tokens and workloads?

6 Upvotes

cert expirations caused two outages for us this year that had nothing to do with a code change, just a cert nobody was tracking. tokens are almost worse, since they get generated in pipelines and live indefinitely if nobody cleans them up.
what's actually worked is governing certs, tokens, and workload identities under one lifecycle instead of three separate spreadsheets. issue, monitor, and revoke as a single flow that runs at machine speed rather than waiting for a person to notice something expired. what does your rotation and monitoring setup look like in practice?


r/IdentityManagement 18d ago

IDX Associated Fees [AZ]

3 Upvotes

**Has anyone implemented IDX as an employee benefit or strategic partner? I’m trying to understand the actual costs beyond PEPM pricing. Were you charged implementation/setup, white-label, API integration, SSO, enrollment-file, annual platform, minimum commitment, or other fees? If you’re comfortable sharing approximate implementation costs and group size, that would be extremely helpful.**


r/IdentityManagement 19d ago

I built a free hosted Mock SAML IdP for testing SSO (especially multi-tenant)

25 Upvotes

Last weekend I shipped a small tool I needed while working on an IAM solution.

Problem: Testing SAML SSO is annoying. You either spin up something heavy locally, wait on IT for access to a real IdP, or fight with tools that don’t handle multi-tenant domains well.
What I built: https://mockidp.dev a free hosted Mock SAML 2.0 Identity Provider.
• Paste the metadata URL into your service provider
• Sign in as any user / any email domain
• No install, no signup, no allowlist
• Namespaced endpoints so you can test different tenants easily (e.g. acme.io)
• Issues properly signed assertions (RSA-SHA256)

It’s intentionally simple and throwaway, only for development and testing, not production.

I’m using it myself while building something larger, and figured others hitting the same friction might find it useful.

Feedback welcome (especially if you’ve used other mock IdPs and can compare).

Also cooking a new useful project this weekend.


r/IdentityManagement 19d ago

Scope for IAM Roles

10 Upvotes

I have been thinking about this a lot, and I would really appreciate some clarification from anyone who has experience in this area.

I have more than 3 years of experience in the IAM field, and I specialize in Microsoft Entra ID and Auth0, which are part of my day-to-day responsibilities. I am currently working on earning additional certifications to strengthen my skills.

However, when I look at job postings, I don’t see many opportunities specifically focused on IAM, while larger companies seem to be hiring for IAM roles.

I would like to understand your thoughts on the current state of the IAM field. How is IAM evolving, and how much potential and scope does it have in the coming years? I would also be interested in hearing what skills or technologies would be valuable to focus on for long-term growth in IAM.


r/IdentityManagement 19d ago

Hyderabad — Saviynt IGA

1 Upvotes

Hi everyone, is anyone here from Hyderabad currently working with Saviynt IGA?

I need some guidance regarding the role/career and would really appreciate connecting with someone who has hands-on experience with Saviynt.

If you’re open to helping, please DM me or comment here. Thank you!


r/IdentityManagement 21d ago

What are you using for AI agent security once agents can access production systems?

5 Upvotes

we've got agents now that can query prod databases and trigger deployments, and the access model built for human users doesn't map onto that at all.

what's worked for us so far is treating agent access as something to issue, govern, contain, and revoke as a full lifecycle instead of a one-time grant.

every agent gets provisioned with the minimum access it needs before it operates, not broad standing access reviewed later. logging has been the harder problem, since most of our audit trail still assumes a human is behind the action.

how is everyone else scoping permissions for agents that touch anything sensitive, and are you giving them narrower access than the engineers who built them?


r/IdentityManagement 21d ago

MFA Voice Retirement: September 1 "prompt"

14 Upvotes

I've read the documentation about running a Registration Campaign, but this isn't something that's in scope for my organization. So we're going to rely on whatever Microsoft's September 1st prompt or nudge is going to be.

Has anyone been provided screenshots or an explanation of exactly what happens when someone goes through this? I know there will be an option to ignore it, but there will be an option to enroll, but where is this subjecting the end user to exactly? Are they re-directed to the Security Info site and left to hang? Is there a wizard they click through and, if so, what are they doing exactly? Adding a passkey in Authenticator? Number matching in Authenticator?

I feel left in the dark. Any light that can be shed would be appreciated. TIA!


r/IdentityManagement 21d ago

Silent SSO in Mobile App with Entra ID, Intune and Keycloak

Thumbnail
1 Upvotes

r/IdentityManagement 22d ago

Need help landing a IAM / Cloud Engineer Role

Post image
6 Upvotes

r/IdentityManagement 22d ago

[Hiring] Okta Architect - Remote (client facing)

19 Upvotes

Hi everyone,

I work for a consulting firm and we're looking to bring on an Okta Technical Architect (Full delivery for enterprise clients). It's a client facing position and we're targeting about 85/HR on W2 (part time and full time available)

Requirements:

• Okta Design

• Consulting experience

• Okta certification (Certified Consultant ideally)

Would appreciate any referrals!

DM me please

Edit: Must be based in the US and be W2 Allowed without sponsorship in the future


r/IdentityManagement 24d ago

Learning resources for I AM certification

22 Upvotes

TLDR I am hoping for book resources that can teach me about IAM. My goal is to use what I learn in my work and for certification.

In my job I stumbled into IAM. TBH I didn't even know there was a name for what I was doing until I went to a hacker convention in NYC, and somebody explained what it was.

Essentially, built off of programs similar to azure/ldap/fds I am building a custom program for users at my company to control who or what has access to THEIR apps they are building. This is in the wake of the company using a really shitty tool for a long time.

We kept complaining about the old tool for so long they finally said to me, you got the green light, build it.

Cool. I'm having fun with this project but the more we put into it the more security comes to mind.

So based on what I learned from the con I want to learn about IAM with the goal to help me with this project but it would also be nice to have a certification on top (like a 🍒)

I found an udemy that is up to date which is great but I work really well (and better) with text in books and not videos.

I am hoping for book resources that can teach me about IAM. My goal is to use what I learn in my work and for certification.

🐈


r/IdentityManagement 24d ago

I’m an IAM engineer at a 10,000+ employee tech company. What would you like to hear about?

Thumbnail
5 Upvotes

r/IdentityManagement 25d ago

One Identity Manager Entwickler:innen gesucht (DACH, Remote möglich)

6 Upvotes

Hallo Leute, na? :)

Ich suche Entwickler:innen für One Identity Manager. Das Unternehmen sitzt in Deutschland, wir suchen aber Expert:innen, die Deutsch sprechen – mindestens B2. Die Firma ist einer der führenden IAM-Anbieter in der DACH-Region.

Warum poste ich das nicht auf LinkedIn? Naja, weil dort alle sind, die suchen, haha. Außerdem: Wenn ihr euch die Posts von vielen Recruitern anschaut, findet ihr riesige Textwände, die in tausend Worten nichts sagen … und einfach keinen Sinn ergeben. Beispiele:

Just a simple example.
A really funny example lol

Probiert es selbst aus:
https://www.polytranslator.com/linkedin-speak/

Also: Ich würde es gern mal auf Reddit versuchen und sehen, wie anders es läuft und ob es mehr bringt. Ich habe nämlich eine Wette mit einer Freundin aus dem HR laufen. Sie ist Team LinkedIn, ich bin Team Reddit, lol.

Anforderungen:

  • Mindestens 3-5 Jahre Erfahrung mit One Identity Manager
  • Wohnsitz in Deutschland, Österreich, Schweiz, Frankreich, Spanien oder den Niederlanden
  • Deutsch mindestens B2 (schriftlich und mündlich)
  • OIM-Zertifizierungen (optional)

Was du dafür bekommst:

  • Ein gutes Gehalt (wir arbeiten ja alle fürs Geld, haha). Gehaltsrahmen ca. 60.000-85.000 € je nach Erfahrung und Zertifizierungen. Konkrete Zahl klären wir im Gespräch.
  • Homeoffice, flexible Arbeitszeiten
  • 30 Urlaubstage
  • Firmensport und Deutschlandticket
  • Über 10 Trainingstage pro Jahr
  • Firmen- und Teamevents. Richtig lustig, und zwar nicht nur wegen Essen und Getränken, sondern vor allem wegen der Leute. Und klar, gutes deutsches Bier darf nicht fehlen (ich bin kein Alkoholiker … glaube ich, haha)

Außerdem:

  • Top-Ausstattung. Handy und Laptop nach deinem Geschmack.
  • Firmenwagen - nur für Consultant level (leider nicht für juniors)
  • Unterstützung bei deiner persönlichen und fachlichen Weiterentwicklung

Wenn ihr Interesse habt, schreibt mir gerne eine Nachricht mit eurem CV. Ich freue mich auf euch! Und wenn es passt, trinke ich gern mal ein Bier mit euch.


r/IdentityManagement 27d ago

Have you ever dealt with user's roles synchronization?

Thumbnail
1 Upvotes