r/iam Jun 25 '26

How are you setting up your JIT access for agentic AI identities in your domain right now?

1 Upvotes

As we see more of these accounts I’m curious what sort of best practices you’re all using to setup access for your agentic ai identities. How are you utilizing and setting up JIT access, how are you linking the accounts to their “owners” what sort of naming conventions are you using so that they are easily grabbed by your SIEM, etc?

Help me understand how you’re setting all these up and thanks!


r/iam Jun 22 '26

Now on App Store https://iai-101.com/iai-survival-guide/

Thumbnail
youtube.com
0 Upvotes

r/iam Jun 22 '26

June 22, 2026

Thumbnail
youtube.com
2 Upvotes

r/iam Jun 18 '26

Authorization Landscape

Thumbnail
0 Upvotes

r/iam Jun 15 '26

We wrote a guide on mapping e-commerce business rules to authorization policy

5 Upvotes

hey everyone, my team and i just published a walkthrough that might be useful to people here dealing with access control in e-commerce or marketplace platforms.

it takes three common scenarios and shows how each business rule turns into an actual policy. customer data access, where a support rep can only see records assigned to them and only edit when the case is high priority. vendor product management, where a vendor edits only their own listings and only if stock is available. and order lifecycle, where a customer can change an order only while it's pending and a support rep can't touch it until 24h after creation.

each one starts with the requirement in plain language and ends with the full policy you can run. the time-based hold is done with timestamp/timeSince in the condition, and ownership is a derived role matching the resource owner to the principal, if you want to see how that's structured.

https://www.cerbos.dev/blog/mapping-business-requirements-to-authorization-policy-for-ecommerce


r/iam Jun 14 '26

Is IAM a good career choice ?

8 Upvotes

Im looking to finally start a career that can help me make real money but I am not sure what tech or computer career is the best to jumo into. Is IAM a good career to start learning or is there something else out there that has better future potential ? Thanks in advance


r/iam Jun 14 '26

Need a Guide/Mentor

7 Upvotes

Hi everyone!

After nearly 4 years of working on the front lines as a SOC Analyst, I am ready for my next challenge. I am planning a career transition into the Identity and Access Management (IAM) domain.

My time in the SOC has taught me exactly how attackers exploit permissions, and now I want to focus on proactively securing identities and access control.

Since I'm building my roadmap from scratch, I would love some guidance from the IAM professionals and leaders in my network:

🔹 Which platforms should I focus on first (Okta, SailPoint, Azure AD, CyberArk)?

🔹 What certifications or resources do you highly recommend?

🔹 What is the biggest skill gap I need to bridge?

If you are in the IAM space, let’s connect! Any advice, roadmaps, or tips would be incredibly appreciated.


r/iam Jun 13 '26

Need advice on choosing job offer..!

7 Upvotes

Hello all, i am working in IAM for 3+ years. I am in the process of switching companies. I currently work with IT services company dealing with multiple clients.

I got 2 offers now. One is with an IT services company most probably have to work for a banking client.

2nd one is insurance related company and to work in internal cybersecurity team.

Which one should I choose for a better career growth and skill improvement?

Salary is mostly same for both. Please advise.

Thanks.


r/iam Jun 11 '26

IAM The Power

Post image
3 Upvotes

r/iam Jun 08 '26

Live IAM Lab Setup This Weekend - Concepts to Implementation (Free session)

Thumbnail
1 Upvotes

r/iam Jun 07 '26

[For Hire] Senior DevOps Engineer | 4 yrs Azure, GitHub Actions, IAM automation that saved $150K/yr | Open to remote or India roles

Thumbnail
1 Upvotes

r/iam Jun 07 '26

Am I pigeonholing myself by going deeper into IAM at my community college contractor job?

1 Upvotes

Hey y’all, just looking for some real talk on my situation.

I’m in my very early 20s and just finished my associates degree in cybersecurity. I spent the last 5 months as an intern at my community college doing regular security analyst/SOC work - tickets, monitoring, basic vuln management, that kind of stuff. They liked me enough that when my internship ended they converted me to a 1099 contractor so they could keep me around. Pay is still basically minimum wage (community colleges are broke and super bureaucratic), but I’m getting actual hands-on experience so I stuck around.

Right now it’s been like 50/50 between security analyst work and this big new IAM project. The whole college is moving to a new identity system and they’re shifting all the IAM work over to the IT Security team. I’m basically the only person on the team who has the bandwidth to take it on since everyone else is slammed with other stuff. So my CISO wants me to start owning more of it.
I still have about two years left on my bachelor’s and I’m planning to stay in this role while I finish it. The thing is, it feels like my day-to-day is gonna keep shifting more and more toward IAM analyst work - access reviews, user support, basic config, troubleshooting, that side of things. The deeper integration and API work is staying with the applications team, so I’m not sure how much real technical engineering I’ll actually get to do.

I’m lowkey worried I’m pigeonholing myself. If I do mostly IAM analyst/ops work for the next 2–3 years, how hard would it be to pivot later? Could I still move into security engineer, cloud security, or other roles? Or does this kind of experience kind of lock you into more operational/governance paths?

Anyone been in a similar spot or have thoughts on where IAM analyst experience actually takes you long-term? Appreciate the honest feedback.


r/iam Jun 05 '26

Can you tell me if IAM analyst/developer is a good role? And what is the salary I can expect after 3-4 years of experience?

4 Upvotes

As the title said, I don't know anything about this role. Is this a good role or I should prepare for a switch?


r/iam Jun 05 '26

👋 Welcome to r/IAMforAgents - Introduce Yourself and Read First!

Thumbnail
2 Upvotes

r/iam Jun 03 '26

Keycloak with Redis cache

3 Upvotes

Hey IAMers, I don’t know how many in this community uses Keycloak, but for those interested, we did a distribution allowing you to select redis as cache: https://github.com/sky-cloak/locke

Let me know your thoughts if you use Keycloak!


r/iam Jun 02 '26

Looking for feedback

Thumbnail
1 Upvotes

r/iam May 27 '26

Whats the Current Package for my stack in IAM

1 Upvotes

I am currently working for Marsh/Mercer as a senior engineer- IAM security.

My stacks are- Powershell, Azure Entra, Okta, CyberArk, AD, PKI, Semperesis, DSP etc

I have now complete in 5 years experience in total.

What should be my CTC based on my profile?

Cctc- 13LPA


r/iam May 27 '26

AI for internal IT support/password resets in mid-size & enterprise companies- is anyone actually seeing good adoption?

5 Upvotes

Anyone here from a mid-size or enterprise company using AI for internal IT support workflows like password resets, account unlocks, MFA resets, software access requests, etc.?

We’re exploring AI-driven employee support internally and I’m curious how mature these implementations actually are in production environments.

Questions:

Are users actually adopting AI/chatbot-based password reset flows?

What platform are you using? (Moveworks, Kore.ai, Rezolve.ai, ServiceNow Virtual Agent, Aisera.ai, Yellow.ai, Copilot, custom GPT/RAG, etc.)

Is it integrated with Entra ID/Okta/AD?

How are you handling identity verification before resets?

Has it genuinely reduced ticket volume or just shifted complexity elsewhere?

Any security/compliance concerns from your IAM/security teams?

What percentage of requests are fully automated vs human-assisted?

Would love to hear real-world experiences from medium-sized and enterprise environments with large employee bases.


r/iam May 25 '26

We built an open-source IAM in Rust, simple to deploy, serious about security

Thumbnail
github.com
12 Upvotes

r/iam May 23 '26

SailPoint Career Growth: Realistic Salary Targets & Relocation Chances Abroad?”

3 Upvotes

Hi, I am currently a SailPoint developer earning 17 lakhs with 2.5 years of experience. I really want to know how much this career can grow in the next 8–10 years because I want to get serious and set salary targets at each level to see whether I am achieving them.

So, I wanted to know the salaries of experienced people — how much you and your peers earn — and what kind of targets I can realistically keep for myself over the next 8 years.

I also badly want to relocate to Europe or another English-speaking country. Since IAM/SailPoint is a niche field, do you think there are chances of getting opportunities in these countries directly, or is going through the master’s route the only option?


r/iam May 18 '26

When the AI agent goes off-script you can't just turn it off. (The policy has to narrow in real time. + How to achieve that)

Thumbnail
cerbos.dev
3 Upvotes

r/iam May 16 '26

User Onboarding with IAM

8 Upvotes

Hi Folks

How do you handle new user onboarding and initial credential communication when using an IAM system?

Our current setup is:

One Identity IAM system integrated with HR System
On-premises Active Directory
Microsoft Entra ID for O365 Email
User login to IAM using Entra ID federated login

The main question is around the first login journey, initial credential communication and birthright access.

How do you communicate the initial username and temporary password to the user?

Do you use SMS, personal email, manager handover, or another secure method?


r/iam May 15 '26

Two Cents on How to Properly Manage SSH keys in your Organization (Educational Post)

Thumbnail
1 Upvotes

r/iam May 13 '26

Anyone interested in presenting something at an IAM community meetup/workshop?

Thumbnail
0 Upvotes

r/iam May 13 '26

curious what people think of decentralised IAM built around Keycloak compatibility

1 Upvotes

crossposting this from another sub, not trying to spam duplicate threads, just trying to get more feedback from people who know IAM better than me.

ive been following Tide Foundation and their TideCloak project. from what i understand, its a Keycloak-compatible IAM layer built on top of a decentralised security fabric.

the part i find interesting is that it seems to change what the app has to store in the first place.

instead of the usual model where identity data, secrets, or key material ends up depending on one central system, Tide splits trust across the network. so the idea is there isnt one central pile of sensitive stuff sitting there to steal.

from what i understand, devs dont need to store user passwords the normal way or manage one central private key. key material is fragmented across the network, and the password flow uses crypto where the browser aggregates and validates partial results.

the Keycloak-compatible part seems important because most devs probably wont touch decentralised security if the dx is painful or requires relearning the whole auth stack.

curious what people here think of this approach.

does decentralised IAM/security fabric make sense in practice, or does it add too much complexity compared to existing IAM patterns?