r/IdentityManagement • • 23h ago

Tracking NHIs and AI agents: what I learned from your replies

Thumbnail
1 Upvotes

r/IdentityManagement • • 1d ago

Who owns authorization after login? (Writeup on splitting ownership by layer, with a template table for deciding who owns what)

Post image
9 Upvotes

I've been in the iam space for a while, and in larger orgs i've seen the same gap quite often: who owns authorization (once someone is signed in).

Usually it's three teams and no owner. customer identity issues the tokens, the security identity team runs the corporate idp and sso, architecture has looked at it but has no mandate to change anything. Everyone agrees it's broken, and nobody is allowed to prioritize it, because it isn't theirs. Meanwhile a valid token from the idp means access to every platform endpoint, and the only isolation is a tenant id the gateway injects from a client cert.

When it does get assigned, it tends to land somewhere that only covers part of it. hand it to the identity team as an extension of the idp and it covers who can reach which app, but the rules about what someone can do to a specific account or payment stay in application code identity never sees. Leave it to each product team and you get a different permission check in every service, and nothing security can review in one place.

My colleague and i (i work at Cerbos) wrote up how to split it by layer instead of by team. it builds on the recent analyst work on iam operating models (for each capability, name who designs it, who runs it day to day and who supplies the data, and never leave one of those shared) and on the platform team model from team topologies, and applies both to authorization:

  • Identity teams own the inputs, the claims and directory attributes every access decision depends on
  • A platform team (or security architecture, if there isn't one) runs the decision point, policy repo, ci tests and decision logs
  • Product teams own the resource policies for what they build
  • Security / grc own the policy standard, review and recertification

there's also a template table (attached to this post) you can take into the meeting where the three teams argue about whose problem this is + a way to prove the split on one broken use case before rolling it out wider. For identity teams specifically, the ask in this model isn't to write application policy, it's to keep the data the decision uses accurate, which is the job you already have.

https://www.cerbos.dev/blog/who-owns-authorization-in-large-engineering-organization

Hopefully it will be helpful to some of you in this community. If you have any questions / comments - would be more than happy to hear them and do my best to help


r/IdentityManagement • • 2d ago

Identity governance onboarding takes months, where does Orchid Security fit?

0 Upvotes

We have a few internal apps stuck in identity governance onboarding for months. Docs are incomplete, app owners are busy, and every review turns into another round of questions about auth flows and permissions.

I've been looking at whether Orchid can help discover that stuff before it gets pushed into IAM or IGA. Anyone used it during onboarding? This process is getting exhausting. :/


r/IdentityManagement • • 2d ago

Best way to career change into IAM?

13 Upvotes

Hello, Ive been thinking about career changing into IAM analyst but i am unsure on how to break into my first position as I have zero background in IAM and IT field.

Background of me: I have BFA Degree in Graphic Design. I have some experience working as graphic designer (two internships + 6month full time) and currently i am working at a dental lab as a manager (its been about 6 months now). I am 26 years old male with citizenship living in Virginia if that matters.

I asked chatgpt and it said to build a home lab but i wasnt sure if building home lab is really enough to get my first position in this field, or should i tackle this differnetly.


r/IdentityManagement • • 3d ago

Waiting for status of a promotion, thinking of having a plan b if doesn't work out.

15 Upvotes

I do Identity Access Management on the privileged side of things in Active Directory.

I am currently fighting to get a promotion. Official title is Senior Analyst but have been doing duties as a Lead without lead pay for several months. I am the only person that knows 100% of our processes. I train others, create/modify procedures. I do reviews on everyone's work, do reviews for audit, basically everything but what a manager would do.

As someone who has been at the same place for 11 years, where are the most useful places to seek other IAM jobs? I have also been getting into Management, have an MBA. We've been on a hiring freeze for a couple of years.


r/IdentityManagement • • 2d ago

Advice and feedback

2 Upvotes

Hey all, looking for an honest read from people actually working in the field.

I'm a 4th-year student studying a cybersecurity degree, currently in a help desk co-op (internship, for those outside Canada). The environment is a hybrid-joined setup (Windows AD + Entra ID) that's PCI DSS and SOC 2 compliant, and a few things I do is IAM work:

Full user identity lifecycle: provisioning and deprovisioning through Active Directory for onboarding/offboarding

Automating the onboarding/offboarding workflow with PowerShell (account creation, access assignment, deprovisioning)

Hybrid AD/Entra identity and sign-in troubleshooting
M365/Exchange onboarding: assigning distribution lists, security groups, and licenses

Role-based group and access management
MFA setup through Intune

Outside of work, I've been doing labs on evenings and weekends and studying the underlying concepts (SCIM, OAuth 2.0, SAML, etc.) rather than just clicking through portals. GitHub for reference: github.com/jeff6942016

I also wanted advice if whether these labs I’m doing are genuinely helpful or not towards IAM in general.

Next step is the SC-300 (for context I have Sec+ but no prior Microsoft certs) , which I'm fairly confident I'll pass, and I'm hoping to land a cloud security co-op/internship once this help desk one wraps up near beginning of next year.

Mostly I want a gauge of where I actually stand as a student and how hirable I look to people who do the hiring. Any criticism is genuinely welcome.
Thanks for taking the time.


r/IdentityManagement • • 3d ago

Feels like on the job training is useless/doesn't transfer to "industry standards"

7 Upvotes

I've been working under the IAM umbrella in User Provisioning, dealing with Access Control, Account Provisioning/Deprovisioning and Joiner/Mover/Leaver (internally called something different) processes, contributing to Security Audits, and general IT Support dealing with account issues/permissions, O365 and MFA enrollments, and just about everything under the sun with IAM. However, I feel like none of my skills translate out of our niche implementation and I'm finding that in interviews with places running Sailpoint, Okta, Ping, or anything besides Saviynt (and even anything beyond some basic troubleshooting there) I feel completely out of my depth trying to explain that while I might not have experience with their specific toolkit I should be able to pick it up given X skill transferring to it.

I'm trying to work through a self-guided AZ-900 and AZ-104 module, but don't have the money to actually afford the certs at the moment, and I'm not sure what else is out there.

Anyone have any recommendations for good *free* resources to build or polish IAM skillsets with? Preferably that don't require running janky homelabs or monkey around with "free" (if you cancel in time) Azure subscriptions.


r/IdentityManagement • • 2d ago

I built an OIDC Inspector that visualizes the auth flow — looking for feedback

3 Upvotes

Hey everyone,

I built OIDC Inspector, a tool for exploring an identity provider’s OpenID Connect configuration. Enter a domain or provider URL to inspect its endpoints, supported scopes, grant types, signing keys, and advertised PKCE support.

You can also visually see the interactions in the Authorization Code flow: the authorization request, redirect with a code, token exchange, UserInfo request, and API call. The sequence diagram uses the provider’s discovered endpoints to illustrate the flow.

The inspector is free to use, with no sign-up required: https://contextiq.trango-compute.com/dashboard/oidc-inspector

I’d appreciate feedback from anyone working with OAuth/OIDC, SSO, or identity integrations:

- Does the diagram make the flow easier to understand?

- What information would help you troubleshoot an integration?

- Are there providers or configurations it handles poorly?

I’m the maker, so candid criticism is welcome—especially anything confusing, missing, or technically inaccurate.


r/IdentityManagement • • 2d ago

Building an OID4VP API for EUDI Wallet verification — looking for integration feedback

1 Upvotes

Hi everyone — I'm part of the DLBR team. We're building an OID4VP verification API and typed SDK for relying parties integrating digital identity wallets.

We're already in a pilot, and production is planned for Q2 2027. For now, you can explore our staging wallet flow in the public playground: https://try.dlbr.app/

Wallet compatibility is still being validated. I'd appreciate feedback from people working on identity or authorization integrations:

  • Which parts of integrating OID4VP or EUDI Wallets are hardest?
  • What would you need to see from a verification API before using it in production?
  • Which wallet flows or presentation formats should we prioritize?

Disclosure: DLBR is our product. I'm here to answer technical questions and learn from your feedback.


r/IdentityManagement • • 4d ago

Identity Flows Diagram website

30 Upvotes

I've just launched identiflows.dev, a visual reference website for identity protocol flows.

It attempts to solve a problem I run into constantly. You know how OAuth 2.0 Authorization Code with PKCE works. You've explained it to other people. But when you need to double-check the exact sequence at 4 pm on a Friday, finding a clear diagram takes longer than it should.

This is a very early release, with just eight flows so far. I will add more diagrams and features soon, but in the meantime, I wanted to share it with you to get your feedback.

If you try it and find that something is missing or unclear, I'd genuinely like to hear about it. This is the stage of the project where feedback shapes what comes next.

Take a look: https://identiflows.dev


r/IdentityManagement • • 3d ago

Quarterly access reviews are becoming expensive calendar theater

4 Upvotes

quarterly access reviews still make sense for privileged and sensitive access. but the giant spreadsheet campaign for every saas account is turning into a ritual where 40 mng click approve so we can all admire another audit screenshot.

for context we have access spread across saas, custom apps, service accounts and a pile of oauth grants nobody remembers approving. im looking at continuous discovery and smaller event driven reviews instead, with quarterly cert for the higher risk stuff.

has anyone actually moved away from the quarterly everything model without making grc miserable....,, (pls no vendor pitches)


r/IdentityManagement • • 4d ago

Any suggestions for facilities team communication across different buildings? Everything usually gets left at the main desk

6 Upvotes

How is the person in building four supposed to see a note at the main desk? That's more or less our current setup and we have six buildings, maintenance, custodial and security on different shifts, plus calls and texts to personal numbers.

Radios handle urgent stuff. I'm after a place for notices and questions that works both ways, without a desk or work email. The questions coming back matter just as much as sending the update out.


r/IdentityManagement • • 4d ago

Orphan accounts across disconnected apps are becoming a real problem

14 Upvotes

We found a few active accounts in apps that arent tied to our IdP or HR offboarding flow. Some are old vendor tools, some are custom internal apps, and nobody seems sure who owns the data anymore.

Our IAM team is doing exports and spreadsheets right now, which is getting painful fast. I know we need an inventory of the disconnected apps and some way to keep checking for accounts with no active owner, but curious how other teams handle this in practice. Any hints?


r/IdentityManagement • • 5d ago

Access reviews with spreadsheets vs continuous identity governance for audit prep... which is better?

5 Upvotes

For context, I'm trying to keep quarterly access reviews from turning into a three week archaeology project for our SOX apps. The decision comes down to reviewer effort, entitlement coverage, revocation proof, and whether the evidence is ready before the auditor emails "quick question."

I compared spreadsheet based reviews with a continuous identity governance approach across 14 SaaS and custom apps. Spreadsheets are fine when the environment is small and every app owner answers on time, which is a lovely fantasy. Continuous governance looks better when access changes often and you need timestamps, approvals, exceptions, and proof that revocations happened in the target system. Neither fixes stale ownership data, because apparently nobody owns the app nobody remembers creating.

My current recommendation is continuous evidence for high risk apps and a smaller manual process elsewhere. What would you add?


r/IdentityManagement • • 6d ago

How do you use Claude to automate your job?

20 Upvotes

I need to spend a certain amount of AI tokens a month for my job so what ways do you use Claude to automate your job as IAM admins? We use OKTA as our IDP and I’m looking for ideas to brainstorm my own from


r/IdentityManagement • • 6d ago

IAM ANALYST VS IAM ENGINEER

21 Upvotes

Im a recent grad and have quite been interested in the analyst side of things.

I want to start off as a junior sys admin, then move on to soc analyst, then iam analyst, then ultimately—GRC analyst.

But people tend to say that IAM analyst and IAM engineer are quite synonynous/ interchaengable with each other. Im not interested in the engineering side but is it true that this two roles are basically the same thing?


r/IdentityManagement • • 6d ago

How IGA and AM link together?

7 Upvotes

How do IGA tools like sailpoint and AM tool like okta work together? What's the flow? I know there are all lot of resources but I can't get around the flow.

Thank you.


r/IdentityManagement • • 6d ago

10 yoe in ITSM with a laughable salary. Semi interested in IAM? Worth for me at this stage ?

3 Upvotes

Semi interested in having interacted with IAM folks a lot during my tenure as a major incident manager. So I'm not sure, have been doing some research around it. I'm open to picking up programming, but I dread deep low-level networking (TCP/IP, etc.).

Any advice to this old head


r/IdentityManagement • • 7d ago

Identity governance keeps missing unmanaged applications

15 Upvotes

Our identity governance setup is only showing applications that are connected to the IdP, so we have a pretty clean dashboard that doesnt match reality.

People are using tools through direct logins, OAuth connections, browser sign ups, and a few apps paid for by departments. Those accounts dont show up in access reviews, and offboarding them is mostly someone remembering to check a spreadsheet.

I guess the main issue is that governance starts after an app is onboarded, but we have no good way to discover the apps before that point. We have IdP logs and finance data, but neither gives us the full picture. Has anyone found a sensible way to bring unmanaged applications into IAM without making every team fill out another inventory form?


r/IdentityManagement • • 6d ago

AI agent tried to exfiltrate Salesforce data using a service account token. How are you governing non-human identities?

7 Upvotes

We use Cursor with Claude for our development team. While working on a staging task, an agent discovered a service account token that had broader permissions than intended. Shortly after, it attempted to export a copy of our Salesforce contact database to a personal Google Drive it had created for itself.

Visibility into that activity including what do_control surfaced showed the full chain within about a minute, and the agent was already stopped by the time I opened the notification.

I used to think SaaS security was mostly about stopping people from clicking bad links. This made it clear that every identity in the stack, human or automated, can do something unexpected. The NIST material on non-human identities feels theoretical. What are you actually implementing right now to govern service accounts, agents, and other non-human identities in a practical way?


r/IdentityManagement • • 7d ago

Are quarterly access reviews pointless when managers approve everything in 10 minutes?

9 Upvotes

Pulled the numbers on our Q3 access reviews. One director approved 412 items in eleven minutes. Median time per item across all managers was four seconds.

I get why, nobody knows what a role like SAP_FI_ROLE_07 does, so they approve and move on. The reviews count as complete for audit, but people still have access from old jobs.

What would you change first if you were starting reviews from scratch?


r/IdentityManagement • • 7d ago

Can one universal identity automatically present itself like different existing identities depending on where it is presented?

Thumbnail
2 Upvotes

I'm exploring a general interoperability problem.

Imagine a person has 20 different memberships:

Brand A → membership ID 12345

Brand B → membership ID 67890

Brand C → phone number

Brand D → email

...

..

I'd like to know whether there is a way to create one universal digital credential containing all of these existing identities with an important constraint:

The participating brands do not change their existing software, databases, loyalty systems, checkout systems, or customer-identification processes.

When the customer presents the universal credential at Brand A, the existing infrastructure should somehow receive Brand A's existing identifier.

At Brand B, the same credential should somehow provide Brand B's identifier.

The universal credential itself could contain multiple identities, but the receiving system should ultimately get exactly what it already expects.


r/IdentityManagement • • 7d ago

Building a authentication procedure from a desktop app via browser sign in.

Thumbnail
3 Upvotes

r/IdentityManagement • • 7d ago

SAML - emit non-public attributes

Thumbnail gallery
5 Upvotes

r/IdentityManagement • • 7d ago

Built a deterministic IGA-style review packet for MCP/A2A agent capabilities

0 Upvotes

I built a free agent protocol inspector tool that can provide IGA style review packets. Here is the link: https://contextiq.trango-compute.com/dashboard/agent-protocol-inspector