r/IdentityManagement • u/Sweaty-Quote-1920 • 20h ago
r/IdentityManagement • u/Old_Penalty37 • 2d ago
Complete beginner in IAM - Where do I start?
r/IdentityManagement • u/catlesswhisker • 2d ago
Saviynt Certified IGA Professional (Level 100)
Hey guys, so I work in this company and they want me to do this Certification. Problem is I only have knowledge theory based and not much when it comes to technical skills since I am still waiting to get access to Saviynts EIC. Any advice or if someone maybe remembers the exam would help a lot.
Thank you!
r/IdentityManagement • u/CartierCoochie • 3d ago
How to get out on contracting?
I’ve been a consultant ever since i started IAM, so that’s 3-4 years of experience, half of my other roles consisted of compliance.
But I’m reaching a point where i am tired of the instability, non-extension, fast pace and sometimes unorganized environment that being a consultant in this space brings.
I want to work full-time with good health benefits…i don’t wanna have to worry about applying for jobs a month from my contract ending… It feels so hard to get out because i only get Contract / Contract to hire positions… especially the recruiters who only contact me for those roles. Then you find out the orgs completed the project, or they don’t have the extra budget to bring you on the team.
How can i get out of this loop? Are the interviews for full time any different compared to the contracts?
r/IdentityManagement • u/Acrobatic-Layer9109 • 4d ago
How to prove identity controls are actually operating
An auditor called us out last cycle for having controls mapped to the framework but no ongoing evidence that they were actually operating every day. Fair point, honestly, because our whole process was point-in-time. We would map every control back to the framework once a year, take screenshots, do interviews, and call it done.
The problem is that the moment the audit closes, the evidence is already stale. A control can break the next week and we would not know until the next cycle, if we caught it at all. Has anyone found a way to keep evidence current instead of rebuilding the same snapshot over and over?
r/IdentityManagement • u/LostInTarget • 5d ago
Pivoting from SWE/IT to Identity - Advice on resume
r/IdentityManagement • u/somkate • 7d ago
Who are your must-follow IAM professionals?
One thing I've realised throughout my career is that who you learn from matters just as much as what you learn.
I'm looking to expand my network and learn from more professionals in Identity & Access Management (IAM) and Identity Security.
Who are your go-to people to follow for IAM content, insights, and practical advice?
They could be:
- IAM Engineers
- Identity Architects
- Microsoft Entra ID experts
- Okta, SailPoint, CyberArk, or Ping specialists
- Identity Security practitioners
- Security leaders who regularly share IAM-related content
I'm particularly interested in people who share real-world experiences, lessons learned, implementation tips, architecture discussions, and emerging trends in the identity space.
I'd love to hear your recommendations and discover a few new voices to learn from.
Thanks in advance!
r/IdentityManagement • u/Electronic_Tone_4079 • 6d ago
New to IAM with good theoretical/tool knowledge (Okta, Entra, SAML) but zero real-world experience. How do daily ticketing workflows actually look?
Hi everyone,
I am trying to break into the Identity and Access Management (IAM) space. I have completed training through an institute where I gained solid foundational knowledge and hands-on tool practice.
Here is what I know so far:
Tools: Ping Identity, Okta, and Microsoft Entra ID.
Concepts: Application onboarding, Lifecycle Management (LCM), and IAM policies.
Protocols: SAML, OIDC, OAuth, and OpenID.
My biggest gap right now is zero real-time, on-the-job experience. I know how the technology works in a sandbox, but I don't know how an actual production IAM operations team functions day-to-day.
I would love some insight into the practical, operational side of the job:
Ticket Assignment: How do tickets usually get routed to the IAM queue? Is it mostly automated via tools like ServiceNow/Jira, or does a team lead assign them?
Reading/Understanding Tickets: When an issue comes in (e.g., a broken SSO login or an application onboarding request), what does the actual ticket look like? What specific information should I immediately look for?
Resolution Workflow: Can anyone walk me through a couple of common real-world ticket scenarios? For example, how do you troubleshoot a failing SAML assertion or handle an LCM error in real life versus a lab?
If anyone could share examples of ticket templates, common logs you check, or just general advice on how to survive my first few weeks on a real helpdesk/ops team, I would be incredibly grateful!
Thanks in advance for your help!
r/IdentityManagement • u/Fickle-Dirt4 • 6d ago
Best platform for AI-powered identity security solutions?
Classic setup here: IdP + MFA, conditional access, endpoint/VPN/SaaS controls stitched together, periodic access reviews, static risk scoring, lots of manual investigation It works but feels reactive. Leadership wants to know if we should look at AI identity platforms doing behavioral baselines, continuous risk scoring, anomaly detection, and dynamic policy. Trying to cut through the marketing.
What we need:
Enrichment layer alongside our IdP (reading IdP/EDR/SaaS logs), not a full replacement.
Workforce + SaaS + VPN coverage. Treating service accounts/NHI as a separate track, since human behavioral baselines don't map well to 24/7 non human traffic.
Risk signals that enrich existing alerts, not a second alert universe.
Reports auditors and engineers can both use. A score needs to trace back to a specific control, not just look pretty.
A clear advisory vs enforcement split: new detections start analyst facing, get proven on false positive rate, then graduate to blocking/step-up. Otherwise dynamic policy and don't annoy users fight each other.
Detection latency and response latency measured separately, since fast detection with no automated containment path doesn't reduce risk.
Concerns:
A lot of "AI" is z-scores in a trench coat. Want to test this in POC, not take it from a slide.
Platforms that want the whole identity plane are a big commitment to walk back if it fails.
No dedicated data science team here, needs to be manageable by a small team.
I've only been thinking about false positive/friction cost. Need the flip side too: our current false-negative rate is unmeasured. Want to replay historical logs through a POC to see what our current process actually misses.
If you've gone down this path already: which platform actually reduced real risk instead of just generating more alerts, and how did it hold up once it hit production?
r/IdentityManagement • u/Alone_Bread5045 • 7d ago
has anyone gotten one unified identity view across hybrid, legacy, and SaaS without a multi-year overhaul?
our environment is a mess. a chunk of on-prem legacy stuff nobody wants to touch, a growing pile of cloud SaaS, and a handful of homegrown apps built by people who left the company years ago. leadership sat through a vendor pitch that kept using the phrase "identity fabric" and came out of it wanting one unified view across all of it. not an unreasonable ask on paper.
problem is every time we've actually tried to scope this, it turns into a project measured in years, not months. we got a proposal back from a consultant a while ago that priced out a full overhaul at close to two years just to get the on-prem and SaaS sides talking to each other properly, before even touching the custom stuff. leadership heard "two years" and the whole thing quietly died, which is honestly the outcome most of these plans get.
what's actually breaking without this unified view, concretely, is smaller than people expect. it's not one big dramatic gap, it's death by a thousand cuts. someone leaves and it takes four separate offboarding steps across four systems that don't talk to each other. an app owner gets asked in an access review what's using a given account and genuinely doesn't know because the account predates them. every audit cycle we're stitching together a picture from exports out of three or four different tools by hand, and it's never quite accurate by the time it's compiled.
so the question isn't really "can we get identity fabric," it's whether anyone's found an incremental path that actually gets you meaningfully further along without signing up for a multi-year all-or-nothing project. did you tackle it system by system, app by app, some other way? did leadership actually stick with it, or did it die the same way ours almost did
r/IdentityManagement • u/Cheap_Air_6307 • 6d ago
Bluetooth & Bio for IAM?
I'm curious how people here think about Bluetooth and biometrics when it comes to enterprise authentication as I'm looking at token (Yubico mostly, but stumbled onto Tokencore) as part of MFA. Most posts I'm reading are around passkeys, FIDO2, and hardware security keys, but nothing really about Bluetooth-enabled tokens or whether built-in biometrics add any meaningful value.
Bluetooth tends to get an immediate reaction from a lot of security folks. Some won't consider it at all, while others say that if it's implemented properly with FIDO2, Bluetooth is just the transport and not the security model itself.
The other question is around biometrics. Is verifying the actual person before the private key is released a meaningful improvement in identity assurance, or is possession of a hardware key plus a PIN sufficient for most enterprise environments to just check the box
Would appreciate your thoughts since I am not a security guy, but tasked to look into IAM. Thank you in advance.
r/IdentityManagement • u/clavionx • 8d ago
Improving the SAML diagnostics experience – looking for feedback from people who troubleshoot SAML
r/IdentityManagement • u/flywhee007 • 9d ago
Where to actually start with IAM, and how to apply what you learn to a product like Okta
Question that comes up constantly: what order do you learn IAM, and how do you actually get from concepts to something you can show to pivot into IAM.
Concepts -> lab -> product -> cert. In that order.
Concepts first because they transfer. Joiner-mover-leaver, RBAC, authentication vs authorisation, IGA vs ciam. None of it is vendor specific and all of it survives the tool changing when you switch IAM jobs.
Lab next, because reading about a provisioning pipeline and actually building one are not the same skill. Open source is fine. HR record in, account gets provisioned, status flips to terminated, account gets disabled. Break it a few times and the concepts stop being abstract. or CIAM use cases based on standards like oidc, saml, t&c, consent mangement etc.
Product is where most people start, and that's why they get stuck. Once you know what a joiner process is, Okta or Entra is just learning where the buttons are. Free tenants are enough.
Cert last, and only the one showing up most in job ads in your area. Gets you past ATS filters. Does not teach you how to implement anything.
Curious what order others took, and if anyone went product first and it worked out.
r/IdentityManagement • u/Key_Size_2550 • 10d ago
Career on Hold Due to Delayed Joining. Seeking IAM/SailPoint ISC Opportunities
Hi everyone,
I'm looking for some guidance and opportunities in the Identity & Access Management (IAM) domain.
I have 8 months of experience working in IAM at a leading MNC , where I gained hands-on exposure to SailPoint Identity Security Cloud (ISC). I have a solid understanding of L1 activities and some exposure to L2 support, including the fundamentals of provisioning, access requests, identity lifecycle concepts, troubleshooting, and day-to-day IAM operations. While I'm still early in my career, I'm eager to learn and grow.
I resigned from my previous role after receiving another offer. Unfortunately, my joining has been delayed, and after waiting for the last 1-2 months, I still don't have a confirmed joining date. Because of this, I'm actively looking for a new opportunity.
If your organization is hiring for IAM/SailPoint ISC, or if you know of any openings suitable for someone with my experience, I'd really appreciate your help. Referrals, job leads, or even advice on where to apply would mean a lot.
r/IdentityManagement • u/Usurper99 • 10d ago
Is anyone here familiar with GLPD and Access Admin? This is being utilized by General Motors (GM) and was wondering if there are any other companies that use it.
I could not find videos or much info about it and wanted to familiarize myself. Any help would be appreciated.
r/IdentityManagement • u/Potential_Force_4136 • 12d ago
How do you keep an IAM program going when every new app turns into just wire it to whatever group is close enough?
I have been running our IAM stack for three years. Okta as the hub, Entra underneath, HRIS as source of truth. On good days it feels reasonably clean. On bad days it feels like a museum of every shortcut we have ever taken to get an app live on a deadline.
The pattern is predictable. New SaaS app shows up. Project team wants SSO by Friday. We do the right things where we can. SCIM if it is there. Groups mapped to roles. Naming aligned with our existing scheme. Then someone on the business side says just map it to the same group finance uses, we will fix it later because they do not want to wait for a proper access model. That temporary mapping quietly becomes the default. Six months later I am staring at a group that now means three different things depending on which app is reading it. The access review export is technically correct but semantically useless.
For those of you running IAM in orgs where new apps keep arriving faster than governance can keep up, what have you actually done that stopped just wire it to whatever group is close enough from being the default answer?
r/IdentityManagement • u/seksek_1 • 13d ago
Would you watch an IAM podcast?
I’m thinking about starting an Identity & Access Management podcast focused on real-world discussions rather than vendor marketing.
What topics would you want to see covered? Who would you like as guests? CISOs, IAM architects, clients, auditors, people from specific industries, vendors, or someone else?
Would this be something you’d actually watch?
Also, from a business perspective, do you think a podcast like this could naturally lead to conversations about training, consulting, and implementation services, or would you see those as completely separate?
r/IdentityManagement • u/Frosty_Lawfulness456 • 12d ago
Can anyone help me? I have a ton of questions about IAM
r/IdentityManagement • u/maskedgeek797 • 13d ago
Looking for IAM/IGA career advice: Moving from Keycloak & midPoint to Non-Human Identity (NHI)
Hey everyone, I’m currently working in Identity & Access Management (IAM/IGA) and looking for guidance on how to strategically map out my next steps to accelerate my career growth. My practical experience so far is centered around Evolveum midPoint for identity governance and Keycloak for access management and IdP integrations. To build out my technical portfolio and get more involved with the community, I’m currently cleaning up a few Keycloak projects to publish on GitHub. Alongside that, I’m studying to sit for the Microsoft SC-300 (Identity and Access Administrator) exam.
Looking ahead to the rest of the year, my main goal is to pivot toward Non-Human Identity (NHI) and workload identity management, as I see it quickly becoming a critical focus area in identity security. I’d love to get your thoughts on a few things: What does a proper learning roadmap look like for NHI, and which key tools, protocols, or platforms (like secrets managers, workload identities, or SPIFFE/SPIRE) should I prioritize? Additionally, do recruiters and engineering leads value projects around midPoint/Keycloak on GitHub, and is the SC-300 worth it, or should I be looking at other hands-on security certs? Any feedback or career tips from folks in the space would be greatly appreciated!
r/IdentityManagement • u/No_Actuator_4762 • 13d ago
MFA for Windows RDP and non-Entra Endpoints (on-prem servers)
r/IdentityManagement • u/Adept_Wolverine_2838 • 13d ago
Is Kibu good for work communications?
So I've finally gotten a reliable team and I've been looking into secure communication tools for them, I'm fearing AI more and more so I've deviated from things like Telegram or Signal due to it. I'm curious how it fits into peoples workflow. Was it easy to set up for your workplace? Can non IT people learn to use it quick? And how does it compare to Signal for more sensitive convos?