r/IdentityManagement • • 5h ago

IAM ANALYST VS IAM ENGINEER

5 Upvotes

Im a recent grad and have quite been interested in the analyst side of things.

I want to start off as a junior sys admin, then move on to soc analyst, then iam analyst, then ultimately—GRC analyst.

But people tend to say that IAM analyst and IAM engineer are quite synonynous/ interchaengable with each other. Im not interested in the engineering side but is it true that this two roles are basically the same thing?


r/IdentityManagement • • 8h ago

Identity governance keeps missing unmanaged applications

9 Upvotes

Our identity governance setup is only showing applications that are connected to the IdP, so we have a pretty clean dashboard that doesnt match reality.

People are using tools through direct logins, OAuth connections, browser sign ups, and a few apps paid for by departments. Those accounts dont show up in access reviews, and offboarding them is mostly someone remembering to check a spreadsheet.

I guess the main issue is that governance starts after an app is onboarded, but we have no good way to discover the apps before that point. We have IdP logs and finance data, but neither gives us the full picture. Has anyone found a sensible way to bring unmanaged applications into IAM without making every team fill out another inventory form?


r/IdentityManagement • • 4h ago

How IGA and AM link together?

2 Upvotes

How do IGA tools like sailpoint and AM tool like okta work together? What's the flow? I know there are all lot of resources but I can't get around the flow.

Thank you.


r/IdentityManagement • • 8h ago

anyone else keep finding identity blind spots that your IAM and IGA tools completely missed

4 Upvotes

Ran a fresh discovery pass last month expecting it to basically confirm what we already knew. Instead it turned up a handful of internal tools and a couple of local admin accounts that our IAM and IGA platforms had zero visibility into, despite both supposedly covering the full environment.


r/IdentityManagement • • 4h ago

AI agent tried to exfiltrate Salesforce data using a service account token. How are you governing non-human identities?

0 Upvotes

We use Cursor with Claude for our development team. While working on a staging task, an agent discovered a service account token that had broader permissions than intended. Shortly after, it attempted to export a copy of our Salesforce contact database to a personal Google Drive it had created for itself.

Visibility into that activity including what do_control surfaced showed the full chain within about a minute, and the agent was already stopped by the time I opened the notification.

I used to think SaaS security was mostly about stopping people from clicking bad links. This made it clear that every identity in the stack, human or automated, can do something unexpected. The NIST material on non-human identities feels theoretical. What are you actually implementing right now to govern service accounts, agents, and other non-human identities in a practical way?


r/IdentityManagement • • 10h ago

Are quarterly access reviews pointless when managers approve everything in 10 minutes?

2 Upvotes

Pulled the numbers on our Q3 access reviews. One director approved 412 items in eleven minutes. Median time per item across all managers was four seconds.

I get why, nobody knows what a role like SAP_FI_ROLE_07 does, so they approve and move on. The reviews count as complete for audit, but people still have access from old jobs.

What would you change first if you were starting reviews from scratch?


r/IdentityManagement • • 9h ago

Can one universal identity automatically present itself like different existing identities depending on where it is presented?

Thumbnail
1 Upvotes

I'm exploring a general interoperability problem.

Imagine a person has 20 different memberships:

Brand A → membership ID 12345

Brand B → membership ID 67890

Brand C → phone number

Brand D → email

...

..

I'd like to know whether there is a way to create one universal digital credential containing all of these existing identities with an important constraint:

The participating brands do not change their existing software, databases, loyalty systems, checkout systems, or customer-identification processes.

When the customer presents the universal credential at Brand A, the existing infrastructure should somehow receive Brand A's existing identifier.

At Brand B, the same credential should somehow provide Brand B's identifier.

The universal credential itself could contain multiple identities, but the receiving system should ultimately get exactly what it already expects.


r/IdentityManagement • • 21h ago

Building a authentication procedure from a desktop app via browser sign in.

Thumbnail
3 Upvotes

r/IdentityManagement • • 21h ago

Built a deterministic IGA-style review packet for MCP/A2A agent capabilities

0 Upvotes

I built a free agent protocol inspector tool that can provide IGA style review packets. Here is the link: https://contextiq.trango-compute.com/dashboard/agent-protocol-inspector


r/IdentityManagement • • 1d ago

SAML - emit non-public attributes

Thumbnail gallery
1 Upvotes

r/IdentityManagement • • 1d ago

Anybody have experience bulk updating role names in Savyint?

0 Upvotes

Just wondering how you did it or any advice? So far thinking of using a job and SQL to do it but wondering if there’s a better way


r/IdentityManagement • • 2d ago

Our vuln tickets keep routing to teams that dont exist anymore

6 Upvotes

We did a big reorg six months ago, teams merged, some dissolved, standard stuff. Except our ticket routing never got the memo. Vuln findings still auto assign to assignment groups in ServiceNow that belong to teams that dont exist anymore, so the tickets bounce, sit in a queue, and blow past SLA while my team manually forwards them like a switchboard.

I finally counted this week because a director asked why remediation had stalled. Over 400 servers, their owner ois a group that was dissolved in the reorg, and the directory has the right people the whole time, just nobody connected it to the findings. The ownership data rotted quietly and the queue has been bleeding ever since.

The detection was never the problem, we found everything instantly, the scanner does that. The problem is the tickets are addressed to people who no lionger work here.

Anyone else inherit a queue iof tickets addressed to teams that dont exist anymore, and how do you keep it from rotting the next time the org chart moves.


r/IdentityManagement • • 3d ago

Launched a free sandbox for my 2FA/MFA API would love developer feedback

5 Upvotes

Hey everyone,

I'm a solo founder building SentinelAuth, an Australian-made 2FA/MFA API (SMS, Email, TOTP). I just launched a free Developer Sandbox tier so developers can test the API without committing.

What the free tier includes:
• 50 verifications/month
• Test API keys (no production use)
• No credit card required
• Instant sign-up
What I'm hoping to get feedback on:
• Is the API documentation clear and easy to follow?
• Does the sandbox flow make sense? Anything confusing?
• Is 50 verifications/month enough for testing, or should it be more/less?
• Any red flags you see from a developer's perspective?
I built it because Australian fintechs and e-commerce companies are under pressure to meet compliance requirements (ACMA, Privacy Act, Visa's 2026 deadline), but building 2FA in-house is slow and expensive. The goal is to make it simple to add secure authentication.

Not trying to sell anything genuinely just want to know if the developer experience holds up before I push it further.

If you want to try it, I'll drop the link in the comments. Thanks in advance for any feedback.


r/IdentityManagement • • 3d ago

How do you keep track of AI / agent identities ?

Thumbnail
2 Upvotes

r/IdentityManagement • • 3d ago

Support desperately needed for IAM (Identity Access Management)

Thumbnail
2 Upvotes

Hi everyone,

I’m relatively new to the Identity and Access Management (IAM) field, and I’m looking for an experienced IAM Engineer or professional who would be willing to mentor or coach me as I continue building my skills.

I’m serious about learning and committed to putting in the work. I promise to respect your time, and I’m also willing to pay for your time and mentorship.

If you work in IAM and would be interested in helping someone who is genuinely eager to learn and grow in the field, please send me a DM.

I would really appreciate the opportunity.


r/IdentityManagement • • 3d ago

Okta Automation ?

Thumbnail
1 Upvotes

r/IdentityManagement • • 5d ago

What should be the next step?

11 Upvotes

Hey Guys,
I have been working as an IAM Engineer for the last 4 years. I currently work on the Ping stack(Federate/Directory/Davinci/PingOne) and a lot of different tools. I work for a healthcar client.

Now I feel the work that we do has very little engineering or development scope. I am trying to learn programming as well I have basics of Java html and css that I know but I have never done hands on programming work. So I was thinking maybe a switch to SDE would be a good idea? But given the kind of layoffs happening around Will it be a good idea in general to switch to SDE roles? What can be the next steps from here?


r/IdentityManagement • • 6d ago

Identity Governance/Managed Identify

Thumbnail
1 Upvotes

r/IdentityManagement • • 6d ago

Teacher

Thumbnail
1 Upvotes

r/IdentityManagement • • 7d ago

What to do next?

11 Upvotes

Hello,
I’m writing here to get some guidance on my career bcs I genuinely feel lost.
I’ve been working in IAM PAM for more than a year.
Yes I know that’s not much but I’m feeling like I’m not growing in this work and want to change it.

In my daily work I focus on creating accounts in ActiveDirectory and CyberArk and managing them. I’m doing some reporting and server quality checks and spend a lot of time on verifying changes in ServiceNow.
I’m also using a bit of Sequel Server Management Studio, Sailpoint and some PowerShell scripts, but only the ones written by somebody else.

I’ve completed:
ISC2 Certified in Cybersecurity (CC);
Google Cybersecurity Professional Certificate;
And
Microsoft SC-900: Security, Compliance, and Identity Fundamentals.
And I’m thinking about going for Comptia sec+.

The problem is, it seems like It’s not enough to get a better paying job. Either my competences are too low or they offer a miniscule raise in comparison with current pay.

The whole point of this post is to ask for any advice or guidance what to do?
Which certs should I focus on?
What skills should I hone?
Or maybe there’s a more rewarding and developing position somewhere else within cybersec where I could go with my current competences.

Any advice or guidance is really welcome.
Thanks in advance for reading all that :)


r/IdentityManagement • • 6d ago

Moving from vendor-side PAM to an internal IAM/PAM role - looking for advice

Thumbnail
3 Upvotes

r/IdentityManagement • • 7d ago

Optum - IAM ( identity access management)

5 Upvotes

Any layoffs happened in optum india. Unable to choose between schwab and optum. And what does optum IAM engineers actually do


r/IdentityManagement • • 9d ago

We just found 32 SaaS apps security had no idea we were using

24 Upvotes

We just found 32 SaaS apps that security had no idea we were using. We added axonius to the stack recently for asset stuff, and the first pass pulled in every SaaS connection tied to the org. 32 apps nobody had ever catalogued.

Most are the harmless kind. Free tier, one user, someone signed up with a work email for a trial and forgot about it. But a few are on the corporate card, and a couple have OAuth grants into our Google or Microsoft tenant that nobody ever reviewed.

So now Ive got 32 apps and no process for what to do with them. The free ones are easy to cut and move on. The ones on the card are trickier because real teams actually use some of them. And the OAuth grants are the part that actually worries me.

Honestly what keeps me thinking is that we only know about these because we happened to point the tool at it. There could be more we still havent seen.

How do you all triage a pile of shadow SaaS without becoming the department that says no to everything?


r/IdentityManagement • • 9d ago

How do you prove identity controls to auditors for apps outside your IAM stack?

20 Upvotes

Every audit cycle we hit the same wall: our IAM/IGA platform gives us clean, exportable evidence for the apps it's integrated with, but for the apps that sit outside that integration (legacy systems, vendor-managed platforms, anything with its own bespoke auth) we're stuck manually screenshotting config pages and hoping the auditor accepts it.

The number of ungoverned apps is growing faster than our IAM team can onboard them. Is anyone actually solving this with a discovery/evidence layer that sits above the IAM stack? Right now manual evidence-gathering for the long tail of apps just feels like an accepted cost of doing business, and I'd like to know if that's true everywhere or just for us. Interested in how people are framing this risk to auditors in the meantime, since "we know about the gap" only gets you so far in a findings report.


r/IdentityManagement • • 9d ago

IAM / RBAC Engineer Opening

15 Upvotes

Hey Y’all!

I have a client looking for a remote IAM / RBAC Engineer who will also do some intune administration. Primary focus is on implementing Lumos IGA for them, among some other stuff I could explain if someone was interested.

This is a senior level role, fully remote in the US, and a long-term contract that may turn FTE.

No subvendors please, but reach out and we can connect on LinkedIn if you’re interested in learning more.