15 articles in the Identity Governance track of the Deep Trust Governance Series.
The post-incident investigation produced a finding that was uncomfortable in its specificity: the attacker had navigated the environment with a precision that suggested d…
The conditional access policy was designed to enforce authentication requirements based on user context: stronger authentication when accessing from unusual locations, ad…
Identity governance programs are designed around formal access requests: a user submits a request, the request is approved by the appropriate authority, and the access is…
An orphaned account is an account in an organizational system with no current, identifiable owner — no active employee, no active contractor, no active vendor relationshi…
Privilege creep is the gradual accumulation of access rights by users who move through roles, projects, and responsibilities over time. Each addition is individually just…
Enterprise SaaS environments accumulate roles faster than any identity governance program was designed to manage. Every SaaS application has its own role model.
The zero trust market is worth billions of dollars. Vendors offer zero trust platforms, zero trust network access, zero trust architecture solutions.
Identity federation allows users to authenticate with one identity provider and access resources across multiple systems and organizations. It is one of the most signific…
Enterprise identity governance was built on the premise that identity is centralized: a directory, an IAM platform, a set of federation standards.
Privilege escalation is typically framed as a security concern about attackers gaining access beyond what they were authorized to have. The more common and more difficult…
Organizations have built excellent infrastructure for giving people access. Joining triggers automation: account creation, group assignment, license provisioning, entitle…
Every system addition is a potential privileged access expansion. Every cloud resource provisioned, every SaaS application deployed, every microservice added creates a ne…
Service accounts are the identity type that enterprise governance programs most consistently underaddress. Human accounts are governed by HR processes, access reviews, an…
Least privilege is one of the most widely adopted access control principles in enterprise security. It is documented in every security framework, required by every compli…
Access controls are designed to enforce defined permissions at a point in time. They do not prevent permissions from accumulating over time as users change roles, join pr…