Identity at the Center

Identity at the Center

Identity at the Center
Држава Сједињене Државе
Жанрови Технологија
Језик EN
Епизоде 447
Последња 14.09.2026

Identity at the Center is a weekly podcast about identity security within identity and access management (IAM). Hosts Jim McDonald and Jeff Steadman draw on decades of real-world IAM experience to discuss news, topics, and guests from the identity management industry. Each episode explores questions such as who has access to what and why that access matters. The show is aimed at identity professionals and others interested in identity security.

Епизоде

  • #447 - Authenticate 2026 Preview with Andi Hindle 14.09.2026 1ч 16мин
    Jeff Steadman sits down with Andi Hindle, conference chair for Authenticate 2026, for a preview of this year's event. Making his seventh appearance on the show, Andi walks through how Authenticate has evolved since its founding alongside Identiverse and outlines six major topic areas shaping the 2026 agenda, including passkeys in practice, regulatory pressures, security and standards architecture, digital identity wallets, and non-human authentication. The conversation moves into hardware-based identity for retail and industrial settings, age verification challenges, and a detour into 3D printing and supply chain assurance. Jeff and Andi dig into continuous identity and zero standing privilege, the shift toward non-human traffic dominating infrastructure requests, and how agentic AI is forcing organizations to rethink authorization and human-in-the-loop decisions. They close with privacy and consent questions for non-human identities, thoughts on where authentication and authorization standards are headed, and a lighter look at Authenticate team traditions and sci-fi recommendations.Connect with Andi: https://www.linkedin.com/in/ahindle/Impact of GDPR on Identity and Access Management by Andi Hindle: https://bok.idpro.org/article/id/24/Learn more about FIDO Authenticate 2026: https://authenticatecon.com/event/authenticate-u-s-2026/Non-FIDO members can use the code IDAC15 to save 15% on their in-person conference pass.Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:10 - Introduction and discount code rundown for upcoming conferences01:10 - Andi Hindle returns for his seventh appearance01:29 - Favorite episode banter and the running Andrew Shikiar joke03:08 - Origins of Authenticate and its relationship with Identiverse09:01 - Passkeys are solved, so what comes next09:53 - Lessons learned building the Authenticate agenda12:59 - The scale of effort behind running Authenticate15:29 - Adjacent topics expanding beyond the core passkeys mission16:09 - Six major topic areas planned for Authenticate 202622:13 - Identity as the foundation for everything digital23:14 - Hardware identity and non-human authentication24:53 - Retail tokens, badges, and age verification use cases28:36 - Replacing things only when the replacement is actually better29:41 - A detour into 3D printing and personal satisfaction31:39 - 3D printing, supply chain assurance, and identity problems36:38 - Introducing continuous identity37:28 - Zero standing privilege and why it matters now40:46 - The human user as the infrastructure edge case45:16 - Speed, scale, and the limits of human in the loop46:11 - Setting red lines for agentic risk50:56 - Privacy and consent questions for non-human identities56:51 - Anonymization, data logging, and GDPR parallels59:51 - A GDPR and IAM resource from the IDPro Body of Knowledge1:00:26 - What Authenticate topics might look like three years out1:04:59 - Why accounts may not make sense for agents1:06:49 - Authorization as the next hard problem to solve1:08:20 - Inside jokes from the Authenticate organizing team1:09:30 - The story behind Andi's favorite Britishism1:10:38 - Book and media recommendations1:14:39 - Closing thoughts and sign-offIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Andi Hindle, Authenticate 2026, FIDO Alliance, passkeys, identity verification, identity wallets, continuous identity, zero standing privilege, agentic identity, non-human identity, authorization, shared signals, GDPR, IDPro, Identiverse, age verification, hardware authentication
  • #446 - Rethinking Identity for AI Agents with Rick Scot 07.09.2026 1ч 10мин
    Rick Scot, Global CIO and CISO at Elevate Textiles, joins Jim and Jeff to talk about how he went from leading a data team to holding both the CIO and CISO seats at a global manufacturing company. Rick shares the moment that pulled him into security, how his tight-knit Charlotte cyber community shapes his thinking, and how he balances speed and control when the two roles pull in different directions. The conversation moves into identity for the age of AI agents: whether an agent is a human or non-human identity (Rick argues it's neither), who should own accountability when something goes wrong, and how session termination has to extend beyond turning off an account. Rick also digs into shadow AI, the real cost of tokens versus flat-rate licenses, and how he evaluates new identity technology against his organization's size and risk appetite. The episode closes with what excites and concerns him most about AI over the next three to five years, his advice for identity practitioners, and a lighter look at hobbies people wouldn't expect.Connect with Rick: https://www.linkedin.com/in/rickscot/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Intro and community shoutouts07:06 - Introducing Rick Scot, Global CIO and CISO at Elevate Textiles07:46 - How Rick got into cybersecurity09:22 - Charlotte's tight-knit cyber community11:18 - The moment that made security the focus13:06 - Balancing the CIO and CISO roles16:17 - What "Identity at the Center" means to Rick19:26 - Where to start when building an IAM program23:29 - Balancing risk and innovation with AI27:46 - Who should own accountability for an AI agent29:38 - A hierarchy for agent identities33:31 - Terminating access and sessions, not just accounts36:25 - Dealing with shadow AI41:37 - Standing up a governance process for new AI projects43:19 - Evaluating new identity technology and token costs48:51 - Training and governance around AI usage52:22 - Established vendors versus disruptive startups56:56 - Looking three to five years ahead1:00:20 - Advice for identity practitioners1:01:41 - Lightning round: hobbies and surprises1:08:40 - Closing and where to find RickIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Rick Scot, Elevate Textiles, CIO, CISO, identity and access management, IAM program, identity governance, AI agents, non-human identity, agentic identity, shadow AI, session management, offboarding, token costs, Charlotte cybersecurity community, identity leadership
  • #445 - Sponsor Spotlight - Twine Security 02.09.2026 52мин
    Jim McDonald hosts this Sponsor Spotlight episode of Identity at the Center, made possible with support from Twine Security. Jim is joined by Benny Porat, co-founder and CEO of Twine Security and previously co-founder and CTO of Claroty. Benny shares how his cybersecurity background led him into identity and explains the concept of the "execution gap," the space where identity teams are accountable for outcomes but lack the full business context to act on their own. The conversation explores Twine Security's AI digital employee, Alex, and how it differs from traditional automation and RPA, where AI-driven execution fits best within identity operations today, and the balance between the parts of a task AI can handle easily versus the harder remaining work. Benny and Jim also dig into governance and trust, including why least privilege matters even more for AI agents and non-human identities, how organizations typically start with read-only access before expanding permissions, and how access reviews and recertification could evolve as AI takes on more of the process. They close with reflections on measuring success, how the identity practitioner's role changes as more execution shifts to AI, and a lighter round on what a personal AI digital employee might look like.Connect with Benny: https://www.linkedin.com/in/bennyporat/Learn more about Twine Security: https://www.twinesecurity.com/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at idacpodcast.com00:00 - Introduction and welcoming Benny Porat, co-founder and CEO of Twine Security00:52 - How Benny found his way into identity and access management02:21 - The origin of the name Twine03:28 - Defining the IAM execution gap05:53 - AI digital employees versus RPA and automation08:07 - Where AI digital employees are best suited today09:45 - Why AI is strong at eighty percent and what makes the rest difficult14:45 - Where a digital employee like Alex fits within identity operations18:43 - Trust, governance, and giving AI agents the right permissions21:42 - Applying least privilege to AI agents and non-human identities25:19 - How organizations start using Alex, from read-only to full execution30:27 - Rethinking the role of access reviews with AI involved33:14 - Measuring efficiency gains and revocation rate improvements36:00 - Addressing concerns about AI replacing IAM practitioners39:12 - How customers define and measure success44:15 - How the practitioner's day-to-day role changes with AI agents47:12 - Closing thoughts and where to learn more47:37 - Lighter note: imagining a personal AI digital employeeKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Benny Porat, Twine Security, Sponsor Spotlight, AI digital employee, Alex, identity and access management, IAM, execution gap, least privilege, access reviews, recertification, agentic AI, non-human identity, NHI, Claroty, IGA, PAM, governance, human in the loop
  • #444 - August 2026 Mailbag 31.08.2026 49мин
    Jeff and Jim open with the unavoidable topic of AI agents and the tension between enabling innovation and governing agent permissions, then run through a packed fall conference schedule. The August mailbag pulls questions from Singapore, Toronto, Prague, Johannesburg, Helsinki, and Seoul. They discuss when externalized authorization makes sense, why passkey recovery can become the weak link in phishing-resistant authentication, what EU digital identity wallets may mean for enterprises, how continuous access evaluation changes the meaning of terminating access, and how to build resilience around a centralized identity provider without creating a second full-scale IdP. The episode closes with a lighter question: if every IAM product needed a giant warning label, what should it say?Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:10 - Welcome and have we talked about AI too much?01:32 - Governing AI agents without becoming the progress prevention department03:50 - Fall conference season and IDPro04:40 - Cybersecurity Summits in Chicago and Atlanta06:40 - SailPoint Navigate, InfoSec World, FIDO Authenticate, and Identiverse DC10:40 - 3D printing, challenge coins, and superfan status11:56 - August mailbag begins12:19 - Singapore: Is externalized authorization ready for mainstream IAM?20:30 - Toronto: Passkeys, account recovery, and help desk social engineering25:55 - Prague: What should enterprises do about EU digital identity wallets?31:44 - Johannesburg: Continuous session revocation and what “terminate access” really means38:04 - Helsinki: Designing identity resilience around a centralized IdP45:23 - Seoul: What warning label should every IAM product have?48:26 - Wrap-up and how to send future mailbag questionsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, August 2026 mailbag, externalized authorization, authorization, policy-based access control, passkeys, account recovery, phishing-resistant authentication, identity verification, EU digital identity wallet, continuous access evaluation, shared signals, session revocation, token revocation, identity resilience, identity provider, disaster recovery, business continuity, AI agents, agentic identity, IDPro, FIDO Authenticate, Identiverse DC, InfoSec World, SailPoint Navigate
  • #443 - Ghosts in the Machine with John Huyette and Omer Arshed 24.08.2026 1ч 13мин
    Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growing risks of AI agents. John introduces five laws for managing AI risk: governability, lineage and integrity, trust boundaries, authority containment, and human impact. The conversation connects those ideas to familiar IAM principles including ownership, auditability, zero trust, least privilege, just-in-time access, privileged access management, and continuous monitoring. They also discuss prompt injection, shadow AI, human accountability, and why organizations should start by building an honest inventory of the AI capabilities already operating in their environments.5 Laws of AI Risk: https://www.linkedin.com/feed/update/urn:li:activity:7487942457075257344/Connect with John: https://www.linkedin.com/in/john-huyette-1373906/Connect with Omer: https://www.linkedin.com/in/omerarshed/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps00:00 Introduction, 3D printing, and conference updates06:58 Introducing John Huyette and Omer Arshed07:52 John’s path from technology risk to AI risk12:11 Omer’s identity origin story13:43 The five laws for managing AI risk18:00 What “ghosts in the machine” means for identity20:17 Governability and ownership of AI identities25:17 Do you know what has access to what?29:43 Applying decades of IAM lessons to AI32:35 Lineage and integrity35:20 Building an AI bill of materials37:12 Trust boundaries and external data38:36 Prompt injection and untrusted content42:48 Applying zero trust principles to AI agents47:26 Authority containment49:56 PAM, least privilege, and just-in-time agent access56:22 Human impact and accountability58:41 Is agentic AI really a new identity problem?01:02:35 Starting with lower-risk AI use cases01:04:21 Where organizations should start01:05:07 Shadow AI and zombie accounts01:07:09 What excuses would an AI give during an access review?01:12:20 Wrap-upKeywordsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, John Huyette, Omer Arshed, RSM, AI risk, AI agents, agentic AI, AI governance, governability, lineage and integrity, trust boundaries, authority containment, human impact, shadow AI, identity governance, IAM, zero trust, privileged access management, PAM, least privilege, just-in-time access, non-human identity, NHI, prompt injection, AI identity, access governance, continuous monitoring
  • #442 - Identiverse 2026 - Identity After Dark with Bravura Security 19.08.2026 1ч 29мин
    Recorded live at Identiverse 2026 in Las Vegas on June 17, Jeff and Jim are joined by Bart Allan, General Manager at Bravura Security, for a live recording with a studio audience. In a late-night talk show format, the three host an open Q&A driven by IAM practitioners in the room. From securing AI identities to whether access reviews are headed the way of the password, this is an unscripted conversation driven by practitioners for practitioners. Topics include identity as a business enabler, zero standing privilege, agentic authentication, standards for AI agents, vendor relationships, the captive customer problem, community, and hiring IAM talent. Thanks to Bravura Security for supporting the Identity at the Center podcast.Connect with Bart: https://www.linkedin.com/in/bartholomewallan/Learn more about Bravura Security: http://bravurasecurity.com/idacConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00:00 Welcome and Introduction00:03:00 AI Identities: Should IAM Teams Panic?00:07:30 Identity as a Business Enabler vs. Cost Center00:24:00 Continuous Identity and the Future of Access Reviews00:35:00 Zero Standing Privilege and JIT Access00:38:00 Standards for Agentic AI00:46:00 Vendor Relationships and the Captive Customer Problem00:55:56 Normalizing Rip and Replace01:01:00 IDPro, Identity Beers, and Building Community01:11:00 Agentic Authentication and Non-Human Identities01:18:00 Hiring IAM Talent01:26:00 Team Diversity and Multiple Perspectives01:27:00 ClosingIdentity at the Center, IDAC, Jeff Steadman, Jim McDonald, Bart Allan, Bravura Security, Identiverse 2026, Identiverse, IAM, identity and access management, identity security, AI identities, agentic identity, agentic authentication, non-human identities, NHI, access reviews, zero standing privilege, JIT access, continuous identity, IGA, vendor selection, identity community, IDPro, IdentiBeer, live podcast
  • #441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer 17.08.2026 37мин
    Live from Identiverse 2026 in Las Vegas, Jeff and Jim sit down with Sachini Siriwardene, winner of this year's Kim Cameron Award, along with Ian Glazer of the Digital Identity Advancement Foundation (DIAF). Sachini shares how she moved from open banking API security into consumer identity work at a bank, and what led her to apply for the award named after identity pioneer Kim Cameron. Ian explains DIAF's mission to remove financial barriers to industry participation and previews the upcoming Vittorio Bertocci award for standards contributors. The conversation covers agentic AI and non-human identity governance, the AuthZen specification, continuous access management, and how practitioners can separate real AI capability from marketing hype. The group also swaps favorite hallway conversations from the show floor, including a discussion on extending the shared signals framework beyond RISC and CAPE, before wrapping with some very Vegas talk about the Sphere.Connect with Sachini: https://www.linkedin.com/in/sachini-siriwardene/Connect with Ian: https://www.linkedin.com/in/iglazer/Learn more about the Digital Identity Advancement Foundation: https://diaf.org/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Cold open and conference banter01:35 - Jim's origin story with identity and Kim Cameron03:22 - Welcoming Sachini Siriwardene and Ian Glazer04:02 - Ian explains the Digital Identity Advancement Foundation05:54 - How Sachini got into identity through open banking08:46 - The moment identity clicked as mission critical09:47 - Agentic AI and non-human identity governance11:25 - Optimist or pessimist on AI and the job market14:45 - Applying for and winning the Kim Cameron Award15:41 - How DIAF selects award recipients17:21 - Standout sessions and the AuthZen specification18:36 - First impressions of Identiverse20:01 - Advice for future award applicants22:03 - Managing agentic identity in practice23:16 - Separating AI hype from real capability24:32 - Where the identity industry can improve27:08 - Acting fast without chasing hype28:05 - Favorite hallway conversations29:23 - Extending the shared signals framework30:39 - A D&D themed conference talk31:08 - Vegas talk and the Sphere experience34:19 - Wrap up and how to support DIAFIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sachini Siriwardene, Ian Glazer, Identiverse 2026, Kim Cameron Award, Vittorio Bertocci Award, Digital Identity Advancement Foundation, DIAF, agentic AI, non-human identity, AuthZen, continuous access management, open banking, OAuth2, FAPI, shared signals framework
  • #440 - Identiverse 2026 - Mike Kiser 10.08.2026 52мин
    Recorded live at Identiverse 2026, Jeff and Jim sit down with returning guest Mike Kiser, Director of Strategy and Standards at SailPoint, for a wide-ranging conversation that spans two of the standards world's most active frontiers. The first half breaks down C2PA, the Coalition for Content Provenance and Authenticity, explaining how it differs from digital watermarking, how metadata and cryptographic signatures build a chain of custody for media, and why this work connects directly back to identity. The conversation then shifts to AI agents and the challenge of defining and governing intent, with Mike drawing an extended analogy to the early, under-regulated days of space exploration. The episode closes with reflections on the value of hallway conversations and community at Identiverse.Connect with Mike: https://www.linkedin.com/in/mike-kiser/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 Introduction from Identiverse 202601:00 Mike previews his two Identiverse talks01:35 What C2PA is and how chain of custody works06:51 Watermarks versus C2PA explained10:06 Why content provenance matters for identity14:22 Is C2PA a standard or a working group16:23 The SpaceX and space debris analogy for agent intent20:13 Governing agent publishing without stifling innovation22:00 Action Identification Theory and the how versus the why27:47 Can an AI actually have intent32:34 Why people humanize and fall in love with chatbots38:37 The case for locking down intent early39:39 Does intent change, or is it a new intent46:19 Favorite hallway conversations at Identiverse51:03 Wrap up and where to find MikeIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Kiser, SailPoint, C2PA, Content Provenance and Authenticity, Identiverse 2026, Shared Signals Framework, AI Agents, Agentic Identity, Digital Watermarking, Decentralized Identity Foundation, Intent-Based Access Control
  • #439 - Sponsor Spotlight - Tuebora 05.08.2026 54мин
    This Sponsor Spotlight episode, made possible with support from Tuebora, features Jim McDonald in conversation with Sanjay Nadimpalli, CEO and founder of Tuebora. Sanjay shares his path into identity beginning as one of the first engineers at Aveksa, then discusses how intelligence is reshaping identity governance and administration by replacing static configuration with continuous, context-aware decision making. The conversation covers the concept of governance debt, how AI can interpret organizational intent expressed in natural language, and where human oversight remains essential. The discussion also explores governance of agentic identities, including how they differ from traditional service accounts, the challenges posed by their ephemeral and dynamic nature, and the policy-driven frameworks needed to manage them. Sanjay closes with a reflection on what identity practitioners should be thinking about for the next few years.Connect with Sanjay: https://www.linkedin.com/in/sanjaynadimpalli/Learn more about Tuebora: https://www.tuebora.com/idacConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00:00 - Introduction and welcome00:00:56 - How Sanjay got into identity00:02:40 - Full circle moment with Deepak Taneja and Zilla00:03:05 - What Tuebora does00:04:14 - The story behind the name Tuebora00:05:20 - Can intelligence replace configuration00:10:05 - Why static configuration falls short today00:14:52 - Customer frustrations with legacy environments00:21:09 - Comparing this to everyday AI tool use00:23:31 - How intelligence drives outcomes00:28:42 - Maintaining security control alongside AI00:32:38 - The orchestra analogy for AI and human roles00:35:28 - Introducing agentic identity governance00:36:10 - Why agentic identities differ from service accounts00:42:20 - The scale problem of agentic identities00:44:00 - Building a framework for agent governance00:47:35 - Closing advice for identity practitioners00:52:06 - Where to find Tuebora nextIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sanjay Nadimpalli, Tuebora, Sponsor Spotlight, identity governance, IGA, agentic identity, AI agents, governance debt, explainability, IAM, access governance, non-human identity, Aveksa, continuous governance, identity governance and administration
  • #438 - Identiverse 2026 - Sean O'Dell 03.08.2026 39мин
    Recorded live at Identiverse 2026 in Las Vegas, Jeff sits down with Decoded co-host Sean O'Dell for a wide-ranging state of the union on continuous identity, shared signals, and the identity questions AI keeps raising. Sean shares what he is hearing on the ground about the upcoming transaction tokens spec, why continuous identity has moved from concept to mainstream adoption, and how shared signals are expanding into commerce. The conversation shifts to AI: the real cost of securing it, why model provenance matters, and the murky question of who is on the hook when an AI agent makes an expensive or harmful decision on your behalf. They debate companion agents, consent versus power of attorney, and whether the identity industry even owns this problem. Sean closes with a simple piece of advice for anyone feeling overwhelmed by AI right now.Connect with Sean: https://www.linkedin.com/in/seanodentity/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps:00:00 Intro and a Decoded update00:44 Transaction tokens spec preview01:51 State of the union on continuous identity03:39 The questions organizations are asking04:34 Is it still all about the data05:07 Shared signals framework moving into commerce06:40 Is AI a fad at Identiverse this year07:11 The real cost of securing AI08:00 Model provenance and indemnity09:39 IAM for AI versus AI for IAM10:18 Trusting agents to act without oversight14:51 Assigning authority to the who and the what16:13 The cruise booking example and who is on the hook20:16 Companion agents, consent, and power of attorney23:00 Does the identity industry own this problem25:00 Relationship and intent as the real issue28:03 Could an insurance market emerge for agentic AI29:18 An access review scenario gone wrong30:41 Small specialized language models for identity tasks32:11 Favorite hallway conversations at Identiverse36:05 Wrap up and words of wisdom on AI FOMOKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sean O'Dell, Decoded, Identiverse 2026, continuous identity, transaction tokens, shared signals framework, agentic AI, AI security, model provenance, IAM, digital identity, identity and access management
  • #437 - Identiverse 2026 - Pam Dingle 27.07.2026 55мин
    Live from the IDAC booth at Identiverse 2026, Jeff and Jim sit down with Pam Dingle, Director of Identity Standards at Microsoft, to unpack agentic identity. Pam breaks down assistive versus autonomous agents, walks through where standards like SPIFFE and OAuth hold up, and explains the difference between delegation, impersonation, and partition. The conversation also covers credential discovery risk, shared signals and revocation, what enterprises should prioritize now, and the value of hallway conversations at Identiverse.Connect with Pam: https://www.linkedin.com/in/pameladingle/OAuth Actor Profile for Delegation: https://www.ietf.org/archive/id/draft-mcguinness-oauth-actor-profile-00.htmlConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps:00:00 Intro and Identiverse 2026 vibes04:01 Defining agentic identity07:06 Has the earth really shifted11:38 An old problem thats been bejeweled15:13 From Nulli Secundus to Microsoft16:00 How standards are holding up19:27 Client ID metadata and just in time trust21:41 Shared signals and the revocation problem24:43 Deploying agentic identity at scale28:11 Registries at scale29:04 Delegation authorization and attenuation32:33 Delegation vs impersonation vs partition36:03 The one thing you can fix right now37:56 Favorite hallway conversation42:29 The solar system of hallway conversations45:51 Remembering Kim Cameron48:00 New voices to watch52:08 Wrap up and thank youKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Pam Dingle, Pamela Dingle, Microsoft, Identiverse 2026, agentic identity, agentic AI, non-human identity, delegation, impersonation, SPIFFE, OAuth, identity standards, IAM, digital identity, workload identity
  • #436 - Sponsor Spotlight - P0 Security 22.07.2026 46мин
    In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, covering how it applies to humans, non-human identities, and AI agents alike. The conversation digs into the difference between authentication and authorization, why zero standing privilege is more achievable now than before agentic adoption took hold, and how dynamic, evidence-based policies can reduce reliance on manual approvals. Greg also shares real examples, including row-level access control for data lakes and a CRM mishap that shows how easily agents can misinterpret intent. The episode closes with a look at where enterprise AI agent governance may be headed over the next few years, plus a lighter conversation about explaining IAM to a 10-year-old. This episode is made possible through the generous support of P0 Security as part of IDAC's nonprofit Sponsor Spotlight series. Learn more at p0.dev/idac.Connect with Greg (Gergely): https://www.linkedin.com/in/gergely-danyi/Learn more about P0: https://p0.dev/idac/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Introduction and sponsor acknowledgment01:13 - Greg Danyi's path into IAM02:18 - What P0 Security solves for03:21 - Where P0 fits versus PAM and IGA04:46 - Agentic identity as a driver of adoption05:27 - MCP servers and unpredictable agent actions07:10 - Defining runtime access control08:50 - How authentication and authorization work together09:07 - Standing access versus expressed intent10:16 - Zero standing privilege in practice12:27 - Agentic identity as a distinct identity class19:24 - Automated evidence for approvals20:42 - Walking through a support agent example22:13 - Row-level access control for data lakes23:35 - Dynamic roles explained29:55 - CRUD risks and underestimated concerns31:32 - Human intent and giving agents clear direction36:32 - Where enterprise AI agent governance is headed39:36 - Advice for CIOs and CISOs getting started41:15 - Explaining IAM to a 10-year-old42:29 - Board games, dice, and calculated risk44:00 - Closing thoughts and where to learn moreKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Greg Danyi, P0 Security, runtime access control, agentic identity, zero standing privilege, non-human identity, authentication, authorization, IAM podcast
  • #435 - Majority Rules: IDAC Live at Identiverse 2026 20.07.2026 26мин
    Jim McDonald and Jeff Steadman took the Identity at the Center podcast live at Identiverse 2026 in Las Vegas for a crowd-sourced game show called Majority Rules. Identity professionals competed in real time, picking answers to IAM and conference questions in a race to predict the majority. With a prize pool of over $5,000 for the top ten scorers, the stakes were high and the honesty was brutal. The episode also marks a milestone: IDAC hitting two million downloads. Thanks to Shirley Han and the CyberRisk Alliance team, and to sponsors Hyper, Red Block, SlashId, Rubrik, Stratacity, FusionAuth, Nexus, CrowdStrike, Hush Security, PlainId, RSM, and CyberRisk Alliance.Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com0:00 Introduction and Two Million Downloads Milestone1:00 Sponsor and Event Team Recognition3:00 How to Play Majority Rules4:00 Warm-Up Round Begins6:00 Battle Royale Mode Explained8:30 Decentralized Identity and the LDAP Reality10:30 Las Vegas Evening Entertainment11:30 Top Identity Trends at Identiverse 202612:30 Access Certification and the 4:55 PM Click13:30 Classic Vegas and Expo Hall Favorites14:50 PAM Strategies and the Post-it Note16:00 Conference Navigation and Footwear Survival18:00 Identity Log Monitoring Chaos19:30 Hallway Track Conversations20:30 Cloud Entitlements and Everyone Gets Root21:00 Sleep Habits at a Security Conference22:00 Business Cards in 202623:00 Legacy App Strategy and Thoughts and Prayers24:45 Las Vegas Dining Preferences25:30 Winners Announced and ClosingKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Identiverse, Identiverse 2026, Majority Rules, live event, game show, IAM, identity and access management, decentralized identity, LDAP, SSO, PAM, privileged access management, cloud entitlements, ISPM, access certification, Las Vegas, cybersecurity, conference
  • #434 - Identiverse 2026 - IdentiBeer Las Vegas 13.07.2026 42мин
    Recorded the night before Identiverse 2026 at BrewDog in Las Vegas, Jeff hosts a roundtable of IdentiBeer chapter leaders and community members from around the world. Espen Bago (Oslo), Marco Venuti (Rome and Milan), Heiko Klarl (Munich), Craig Ramsay (Nashville), Tina Srivastava and Elie Azerad (San Francisco), Bertrand Carlier (Paris, in planning), Ole Shved (Detroit, forming), and Roland Baum (Frankfurt) share what makes IdentiBeer work, how chapters get started, and what draws people in. First-time Identiverse attendee Varshith Reddy joins mid-conversation for some live conference tips. The group celebrates going 35 minutes without mentioning AI and closes with everyone's drink of choice and an impromptu MFA rap.Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com0:00 Welcome and intro0:41 What is IdentiBeer? Espen Bago explains2:31 Marco Venuti and the Italian chapters5:07 Could there be an IdentiBeer conference?6:03 Heiko Klarl and IdentiBeer Munich7:09 Craig Ramsay and the new Nashville chapter9:53 Beer is just clickbait and vendor neutrality12:45 Tina Srivastava and the IDPro Slack connection13:18 Ole Shved and the future Detroit chapter14:14 Advice for new chapter organizers16:33 Keep the momentum: do another one soon17:01 What draws people to IdentiBeer?17:37 The IdentiBeer charter and inclusivity18:20 Elie Azerad and the San Francisco chapter21:08 Tina and the South Bay satellite idea25:50 Bertrand Carlier and plans for Paris29:31 Varshith Reddy: tips for first-time Identiverse attendees34:12 35 minutes without saying AI36:20 Roland Baum and the Frankfurt Identivier39:06 What is your drink of choice?40:48 Tina's MFA rap and closing thoughtsKeywords: IdentiBeer, Identiverse 2026, IAM community, Identity and Access Management, Jeff Steadman, Jim McDonald, IDAC, Identity at the Center, Espen Bago, Marco Venuti, Heiko Klarl, Craig Ramsay, Tina Srivastava, Elie Azerad, Bertrand Carlier, Ole Shved, Roland Baum, Varshith Reddy, IDPro, community building, vendor neutral, IAM networking, Las Vegas
  • #433 - Sponsor Spotlight - FusionAuth 08.07.2026 55мин
    Jim McDonald sits down with Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, for an in-depth conversation on customer identity and access management. Dan explains how FusionAuth views authentication as the front door to any application and why control, deployment flexibility, and developer ownership are central to their approach. The discussion covers progressive registration, friction vs. usability, customization options, identity standards, the build vs. buy debate, risk-based MFA, and how AI agents will shape the future of customer identity. This episode and others is made possible with support from FusionAuth. Learn more at fusionauth.io/idac.Connect with Dan: https://www.linkedin.com/in/mooreds/Learn more about FusionAuth: https://fusionauth.io/idacBlog article mentioned: https://bobdahacker.com/blog/fifa-hackConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00:00 Introduction00:01:18 What is FusionAuth?00:03:15 Dan's identity origin story00:04:19 Developer focus and ethos00:06:54 Authentication as the front door00:10:00 Balancing friction and usability00:15:24 Customization in CIAM00:18:10 What sets FusionAuth apart00:20:33 FusionAuth's customer sweet spot00:25:48 Deployment flexibility and the control spectrum00:30:19 Common challenges in CIAM00:33:06 Build vs. buy for authentication00:36:00 Omni-channel authentication00:40:27 Why identity standards matter00:42:07 Risk-based MFA and intelligent challenges00:45:00 AI agents and the future of CIAM00:49:23 Closing thoughts00:51:35 Vacation roundupKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Moore, FusionAuth, CIAM, customer identity, authentication, access management, IAM, identity standards, MFA, risk-based authentication, progressive registration, OAuth, OIDC, SAML, AI agents, deployment flexibility, build vs buy, Sponsor Spotlight
  • #432 - IdentiBeer Rome and 3 Courses of IAM with Alessandro Piscopo 06.07.2026 44мин
    Jim McDonald takes the Identity at the Center podcast on the road to Rome, Italy, for a special two-part episode. The first segment is an IdentiBeer roundup where Jim gathers quick-fire takes from practitioners in the Italian IAM community, including Andrea Rossi and Alessandro Piscopo of IAMONES and Marco Venuti of Thales on the biggest trends shaping identity today. The second segment is a three-course meal where Jim sits down with Alessandro Piscopo, Head of AI and Co-founder at IAMONES, to discuss AI and identity over food and wine.Across a seafood starter, scialatielli alla pescatora, and tiramisu, the conversation covers the history of AI in identity, why LLMs represent a revolution rather than an evolution, the AI-first product philosophy versus retrofitting AI onto legacy systems, compute and architecture constraints facing large language models, and what life looks like for the IAM practitioner in 2030. Alessandro envisions an identity equivalent of Claude Code, a specialized AI tool that democratizes identity expertise the way coding assistants have transformed software development.0:00 Intro and IdentiBeer Rome roundup7:01 Alessandro on AI for IAM vs. IAM for AI12:00 Three-course dinner begins - Course 1: Seafood starter14:09 History of AI in identity, from ML models to LLMs17:51 Course 2: Scialatielli alla pescatora and Falanghina wine19:56 AI-first products vs. AI layered onto legacy systems22:00 Transition period and the new world of identity24:04 The ChatGPT moment vs. the iPhone moment27:05 Compute constraints, energy costs, and architecture breakthroughs30:46 Smaller models and cost-efficiency tradeoffs32:35 Course 3: Tiramisu, baba, and espresso33:00 Life as an IAM practitioner in 203035:19 Claude Code for IAM and democratizing identity tools37:24 App store ecosystem analogy for AI platforms43:07 Closing thoughtsKeywords: IAM, identity and access management, AI for IAM, IAM for AI, agentic AI, non-human identity, IGA, LLMs, large language models, AI-first, machine learning, Alessandro Piscopo, IAMONES, Jim McDonald, Jeff Steadman, Identity at the Center, IDAC, IdentiBeer, Rome, Italy, Marco Venuti, Thales, Andrea Rossi, agentic identity, transformer architecture, compute efficiency, identity practitioner 2030, Claude Code for IAM, identity democratization, Identiverse, European Identity Conference
  • #431 - Tectonic Shifts in Identity Security with Martin Kuppinger 29.06.2026 1ч 1мин
    Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Kuppinger, founder and distinguished analyst at KuppingerCole. They dig into the tectonic shifts AI is bringing to identity and security, the AI security fabric framework, why decentralized identity thinking may be essential for governing the agentic mesh, the ongoing debate over NHI terminology, what organizations can do tactically today, and what concerns Martin most about where the industry is heading by 2030.Connect with Martin: https://www.linkedin.com/in/martinkuppinger/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 Introduction and Welcome00:50 What a Distinguished Analyst Does01:37 EIC 2026: Thought Leadership and Best Practice04:17 Agentic AI: Non-Directed, Non-Deterministic Identity08:22 Speed of Change: Tactical Now, Strategic Later12:34 The AI Security Fabric: Five Capability Blocks15:10 Identity Fabric Origins and Market Growth18:27 Discovery as the Foundation for Governance19:48 Governance, Explainability, and Organizational Gaps22:00 Agent Lineage and Rethinking NHI Terminology23:50 LLMs vs. Small Language Models26:23 Is Agentic Identity a Genuinely New Problem?32:29 Humanoid Robots and the Limits of AI Reasoning37:05 Decentralized Identity, Trust Frameworks, and Signals41:07 Identity Verification and Consent for Agents48:42 What Concerns Martin About the Future of Identity50:34 Favorite AI Application: Assisted Driving55:00 Self-Driving Cars, Data, and Personal PrivacyKeywords: Martin Kuppinger, KuppingerCole, EIC 2026, EIC Berlin, agentic AI, AI security fabric, identity fabric, decentralized identity, AI governance, non-human identity, autonomous identity, dependent identity, agent lineage, explainability, MCP server, small language models, verifiable credentials, risk-based authorization, OT security, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity security
  • #430 - AI for IAM and IAM for AI with Martin Sandren 22.06.2026 59мин
    Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Sandren, IAM Product Lead at IKEA, for a wide-ranging conversation covering nearly every corner of modern identity security. Martin shares what has changed since his first IDAC appearance on episode 293, including the rise of AI, growing interest in digital sovereignty, and the maturing shared signals framework. The conversation moves through risk-based defense in depth, tiered MFA rollout strategies, session management, and the real challenge of trusting AI to make security decisions. Martin introduces identity dark matter and explains how IVIP can surface the 95-plus percent of applications that never reach an IGA system. The episode also covers shadow AI, MCP server risks, the SaaSpocalypse debate, and the EU AI Act. It closes on a grounded note: solar panels.Connect with Martin: https://www.linkedin.com/in/martinsandren/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTIMESTAMPS00:00 Welcome and EIC 2026 intro01:47 What has changed in two years: AI, sovereignty, shared signals03:06 Martin's EIC presentations: AI for IAM and IAM for AI04:46 Can you prioritize one direction over the other?07:13 What would it take to trust AI making identity decisions?09:32 AI-enhanced detection and risk-based session management13:07 Session invalidation and the shared signals framework14:11 Defense in depth and right-sizing privileges18:25 MFA today: any MFA versus phish-resistant MFA19:17 AI chatbots, enterprise LLMs, and shadow AI23:11 MCP servers, NHI risk, and return on risk thinking27:00 AI configuring IAM systems: how close are we?31:30 LLM costs, the SaaSpocalypse, and enterprise AI futures40:10 Identity dark matter and the IVIP concept44:16 CMDB versus IVIP: do you need both?46:18 The EU AI Act and building an AI governance registry49:18 Where to start: get your AI inventory in place first50:00 Closing thoughts and the solar panel tangentKEYWORDSAI for IAM, IAM for AI, identity dark matter, IVIP, IGA, shared signals framework, phish-resistant MFA, defense in depth, session management, MCP servers, NHI, shadow AI, SaaSpocalypse, EU AI Act, AI governance, zero standing privilege, EIC 2026, IKEA, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Martin Sandren
  • #429 - Sponsor Spotlight - SailPoint 17.06.2026 1ч 7мин
    This episode is presented courtesy of SailPoint. Rob Sebaugh, Senior Identity Strategist at SailPoint, joins Jeff and Jim for a wide-ranging conversation on the past, present, and future of identity governance. Rob brings more than two decades of practitioner experience to the table, including 16 years running large-scale identity programs before making the move to the vendor side. The conversation covers what identity governance means today, why it must move to the forefront rather than be treated as an afterthought in an agentic world, and how organizations need to think fundamentally differently about non-human identities. Jeff and Jim explore the concept of treating AI as a first-class identity, how AI is beginning to replace rubber-stamp access certifications, the shift toward policy-based access control, and the practical path toward zero standing privilege. The episode wraps with a lighter conversation about Rob's 3D printing hobby.About SailPoint:SailPoint (Nasdaq: SAIL) is defining the new era of adaptive identity security. In a world where non-human identities now significantly outnumber humans, our AI-powered platform unifies identity, security, and data intelligence to protect today’s enterprise from advanced identity-based threats. We deliver the identity solution that spans both the breadth of identities and the depth of context needed to drive real-time access with confidence. Built on principles like zero-standing privilege and contextualized risk, our SailPoint platform transforms identity from a point of vulnerability into a powerful security advantage. Trusted by many of the world's leading organizations, SailPoint secures the enterprise with intelligent, autonomous identity security.Learn more about SailPoint: https://www.sailpoint.com/Connect with Rob: https://www.linkedin.com/in/rob-sebaugh-1ba9013/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps:00:00 Introduction00:48 Rob Sebaugh and the identity strategist role at SailPoint04:38 Practitioner advice from the field07:49 What SailPoint does: the hotel key analogy11:04 Buying identity technology means buying a business process13:30 What identity governance is and why it still matters16:47 Risk-appropriate governance and privileged access19:39 Non-human identities and the scale of the agentic challenge22:57 Treating AI as a first-class identity24:28 When AI makes governance decisions: beyond rubber stamping28:04 Is identity governance a binary decision?29:58 Securing data inside AI and large language models34:09 Identity: the field that reinvents itself35:01 Identity as the new control plane37:21 Is all access privileged access?40:25 Zero standing privilege in practice44:22 Innovation, continuous identity, and what SailPoint is building46:28 Identity posture management50:13 Practitioner advice for the next three to five years53:00 The future of IGA in ten years57:44 Lighter note: 3D printing with Rob Sebaugh1:05:35 Final thoughts on SailPointKeywords: Rob Sebaugh, SailPoint, identity governance, identity security, IGA, non-human identities, agentic AI, zero standing privilege, just-in-time access, identity posture management, control plane, zero trust, policy-based access control, AI certification, rubber stamping, sponsor spotlight, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald
  • #428 - Modernizing IGA with Thomas Zarnhofer 15.06.2026 42мин
    Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Thomas Zarnhofer, IAM Architect at a major retail company in central Europe. Thomas shares his experience leading a full IGA transformation from a decade-old on-premise system to a modern cloud-based platform. The conversation covers the shift from a contract-based to a person-based identity model, the importance of cleaning data before migration begins, a three-phase framework of Foundation, Migration, and Adoption, lessons learned from running two systems in parallel, and a look at how AI could make IGA predictive. The episode ends with Thomas's tips for visiting Austria.Connect with Thomas: https://www.linkedin.com/in/tzarnhofer/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps00:00 Introduction and EIC 2026 Setting02:00 Thomas's Identity Origin Story04:21 The Catalyst for IGA Modernization07:43 Contract-Based vs Person-Based Identity Models09:22 Consolidating Master Data Sources11:39 Data Quality and Attribute Ownership13:34 Partnering with HR for Clean Data16:43 Data Analysis: Why They Chose Excel Over AI17:53 Clean Your Data Before You Migrate18:23 The Three Phases: Foundation, Migration, Adoption20:12 Driving Adoption Across the Organization21:10 Running Two Systems in Parallel22:47 Challenge Everything vs Lift and Shift27:23 Surprises in the Cloud IGA Journey29:02 Testing Requirements in the Cloud29:51 AI and the Future of IGA32:25 AI Chatbots and Role Discovery35:30 Scoping Business Role Visibility36:06 Life Outside IAM: Travel and Austria TipsKeywords:IAM, IGA, Identity Governance, IGA Migration, On-Premises to Cloud, Identity Model, Contract-Based Identity, Person-Based Identity, Master Data, Data Quality, HR Integration, Joiner Mover Leaver, Cloud IGA, Retail IAM, EIC 2026, AI in IGA, Predictive IGA, Role Management, Access Governance, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Thomas Zarnhofer

Популаран у

Овај подкаст се појављује и у подкаст листама ових земаља.