Identity and Access Management (IAM)
What is Identity and Access Management (IAM)?
Identity and Access Management (IAM)A discipline and set of technologies for defining digital identities and controlling which resources each identity may access under which conditions.
Identity and Access Management (IAM) is the framework of policies, processes and tooling that manages the lifecycle of human and machine identities and governs their access to applications, data and infrastructure. Core capabilities include provisioning and deprovisioning, authentication, authorization, single sign-on (SSO), multi-factor authentication, role and entitlement management, and audit logging. IAM is the backbone of zero-trust architectures, where every access decision depends on a verified identity and its attributes rather than network location.
IAM is built on open standards: SAML 2.0 and OpenID Connect (layered on OAuth 2.0) for federated SSO, and SCIM 2.0 (IETF RFCs 7642/7643/7644) for cross-domain user provisioning that automatically creates, updates and deactivates accounts across SaaS apps. Mature programs add adjacent disciplines — Identity Governance and Administration (IGA) for access certification, Privileged Access Management (PAM) for admin accounts, and CIEM for cloud entitlements.
Weak IAM is a leading breach cause: stolen or reused credentials are consistently among the top initial-access vectors in the Verizon DBIR, and orphaned accounts, standing privilege, and unmanaged service identities are routinely abused for lateral movement. Enforcing least privilege, just-in-time access, and prompt joiner-mover-leaver deprovisioning shrinks that attack surface.
flowchart LR
A[Identity source: HR, directory] --> B[Provisioning via SCIM]
B --> C[Identity store and IdP]
C --> D[Authentication: MFA, SSO]
D --> E[Authorization: RBAC/ABAC policy]
E --> F{Access decision}
F -->|Permit| G[Resource access + audit log]
F -->|Deny| H[Block and alert]● Examples
- 01
Okta, Microsoft Entra ID and Ping Identity used as enterprise IAM platforms.
- 02
Joiner-mover-leaver workflows that automatically grant and revoke application access.
● Frequently asked questions
What is Identity and Access Management (IAM)?
A discipline and set of technologies for defining digital identities and controlling which resources each identity may access under which conditions. It belongs to the Identity & Access category of cybersecurity.
What does Identity and Access Management (IAM) mean?
A discipline and set of technologies for defining digital identities and controlling which resources each identity may access under which conditions.
How do you defend against Identity and Access Management (IAM)?
Defences for Identity and Access Management (IAM) typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for Identity and Access Management (IAM)?
Common alternative names include: IAM, Identity management.