Published by Identity at the Center
Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what? Visit us on the web at idacpodcast.com
Listen on Apple Podcasts39 min
Recorded live at Identiverse 2026 in Las Vegas, Jeff sits down with Decoded co-host Sean O'Dell for a wide-ranging state of the union on continuous identity, shared signals, and the identity questions AI keeps raising. Sean shares what he is hearing on the ground about the upcoming transaction tokens spec, why continuous identity has moved from concept to mainstream adoption, and how shared signals are expanding into commerce. The conversation shifts to AI: the real cost of securing it, why model provenance matters, and the murky question of who is on the hook when an AI agent makes an expensive or harmful decision on your behalf. They debate companion agents, consent versus power of attorney, and whether the identity industry even owns this problem. Sean closes with a simple piece of advice for anyone feeling overwhelmed by AI right now. Connect with Sean: https://www.linkedin.com/in/seanodentity/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com Timestamps: 00:00 Intro and a Decoded update 00:44 Transaction tokens spec preview 01:51 State of the union on continuous identity 03:39 The questions organizations are asking 04:34 Is it still all about the data 05:07 Shared signals framework moving into commerce 06:40 Is AI a fad at Identiverse this year 07:11 The real cost of securing AI 08:00 Model provenance and indemnity 09:39 IAM for AI versus AI for IAM 10:18 Trusting agents to act without oversight 14:51 Assigning authority to the who and the what 16:13 The cruise booking example and who is on the hook 20:16 Companion agents, consent, and power of attorney 23:00 Does the identity industry own this problem 25:00 Relationship and intent as the real issue 28:03 Could an insurance market emerge for agentic AI 29:18 An access review scenario gone wrong 30:41 Small specialized language models for identity tasks 32:11 Favorite hallway conversations at Identiverse 36:05 Wrap up and words of wisdom on AI FOMO Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sean O'Dell, Decoded, Identiverse 2026, continuous identity, transaction tokens, shared signals framework, agentic AI, AI security, model provenance, IAM, digital identity, identity and access management
55 min
Live from the IDAC booth at Identiverse 2026, Jeff and Jim sit down with Pam Dingle, Director of Identity Standards at Microsoft, to unpack agentic identity. Pam breaks down assistive versus autonomous agents, walks through where standards like SPIFFE and OAuth hold up, and explains the difference between delegation, impersonation, and partition. The conversation also covers credential discovery risk, shared signals and revocation, what enterprises should prioritize now, and the value of hallway conversations at Identiverse. Connect with Pam: https://www.linkedin.com/in/pameladingle/ OAuth Actor Profile for Delegation: https://www.ietf.org/archive/id/draft-mcguinness-oauth-actor-profile-00.html Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com Timestamps: 00:00 Intro and Identiverse 2026 vibes 04:01 Defining agentic identity 07:06 Has the earth really shifted 11:38 An old problem thats been bejeweled 15:13 From Nulli Secundus to Microsoft 16:00 How standards are holding up 19:27 Client ID metadata and just in time trust 21:41 Shared signals and the revocation problem 24:43 Deploying agentic identity at scale 28:11 Registries at scale 29:04 Delegation authorization and attenuation 32:33 Delegation vs impersonation vs partition 36:03 The one thing you can fix right now 37:56 Favorite hallway conversation 42:29 The solar system of hallway conversations 45:51 Remembering Kim Cameron 48:00 New voices to watch 52:08 Wrap up and thank you Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Pam Dingle, Pamela Dingle, Microsoft, Identiverse 2026, agentic identity, agentic AI, non-human identity, delegation, impersonation, SPIFFE, OAuth, identity standards, IAM, digital identity, workload identity
46 min
In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, covering how it applies to humans, non-human identities, and AI agents alike. The conversation digs into the difference between authentication and authorization, why zero standing privilege is more achievable now than before agentic adoption took hold, and how dynamic, evidence-based policies can reduce reliance on manual approvals. Greg also shares real examples, including row-level access control for data lakes and a CRM mishap that shows how easily agents can misinterpret intent. The episode closes with a look at where enterprise AI agent governance may be headed over the next few years, plus a lighter conversation about explaining IAM to a 10-year-old. This episode is made possible through the generous support of P0 Security as part of IDAC's nonprofit Sponsor Spotlight series. Learn more at p0.dev/idac. Connect with Greg (Gergely): https://www.linkedin.com/in/gergely-danyi/ Learn more about P0: https://p0.dev/idac/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00 - Introduction and sponsor acknowledgment 01:13 - Greg Danyi's path into IAM 02:18 - What P0 Security solves for 03:21 - Where P0 fits versus PAM and IGA 04:46 - Agentic identity as a driver of adoption 05:27 - MCP servers and unpredictable agent actions 07:10 - Defining runtime access control 08:50 - How authentication and authorization work together 09:07 - Standing access versus expressed intent 10:16 - Zero standing privilege in practice 12:27 - Agentic identity as a distinct identity class 19:24 - Automated evidence for approvals 20:42 - Walking through a support agent example 22:13 - Row-level access control for data lakes 23:35 - Dynamic roles explained 29:55 - CRUD risks and underestimated concerns 31:32 - Human intent and giving agents clear direction 36:32 - Where enterprise AI agent governance is headed 39:36 - Advice for CIOs and CISOs getting started 41:15 - Explaining IAM to a 10-year-old 42:29 - Board games, dice, and calculated risk 44:00 - Closing thoughts and where to learn more Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Greg Danyi, P0 Security, runtime access control, agentic identity, zero standing privilege, non-human identity, authentication, authorization, IAM podcast
26 min
Jim McDonald and Jeff Steadman took the Identity at the Center podcast live at Identiverse 2026 in Las Vegas for a crowd-sourced game show called Majority Rules. Identity professionals competed in real time, picking answers to IAM and conference questions in a race to predict the majority. With a prize pool of over $5,000 for the top ten scorers, the stakes were high and the honesty was brutal. The episode also marks a milestone: IDAC hitting two million downloads. Thanks to Shirley Han and the CyberRisk Alliance team, and to sponsors Hyper, Red Block, SlashId, Rubrik, Stratacity, FusionAuth, Nexus, CrowdStrike, Hush Security, PlainId, RSM, and CyberRisk Alliance. Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 0:00 Introduction and Two Million Downloads Milestone 1:00 Sponsor and Event Team Recognition 3:00 How to Play Majority Rules 4:00 Warm-Up Round Begins 6:00 Battle Royale Mode Explained 8:30 Decentralized Identity and the LDAP Reality 10:30 Las Vegas Evening Entertainment 11:30 Top Identity Trends at Identiverse 2026 12:30 Access Certification and the 4:55 PM Click 13:30 Classic Vegas and Expo Hall Favorites 14:50 PAM Strategies and the Post-it Note 16:00 Conference Navigation and Footwear Survival 18:00 Identity Log Monitoring Chaos 19:30 Hallway Track Conversations 20:30 Cloud Entitlements and Everyone Gets Root 21:00 Sleep Habits at a Security Conference 22:00 Business Cards in 2026 23:00 Legacy App Strategy and Thoughts and Prayers 24:45 Las Vegas Dining Preferences 25:30 Winners Announced and Closing Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Identiverse, Identiverse 2026, Majority Rules, live event, game show, IAM, identity and access management, decentralized identity, LDAP, SSO, PAM, privileged access management, cloud entitlements, ISPM, access certification, Las Vegas, cybersecurity, conference
42 min
Recorded the night before Identiverse 2026 at BrewDog in Las Vegas, Jeff hosts a roundtable of IdentiBeer chapter leaders and community members from around the world. Espen Bago (Oslo), Marco Venuti (Rome and Milan), Heiko Klarl (Munich), Craig Ramsay (Nashville), Tina Srivastava and Elie Azerad (San Francisco), Bertrand Carlier (Paris, in planning), Ole Shved (Detroit, forming), and Roland Baum (Frankfurt) share what makes IdentiBeer work, how chapters get started, and what draws people in. First-time Identiverse attendee Varshith Reddy joins mid-conversation for some live conference tips. The group celebrates going 35 minutes without mentioning AI and closes with everyone's drink of choice and an impromptu MFA rap. Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 0:00 Welcome and intro 0:41 What is IdentiBeer? Espen Bago explains 2:31 Marco Venuti and the Italian chapters 5:07 Could there be an IdentiBeer conference? 6:03 Heiko Klarl and IdentiBeer Munich 7:09 Craig Ramsay and the new Nashville chapter 9:53 Beer is just clickbait and vendor neutrality 12:45 Tina Srivastava and the IDPro Slack connection 13:18 Ole Shved and the future Detroit chapter 14:14 Advice for new chapter organizers 16:33 Keep the momentum: do another one soon 17:01 What draws people to IdentiBeer? 17:37 The IdentiBeer charter and inclusivity 18:20 Elie Azerad and the San Francisco chapter 21:08 Tina and the South Bay satellite idea 25:50 Bertrand Carlier and plans for Paris 29:31 Varshith Reddy: tips for first-time Identiverse attendees 34:12 35 minutes without saying AI 36:20 Roland Baum and the Frankfurt Identivier 39:06 What is your drink of choice? 40:48 Tina's MFA rap and closing thoughts Keywords: IdentiBeer, Identiverse 2026, IAM community, Identity and Access Management, Jeff Steadman, Jim McDonald, IDAC, Identity at the Center, Espen Bago, Marco Venuti, Heiko Klarl, Craig Ramsay, Tina Srivastava, Elie Azerad, Bertrand Carlier, Ole Shved, Roland Baum, Varshith Reddy, IDPro, community building, vendor neutral, IAM networking, Las Vegas
55 min
Jim McDonald sits down with Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, for an in-depth conversation on customer identity and access management. Dan explains how FusionAuth views authentication as the front door to any application and why control, deployment flexibility, and developer ownership are central to their approach. The discussion covers progressive registration, friction vs. usability, customization options, identity standards, the build vs. buy debate, risk-based MFA, and how AI agents will shape the future of customer identity. This episode and others is made possible with support from FusionAuth. Learn more at fusionauth.io/idac. Connect with Dan: https://www.linkedin.com/in/mooreds/ Learn more about FusionAuth: https://fusionauth.io/idac Blog article mentioned: https://bobdahacker.com/blog/fifa-hack Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00:00 Introduction 00:01:18 What is FusionAuth? 00:03:15 Dan's identity origin story 00:04:19 Developer focus and ethos 00:06:54 Authentication as the front door 00:10:00 Balancing friction and usability 00:15:24 Customization in CIAM 00:18:10 What sets FusionAuth apart 00:20:33 FusionAuth's customer sweet spot 00:25:48 Deployment flexibility and the control spectrum 00:30:19 Common challenges in CIAM 00:33:06 Build vs. buy for authentication 00:36:00 Omni-channel authentication 00:40:27 Why identity standards matter 00:42:07 Risk-based MFA and intelligent challenges 00:45:00 AI agents and the future of CIAM 00:49:23 Closing thoughts 00:51:35 Vacation roundup Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Moore, FusionAuth, CIAM, customer identity, authentication, access management, IAM, identity standards, MFA, risk-based authentication, progressive registration, OAuth, OIDC, SAML, AI agents, deployment flexibility, build vs buy, Sponsor Spotlight
44 min
Jim McDonald takes the Identity at the Center podcast on the road to Rome, Italy, for a special two-part episode. The first segment is an IdentiBeer roundup where Jim gathers quick-fire takes from practitioners in the Italian IAM community, including Andrea Rossi and Alessandro Piscopo of IAMONES and Marco Venuti of Thales on the biggest trends shaping identity today. The second segment is a three-course meal where Jim sits down with Alessandro Piscopo, Head of AI and Co-founder at IAMONES, to discuss AI and identity over food and wine. Across a seafood starter, scialatielli alla pescatora, and tiramisu, the conversation covers the history of AI in identity, why LLMs represent a revolution rather than an evolution, the AI-first product philosophy versus retrofitting AI onto legacy systems, compute and architecture constraints facing large language models, and what life looks like for the IAM practitioner in 2030. Alessandro envisions an identity equivalent of Claude Code, a specialized AI tool that democratizes identity expertise the way coding assistants have transformed software development. 0:00 Intro and IdentiBeer Rome roundup 7:01 Alessandro on AI for IAM vs. IAM for AI 12:00 Three-course dinner begins - Course 1: Seafood starter 14:09 History of AI in identity, from ML models to LLMs 17:51 Course 2: Scialatielli alla pescatora and Falanghina wine 19:56 AI-first products vs. AI layered onto legacy systems 22:00 Transition period and the new world of identity 24:04 The ChatGPT moment vs. the iPhone moment 27:05 Compute constraints, energy costs, and architecture breakthroughs 30:46 Smaller models and cost-efficiency tradeoffs 32:35 Course 3: Tiramisu, baba, and espresso 33:00 Life as an IAM practitioner in 2030 35:19 Claude Code for IAM and democratizing identity tools 37:24 App store ecosystem analogy for AI platforms 43:07 Closing thoughts Keywords: IAM, identity and access management, AI for IAM, IAM for AI, agentic AI, non-human identity, IGA, LLMs, large language models, AI-first, machine learning, Alessandro Piscopo, IAMONES, Jim McDonald, Jeff Steadman, Identity at the Center, IDAC, IdentiBeer, Rome, Italy, Marco Venuti, Thales, Andrea Rossi, agentic identity, transformer architecture, compute efficiency, identity practitioner 2030, Claude Code for IAM, identity democratization, Identiverse, European Identity Conference
1 hr 1 min
Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Kuppinger, founder and distinguished analyst at KuppingerCole. They dig into the tectonic shifts AI is bringing to identity and security, the AI security fabric framework, why decentralized identity thinking may be essential for governing the agentic mesh, the ongoing debate over NHI terminology, what organizations can do tactically today, and what concerns Martin most about where the industry is heading by 2030. Connect with Martin: https://www.linkedin.com/in/martinkuppinger/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00 Introduction and Welcome 00:50 What a Distinguished Analyst Does 01:37 EIC 2026: Thought Leadership and Best Practice 04:17 Agentic AI: Non-Directed, Non-Deterministic Identity 08:22 Speed of Change: Tactical Now, Strategic Later 12:34 The AI Security Fabric: Five Capability Blocks 15:10 Identity Fabric Origins and Market Growth 18:27 Discovery as the Foundation for Governance 19:48 Governance, Explainability, and Organizational Gaps 22:00 Agent Lineage and Rethinking NHI Terminology 23:50 LLMs vs. Small Language Models 26:23 Is Agentic Identity a Genuinely New Problem? 32:29 Humanoid Robots and the Limits of AI Reasoning 37:05 Decentralized Identity, Trust Frameworks, and Signals 41:07 Identity Verification and Consent for Agents 48:42 What Concerns Martin About the Future of Identity 50:34 Favorite AI Application: Assisted Driving 55:00 Self-Driving Cars, Data, and Personal Privacy Keywords: Martin Kuppinger, KuppingerCole, EIC 2026, EIC Berlin, agentic AI, AI security fabric, identity fabric, decentralized identity, AI governance, non-human identity, autonomous identity, dependent identity, agent lineage, explainability, MCP server, small language models, verifiable credentials, risk-based authorization, OT security, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity security
59 min
Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Sandren, IAM Product Lead at IKEA, for a wide-ranging conversation covering nearly every corner of modern identity security. Martin shares what has changed since his first IDAC appearance on episode 293, including the rise of AI, growing interest in digital sovereignty, and the maturing shared signals framework. The conversation moves through risk-based defense in depth, tiered MFA rollout strategies, session management, and the real challenge of trusting AI to make security decisions. Martin introduces identity dark matter and explains how IVIP can surface the 95-plus percent of applications that never reach an IGA system. The episode also covers shadow AI, MCP server risks, the SaaSpocalypse debate, and the EU AI Act. It closes on a grounded note: solar panels. Connect with Martin: https://www.linkedin.com/in/martinsandren/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com TIMESTAMPS 00:00 Welcome and EIC 2026 intro 01:47 What has changed in two years: AI, sovereignty, shared signals 03:06 Martin's EIC presentations: AI for IAM and IAM for AI 04:46 Can you prioritize one direction over the other? 07:13 What would it take to trust AI making identity decisions? 09:32 AI-enhanced detection and risk-based session management 13:07 Session invalidation and the shared signals framework 14:11 Defense in depth and right-sizing privileges 18:25 MFA today: any MFA versus phish-resistant MFA 19:17 AI chatbots, enterprise LLMs, and shadow AI 23:11 MCP servers, NHI risk, and return on risk thinking 27:00 AI configuring IAM systems: how close are we? 31:30 LLM costs, the SaaSpocalypse, and enterprise AI futures 40:10 Identity dark matter and the IVIP concept 44:16 CMDB versus IVIP: do you need both? 46:18 The EU AI Act and building an AI governance registry 49:18 Where to start: get your AI inventory in place first 50:00 Closing thoughts and the solar panel tangent KEYWORDS AI for IAM, IAM for AI, identity dark matter, IVIP, IGA, shared signals framework, phish-resistant MFA, defense in depth, session management, MCP servers, NHI, shadow AI, SaaSpocalypse, EU AI Act, AI governance, zero standing privilege, EIC 2026, IKEA, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Martin Sandren
1 hr 7 min
This episode is presented courtesy of SailPoint. Rob Sebaugh, Senior Identity Strategist at SailPoint, joins Jeff and Jim for a wide-ranging conversation on the past, present, and future of identity governance. Rob brings more than two decades of practitioner experience to the table, including 16 years running large-scale identity programs before making the move to the vendor side. The conversation covers what identity governance means today, why it must move to the forefront rather than be treated as an afterthought in an agentic world, and how organizations need to think fundamentally differently about non-human identities. Jeff and Jim explore the concept of treating AI as a first-class identity, how AI is beginning to replace rubber-stamp access certifications, the shift toward policy-based access control, and the practical path toward zero standing privilege. The episode wraps with a lighter conversation about Rob's 3D printing hobby. About SailPoint: SailPoint (Nasdaq: SAIL) is defining the new era of adaptive identity security. In a world where non-human identities now significantly outnumber humans, our AI-powered platform unifies identity, security, and data intelligence to protect today’s enterprise from advanced identity-based threats. We deliver the identity solution that spans both the breadth of identities and the depth of context needed to drive real-time access with confidence. Built on principles like zero-standing privilege and contextualized risk, our SailPoint platform transforms identity from a point of vulnerability into a powerful security advantage. Trusted by many of the world's leading organizations, SailPoint secures the enterprise with intelligent, autonomous identity security. Learn more about SailPoint: https://www.sailpoint.com/ Connect with Rob: https://www.linkedin.com/in/rob-sebaugh-1ba9013/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com Timestamps: 00:00 Introduction 00:48 Rob Sebaugh and the identity strategist role at SailPoint 04:38 Practitioner advice from the field 07:49 What SailPoint does: the hotel key analogy 11:04 Buying identity technology means buying a business process 13:30 What identity governance is and why it still matters 16:47 Risk-appropriate governance and privileged access 19:39 Non-human identities and the scale of the agentic challenge 22:57 Treating AI as a first-class identity 24:28 When AI makes governance decisions: beyond rubber stamping 28:04 Is identity governance a binary decision? 29:58 Securing data inside AI and large language models 34:09 Identity: the field that reinvents itself 35:01 Identity as the new control plane 37:21 Is all access privileged access? 40:25 Zero standing privilege in practice 44:22 Innovation, continuous identity, and what SailPoint is building 46:28 Identity posture management 50:13 Practitioner advice for the next three to five years 53:00 The future of IGA in ten years 57:44 Lighter note: 3D printing with Rob Sebaugh 1:05:35 Final thoughts on SailPoint Keywords: Rob Sebaugh, SailPoint, identity governance, identity security, IGA, non-human identities, agentic AI, zero standing privilege, just-in-time access, identity posture management, control plane, zero trust, policy-based access control, AI certification, rubber stamping, sponsor spotlight, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald
42 min
Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Thomas Zarnhofer, IAM Architect at a major retail company in central Europe. Thomas shares his experience leading a full IGA transformation from a decade-old on-premise system to a modern cloud-based platform. The conversation covers the shift from a contract-based to a person-based identity model, the importance of cleaning data before migration begins, a three-phase framework of Foundation, Migration, and Adoption, lessons learned from running two systems in parallel, and a look at how AI could make IGA predictive. The episode ends with Thomas's tips for visiting Austria. Connect with Thomas: https://www.linkedin.com/in/tzarnhofer/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com Timestamps 00:00 Introduction and EIC 2026 Setting 02:00 Thomas's Identity Origin Story 04:21 The Catalyst for IGA Modernization 07:43 Contract-Based vs Person-Based Identity Models 09:22 Consolidating Master Data Sources 11:39 Data Quality and Attribute Ownership 13:34 Partnering with HR for Clean Data 16:43 Data Analysis: Why They Chose Excel Over AI 17:53 Clean Your Data Before You Migrate 18:23 The Three Phases: Foundation, Migration, Adoption 20:12 Driving Adoption Across the Organization 21:10 Running Two Systems in Parallel 22:47 Challenge Everything vs Lift and Shift 27:23 Surprises in the Cloud IGA Journey 29:02 Testing Requirements in the Cloud 29:51 AI and the Future of IGA 32:25 AI Chatbots and Role Discovery 35:30 Scoping Business Role Visibility 36:06 Life Outside IAM: Travel and Austria Tips Keywords: IAM, IGA, Identity Governance, IGA Migration, On-Premises to Cloud, Identity Model, Contract-Based Identity, Person-Based Identity, Master Data, Data Quality, HR Integration, Joiner Mover Leaver, Cloud IGA, Retail IAM, EIC 2026, AI in IGA, Predictive IGA, Role Management, Access Governance, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Thomas Zarnhofer
1 hr 13 min
Jeff and Jim are joined by Heather Flanagan, Content Chair, and Andi Hindle, Conference Chair, for a full preview of Identiverse 2026 at Mandalay Bay in Las Vegas. They cover the 2026 theme of trust and change, why AI was removed as a standalone track and redistributed across all content areas, the provocative argument that non-human access now dramatically outpaces human access and is reshaping identity system design, whether authentication is truly solved, authorization as the harder unsolved problem, CFP surprises, networking events including Women at Identiverse, and predictions for 2027. Save 30% with code IDV26-IDAC30%. New IDPro members save $25 at idpro.org/idac. Connect with Heather: https://www.linkedin.com/in/hlflanagan/ Connect with Andi: https://www.linkedin.com/in/ahindle/ Identiverse 2026: https://events.identiverse.com/2026/begin?code=IDV26-IDAC30%25 Heather's IAM Conference List: https://github.com/fedidcg/meetings/wiki/2026-List-of-Identity-and-Related-Conferences-and-Standards-Development-Events Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com TIMESTAMPS 00:00:00 Introduction and SolarWinds breach banter 00:03:27 Identiverse preview and discount codes 00:06:10 Guest introductions 00:06:52 Role of Content Chair 00:08:46 Role of Conference Chair 00:11:16 2026 conference theme 00:15:00 AI as context, not a standalone track 00:16:32 Control plane vs enablement plane debate 00:22:19 What the industry is underestimating 00:24:00 Non-human access outpaces human access 00:26:52 Is authentication solved? Passkeys 00:30:31 Authorization: far from solved 00:36:04 Extensibility in standards and deployments 00:38:22 CFP surprises: fraud and identity proofing 00:41:48 Usability and UX gaps 00:43:18 Agentic AI: identity or governance? 00:47:55 Networking and newcomer programming 00:51:45 Women at Identiverse 00:52:46 AI-generated CFP submissions 00:55:00 Predictions for Identiverse 2027 00:58:04 Theme songs for Identiverse 2026 01:02:58 Heather's identity conference list on GitHub 01:04:47 Swag culture at identity conferences 01:12:25 Wrap-up KEYWORDS Identiverse 2026, Heather Flanagan, Andi Hindle, identity conference, NHI, non-human identity, agentic AI, passkeys, authentication, authorization, IAM, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, digital identity, continuous identity architecture, zero standing privilege, verifiable credentials, identity governance
1 hr 2 min
This episode and the Identity at the Center podcast is supported by CrowdStrike. Learn more at crowdstrike.com. Jeff Steadman and Jim McDonald sit down with Scott Kriz, GM of Continuous Identity at CrowdStrike, for a deep dive into continuous identity, zero standing access, and the convergence of identity and security. Scott traces his path from co-founding Bitium, to selling it to Google Cloud, to building SGNL and ultimately joining CrowdStrike. The conversation covers how continuous identity works in practice, why traditional PAM and IGA fall short in a real-time world, and what the rise of agentic AI means for identity governance at scale. Connect with Scott: https://www.linkedin.com/in/scottkriz/ Learn more about Crowdstrike: https://www.crowdstrike.com/en-us/platform/next-gen-identity-security/caep/?idac Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00:00 Introduction and welcome 00:01:21 How Scott got into identity and co-founded Bitium 00:03:55 Selling to Google Cloud and the inspiration for SGNL 00:05:02 Continuous identity and zero standing access explained 00:09:13 Defining continuous identity at CrowdStrike 00:10:20 How continuous identity differs from PAM and IGA 00:15:06 Data as the foundation for continuous identity 00:19:29 Open ecosystems, Shared Signals Framework, and CAEP 00:25:26 Agents, identity chaining, SPIFFE, SPIRE, and MCP gateways 00:33:02 Identity inside CrowdStrike's broader security strategy 00:37:27 Identity security budgets and ROI-driven purchasing 00:40:04 Agentic scale and the need for automated identity controls 00:43:39 The SGNL acquisition: what it means for both companies 00:50:25 Zero trust as a real architectural framework 00:54:00 Helicopter skiing, avalanches, and staying present Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Scott Kriz, CrowdStrike, SGNL, continuous identity, zero standing access, PAM, IGA, zero trust, agentic AI, non-human identity, NHI, SPIFFE, SPIRE, MCP, identity security, real-time authorization, cybersecurity
46 min
Jeff and Jim recap their week at KuppingerCole's EIC 2026 in Berlin, covering standout keynotes, hallway conversations, and sessions on securing AI agents, CIAM, and AI versus nuclear regulation. They announce a giveaway of Eve Maler's signed copy of Mastering Digital Identity for YouTube commenters by June 12th. The episode also features live footage and a full interview with Espen Bago, founder of IdentiBeer, recorded at the Berlin event. Jeff, Jim, and Espen discuss the rapid global growth of the IdentiBeer community, terminology challenges around NHI and IAM concepts, the gap between conference talk and real client needs, and why the industry keeps bypassing foundational data work in the rush toward AI and agentic identity. Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00:10 Welcome and EIC 2026 Setup 00:03:57 Eve Maler Book Giveaway Details 00:05:00 Conference Highlights: Keynotes and Hallway Con 00:06:07 Elizabeth Garber's Standing Ovation Keynote 00:07:02 Brazil Invitation and Securing AI Agents 00:09:10 Nuclear Regulation vs. AI Regulation 00:11:07 Upcoming EIC Episode Preview 00:14:16 IdentiBeer Berlin Live Event 00:14:29 Interview with Espen Bago Begins 00:15:14 IdentiBeer Growth and Global Expansion 00:17:23 The IdentiBeer Name Debate 00:23:26 Data Quality Gaps in NHI and IAM 00:26:31 Who Owns IAM Terminology? 00:34:20 Conference Talk vs. Client Reality 00:40:52 The HR-IAM Gap Nobody Talks About 00:43:17 Fundamentals: The Karate Kid Analogy Keywords: EIC 2026, European Identity Conference, IdentiBeer, Espen Bago, Eve Maler, Elizabeth Garber, Mastering Digital Identity, Berlin, Identiverse, NHI, non-human identities, IAM fundamentals, AI regulation, agentic identity, IGA, PAM, CIAM, IDPro, identity community, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald
1 hr 11 min
Jeff and Jim are back with the May 2026 mailbag, answering listener questions from Amsterdam, Mumbai, Austin, and Berlin. Topics include navigating IAM vendor acquisitions, defending against AI deepfakes in remote onboarding, governing contractor and third-party identities, fixing the leaver process in IGA, and tackling a decade of IAM technical debt. The episode closes with unpopular industry opinions: why RFPs are procurement theater, why rip and replace should be normalized, and why one-throat-to-choke vendor thinking usually backfires. IDPro new member discount: https://idpro.org/idac/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com CHAPTER TIMESTAMPS 00:00 Intro and SNL nostalgia 03:25 AI model roundup: ChatGPT, Claude, Gemini, and usage limits 10:16 Identiverse 2026 and IDPro member discount 14:53 Q1: Navigating vendor acquisitions (Isabelle, Amsterdam) 24:00 Q2: AI deepfakes in identity verification (Rajan, Mumbai) 32:32 Q3: Contractor and third-party identity governance (Caleb, Austin) 43:00 Q4: The leaver process and IGA scope gaps (Anonymous) 51:10 Q5: Tackling IAM technical debt (Tomas, Berlin) 57:00 Normalizing rip and replace 01:01:00 RFPs, one throat to choke, and other hot takes 01:08:00 Wrap-up KEYWORDS IAM, identity governance, IGA, vendor consolidation, acquisitions, deepfakes, identity verification, contractor management, non-employee identity, technical debt, rip and replace, RFP, joiner mover leaver, leaver process, Identiverse 2026, IDPro, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald
1 hr 1 min
Jeff and Jim welcome back Robert Snodgrass, Principal at RSM, for a deep dive into the RSM Middle Market Business Index cybersecurity report. The conversation covers the confidence gap facing middle market organizations, why digital identity remains undervalued despite being the primary attack surface, non-human identity governance, flat cybersecurity budgets, risk framework adoption, and what good incident response preparedness actually looks like. The episode wraps with a spirited Bitcoin Pizza Day toppings debate. Connect with Robert: https://www.linkedin.com/in/robert-snodgrass-7a199412/ Review the RSM US Middle Market Business Index Special Report on Cybersecurity 2026: https://rsmus.com/middle-market/cybersecurity-mmbi.html?cmpid=ola:45559-idac:bb01 IDPro new member discount: https://idpro.org/idac/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com TIMESTAMPS 00:00:00 Introduction and Scatter Spider social engineering discussion 00:04:00 IDPro discount code and upcoming conferences 00:06:26 Guest intro: Robert Snodgrass and the MMBI report 00:09:05 Defining the modern middle market 00:12:00 The confidence gap: 96% confident, 18% breached 00:15:04 Why attackers log in and top identity investment priorities 00:19:00 Why only 23% of leaders prioritize digital identity 00:22:00 Internal partnerships as the path to identity program success 00:25:10 AI, shadow AI, and non-human identity risks 00:31:00 NHI governance at scale: 45 to 1 ratio 00:34:50 Cybersecurity budget realities in the middle market 00:39:00 EU regulation and top-line cybersecurity drivers 00:42:03 NIST CSF adoption and risk framework value 00:46:00 Incident response planning: the two-minute drill 00:52:16 Bitcoin Pizza Day and closing thoughts KEYWORDS identity security, middle market, cybersecurity, MMBI, RSM, Robert Snodgrass, phishing-resistant MFA, non-human identities, NHI, shadow AI, incident response, NIST CSF, IAM, identity governance, ransomware, tabletop exercises, digital identity, cybersecurity budget, identity program, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald
1 hr 18 min
Episode 422 is the debut of Decoded by Identity at the Center, a new sub-series hosted by Jeff Steadman and Sean O'Dell dedicated to unpacking the specifications and standards powering IAM. Joining them is Pieter Kasselman, VP of Open Standards at Defakto and chair of the WIMSE working group. The conversation covers why traditional non-human identity approaches break at agentic scale, how SPIFFE and SPIRE enable short-lived automated credential provisioning without long-lived secrets, and why treating agents as workloads unlocks a decade of existing standards. Pieter walks through critical OAuth specs including JWT authorization grant, token exchange, client ID metadata, and the emerging transaction tokens draft. Sean connects these to practical gateway architecture, continuous access evaluation, and policy-based authorization. The episode closes with real-world deployment examples and a clear takeaway: the tools to secure agentic identity are available today. Episode Links:Pieter Kasselman: https://www.linkedin.com/in/pieter-kasselman-0259862/AI Agent Authentication and Authorization: https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/Workload Identity in Multi-system environments (WIMSE): https://ietf-wg-wimse.github.io/OAuth SPIFFE Client Authentication: https://datatracker.ietf.org/doc/draft-ietf-oauth-spiffe-client-auth/Transaction Tokens: https://datatracker.ietf.org/doc/draft-ietf-oauth-transaction-tokens/08/Agentic Identity Control Framework. You Already Have the Pieces. Now Build It. by Sean O'Dell: https://www.linkedin.com/pulse/agentic-identity-control-framework-you-already-have-pieces-o-dell-61b5e/ Timestamps: 00:00 Introduction to Decoded by Identity at the Center 00:13 The mission of the Decoded sub-series 03:02 Guest intro: Pieter Kasselman, VP of Open Standards at Defakto 06:21 Why agentic identity is urgent: scale, multi-platform, and shifting threat landscape 10:42 The real cost of API keys and credential sprawl in agentic systems 13:23 Agentic identity identifiers and how SPIFFE assigns unique workload IDs 21:00 Credential types: X.509, JWTs, and workload identity tokens 31:00 Connecting SPIFFE to OAuth and dynamic registration with client ID metadata 38:18 SPIFFE SVIDs, multiple credentials per agent, and governance traceability 41:44 Authentication versus authorization: delegation versus impersonation 47:00 Transaction tokens: binding access to specific transactions to stop token theft 51:21 Identity chaining and cross-domain authorization 55:00 Shared Signals Framework and dynamic authorization 57:00 Gateways, CAEP, and mid-flight token revocation for rogue agents 59:31 What you can deploy today with SPIFFE, OAuth, and existing IDPs 01:02:58 Policy-based access control and why instance-level governance cannot scale 01:04:58 Workload identity federation: Anthropic and Google Agent ID updates 01:07:13 Cross-platform federation and the law of agentic utility 01:11:55 Elevator pitch: agents are workloads and 95% of the problem is solved now 01:17:03 What is coming next: a transaction tokens deep dive Keywords: agentic identity, SPIFFE, SPIRE, OAuth, transaction tokens, Shared Signals Framework, WIMSE, workload identity, non-human identity, authorization delegation, JWT, CAEP, API gateway, IAM standards, AIMS, Jeff Steadman, Sean O'Dell, Pieter Kasselman, IDAC, Identity at the Center, Jim McDonald, Decoded by Identity at the Center Decoded by Identity at the Center: Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Sean O'Dell: https://www.linkedin.com/in/seanodentity/ Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Visit the show on the web at https://idacdecoded.com/
1 hr 10 min
Jeff and Jim welcome back Henrique Teixeira, SVP of Strategy at Saviynt, for his fourth appearance on the podcast. The episode opens with Jim's firsthand experience building an AI agent for a work project and discovering in real time how identity management challenges surface in the agentic era. After conference updates on EIC in Berlin and Identiverse in Las Vegas, Henrique unpacks the crowded terminology around AI agent governance, from Gartner's agent management platforms to UADP, the Unified Agentic Defense Platform. He proposes a three-pillar framework for managing AI and non-human identities: discovery, identity lifecycle and governance, and runtime access management, with guidance on where to start depending on whether your organization is greenfield or legacy-heavy. The conversation then examines how AI is reshaping the analyst business model, what makes information sources trustworthy, and how proprietary inquiry data forms the real competitive moat for firms like Gartner and Forrester. The episode closes with a wide-ranging discussion on AI's risk to shared cultural experiences, hyper-personalized entertainment, and the ethics of licensing your digital identity in the afterlife. Connect with Henrique: https://www.linkedin.com/in/bernardes/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00:00 Intro 00:00:55 Jim's AI Agent Experiment and Identity Lessons 00:06:04 Conference News: EIC and Identiverse 00:07:22 Identity Beer Community Events 00:08:40 Introducing Henrique Teixeira 00:12:00 AI Control Plane: Competing Terminologies 00:17:36 Three Pillars of AI Agent Identity Management 00:18:46 Why Visibility Matters More for NHI 00:20:00 Ownership, Accountability, and Humans at the Control Plane 00:24:26 Industry Maturity and the Gaps That Remain 00:25:41 Where to Start: Governance-First vs. Visibility-First 00:29:52 AI's Impact on the Analyst Profession 00:34:57 What Analyst Firms Have That AI Cannot Replace 00:39:04 Trust, Boutique Analysts, and Repeatability 00:44:34 Proprietary AI Chatbots and Gated Intelligence 00:49:30 IP Rights and the Legal Gray Zone of AI Training 00:52:14 AI and the Erosion of Shared Cultural Experience 00:58:00 AI Music, Personalized Entertainment, and the Future of Art 01:03:47 Digital Afterlife, Voice Clones, and AI Personas 01:08:18 Wrap-Up and Closing Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Henrique Teixeira, Saviynt, AI identity control plane, non-human identities, NHI, agentic AI, AI agents, AI governance, identity lifecycle, access management, discovery, agent management platform, UADP, IAM, Gartner, analyst firms, AI and culture, digital identity, identity security, EIC, Identiverse, identity beer
1 hr 13 min
This episode is made possible by GitGuardian. Jeff speaks with Dwayne McDaniel, Principal Developer Advocate at GitGuardian, about secrets sprawl, non-human identity governance, and the findings of the State of Secret Sprawl 2026 report. With 28.6 million secrets leaked to public GitHub in 2025 - a 34% year-over-year increase - they explore why hardcoded credentials persist, how agentic AI tools are making the problem worse, and what IAM practitioners can do to start addressing machine identity governance. Topics include GitGuardian's Good Samaritan notification program, the growing NHI inventory challenge, SPIFFE and SPIRE as a path to zero standing privilege, and data showing Claude Code co-authored commits are more than twice as likely to contain leaked secrets. Visit gitguardian.com/lps/idac to learn more. Connect with Dwayne: https://www.linkedin.com/in/dwaynemcdaniel/ Dwayne's website: https://dwayne-mcdaniel.com/ Learn more about GitGuardian: https://www.gitguardian.com/lps/idac GitGuardian Good Samaritan Program (free) - https://www.gitguardian.com/good-samaritan The State of Secrets Sprawl 2026: https://www.gitguardian.com/state-of-secrets-sprawl-report-2026 SPIFFE Book: https://spiffe.io/book/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com TIMESTAMPS: 00:00 Introduction and sponsor welcome 00:48 Dwayne's background and path to developer advocacy 04:11 Surprises from entering the identity and security space 06:29 What a principal developer advocate actually does 09:32 Why secrets became Dwayne's focus area 14:10 GitGuardian: overview and mission 19:36 Where secrets commonly leak across the SDLC 22:17 The Good Samaritan notification program explained 28:00 Why 70% of leaked secrets from 2022 were still valid in 2025 33:54 State of Secret Sprawl 2026: the year software changed 40:39 AI coding tools, Claude Code, and secrets leakage data 47:28 Practical questions for IAM practitioners to start asking 52:24 Zero standing privilege and the case for SPIFFE/SPIRE 01:00:00 Resources: the SPIFFE book, WIMSE, and AWS STS 01:02:51 Hot sauce, the Cubs, and closing thoughts KEYWORDS: secrets sprawl, hardcoded secrets, non-human identity, NHI governance, GitGuardian, SPIFFE, SPIRE, workload identity, DevSecOps, agentic AI, Claude Code, zero standing privilege, supply chain security, credential abuse, identity and access management, IAM, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dwayne McDaniel
29 min
Recorded live as part of the Identity Management Day 2026 streaming program, Jeff and Jim mark their fifth IMD episode. Introduced by Jeff Reich from the Identity Defined Security Alliance, they reflect on how the IAM industry has evolved since their first IMD episode in 2021 and grade overall progress a C. Topics include what has genuinely improved (passkeys, MFA adoption, broader awareness), what hasn't (compliance fatigue, security theater, persistent credential theft), the exploding challenge of non-human identity governance, whether AI will eventually need to certify other AI, and how AI-powered phishing and deep fakes are raising the bar for identity verification. The episode wraps with chat-submitted IAM bumper stickers. Identity Management Day 2026: https://www.idsalliance.org/event/identity-management-day-2026/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com CHAPTERS 0:00 - Jeff Reich intro from the IMD stream 2:00 - Identity Management Day 2026 kicks off 3:30 - Five years of IMD: a look back at episode 88 7:00 - Does IMD move the needle? 9:30 - Who is Identity Management Day actually for? 12:00 - What has improved in IAM over five years 16:00 - What hasn't improved: compliance fatigue and security theater 18:30 - Grading the IAM industry 21:00 - NHI governance: visibility and accountability 26:00 - Can AI certify AI? Agentic identity governance 29:00 - AI-powered phishing and the evolving threat landscape 32:00 - Deep fakes and the identity verification challenge 36:00 - Lighter note: IAM bumper stickers KEYWORDS identity management day, identity management day 2026, NHI, non-human identity, agentic AI, phishing, deep fakes, IGA, passkeys, MFA, IAM, identity governance, access management, cybersecurity, credential theft, security awareness, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald
Bring this source into Mato to analyze its transferable patterns and turn them into an original show concept for your audience.
Create a show inspired by this