
Identity at the Center
By Identity at the Center


#435 - Majority Rules: IDAC Live at Identiverse 2026
Jim McDonald and Jeff Steadman took the Identity at the Center podcast live at Identiverse 2026 in Las Vegas for a crowd-sourced game show called Majority Rules. Identity professionals competed in real time, picking answers to IAM and conference questions in a race to predict the majority. With a prize pool of over $5,000 for the top ten scorers, the stakes were high and the honesty was brutal. The episode also marks a milestone: IDAC hitting two million downloads. Thanks to Shirley Han and the CyberRisk Alliance team, and to sponsors Hyper, Red Block, SlashId, Rubrik, Stratacity, FusionAuth, Nexus, CrowdStrike, Hush Security, PlainId, RSM, and CyberRisk Alliance.
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
0:00 Introduction and Two Million Downloads Milestone
1:00 Sponsor and Event Team Recognition
3:00 How to Play Majority Rules
4:00 Warm-Up Round Begins
6:00 Battle Royale Mode Explained
8:30 Decentralized Identity and the LDAP Reality
10:30 Las Vegas Evening Entertainment
11:30 Top Identity Trends at Identiverse 2026
12:30 Access Certification and the 4:55 PM Click
13:30 Classic Vegas and Expo Hall Favorites
14:50 PAM Strategies and the Post-it Note
16:00 Conference Navigation and Footwear Survival
18:00 Identity Log Monitoring Chaos
19:30 Hallway Track Conversations
20:30 Cloud Entitlements and Everyone Gets Root
21:00 Sleep Habits at a Security Conference
22:00 Business Cards in 2026
23:00 Legacy App Strategy and Thoughts and Prayers
24:45 Las Vegas Dining Preferences
25:30 Winners Announced and Closing
Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Identiverse, Identiverse 2026, Majority Rules, live event, game show, IAM, identity and access management, decentralized identity, LDAP, SSO, PAM, privileged access management, cloud entitlements, ISPM, access certification, Las Vegas, cybersecurity, conference

#434 - Identiverse 2026 - IdentiBeer Las Vegas
Recorded the night before Identiverse 2026 at BrewDog in Las Vegas, Jeff hosts a roundtable of IdentiBeer chapter leaders and community members from around the world. Espen Bago (Oslo), Marco Venuti (Rome and Milan), Heiko Klarl (Munich), Craig Ramsay (Nashville), Tina Srivastava and Elie Azerad (San Francisco), Bertrand Carlier (Paris, in planning), Ole Shved (Detroit, forming), and Roland Baum (Frankfurt) share what makes IdentiBeer work, how chapters get started, and what draws people in. First-time Identiverse attendee Varshith Reddy joins mid-conversation for some live conference tips. The group celebrates going 35 minutes without mentioning AI and closes with everyone's drink of choice and an impromptu MFA rap.
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
0:00 Welcome and intro
0:41 What is IdentiBeer? Espen Bago explains
2:31 Marco Venuti and the Italian chapters
5:07 Could there be an IdentiBeer conference?
6:03 Heiko Klarl and IdentiBeer Munich
7:09 Craig Ramsay and the new Nashville chapter
9:53 Beer is just clickbait and vendor neutrality
12:45 Tina Srivastava and the IDPro Slack connection
13:18 Ole Shved and the future Detroit chapter
14:14 Advice for new chapter organizers
16:33 Keep the momentum: do another one soon
17:01 What draws people to IdentiBeer?
17:37 The IdentiBeer charter and inclusivity
18:20 Elie Azerad and the San Francisco chapter
21:08 Tina and the South Bay satellite idea
25:50 Bertrand Carlier and plans for Paris
29:31 Varshith Reddy: tips for first-time Identiverse attendees
34:12 35 minutes without saying AI
36:20 Roland Baum and the Frankfurt Identivier
39:06 What is your drink of choice?
40:48 Tina's MFA rap and closing thoughts
Keywords: IdentiBeer, Identiverse 2026, IAM community, Identity and Access Management, Jeff Steadman, Jim McDonald, IDAC, Identity at the Center, Espen Bago, Marco Venuti, Heiko Klarl, Craig Ramsay, Tina Srivastava, Elie Azerad, Bertrand Carlier, Ole Shved, Roland Baum, Varshith Reddy, IDPro, community building, vendor neutral, IAM networking, Las Vegas

#433 - Sponsor Spotlight - FusionAuth
Jim McDonald sits down with Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, for an in-depth conversation on customer identity and access management. Dan explains how FusionAuth views authentication as the front door to any application and why control, deployment flexibility, and developer ownership are central to their approach. The discussion covers progressive registration, friction vs. usability, customization options, identity standards, the build vs. buy debate, risk-based MFA, and how AI agents will shape the future of customer identity. This episode and others is made possible with support from FusionAuth. Learn more at fusionauth.io/idac.
Connect with Dan: https://www.linkedin.com/in/mooreds/
Learn more about FusionAuth: https://fusionauth.io/idac
Blog article mentioned: https://bobdahacker.com/blog/fifa-hack
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:00:00 Introduction
00:01:18 What is FusionAuth?
00:03:15 Dan's identity origin story
00:04:19 Developer focus and ethos
00:06:54 Authentication as the front door
00:10:00 Balancing friction and usability
00:15:24 Customization in CIAM
00:18:10 What sets FusionAuth apart
00:20:33 FusionAuth's customer sweet spot
00:25:48 Deployment flexibility and the control spectrum
00:30:19 Common challenges in CIAM
00:33:06 Build vs. buy for authentication
00:36:00 Omni-channel authentication
00:40:27 Why identity standards matter
00:42:07 Risk-based MFA and intelligent challenges
00:45:00 AI agents and the future of CIAM
00:49:23 Closing thoughts
00:51:35 Vacation roundup
Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Moore, FusionAuth, CIAM, customer identity, authentication, access management, IAM, identity standards, MFA, risk-based authentication, progressive registration, OAuth, OIDC, SAML, AI agents, deployment flexibility, build vs buy, Sponsor Spotlight

#432 - IdentiBeer Rome and 3 Courses of IAM with Alessandro Piscopo
Jim McDonald takes the Identity at the Center podcast on the road to Rome, Italy, for a special two-part episode. The first segment is an IdentiBeer roundup where Jim gathers quick-fire takes from practitioners in the Italian IAM community, including Andrea Rossi and Alessandro Piscopo of IAMONES and Marco Venuti of Thales on the biggest trends shaping identity today. The second segment is a three-course meal where Jim sits down with Alessandro Piscopo, Head of AI and Co-founder at IAMONES, to discuss AI and identity over food and wine.
Across a seafood starter, scialatielli alla pescatora, and tiramisu, the conversation covers the history of AI in identity, why LLMs represent a revolution rather than an evolution, the AI-first product philosophy versus retrofitting AI onto legacy systems, compute and architecture constraints facing large language models, and what life looks like for the IAM practitioner in 2030. Alessandro envisions an identity equivalent of Claude Code, a specialized AI tool that democratizes identity expertise the way coding assistants have transformed software development.
0:00 Intro and IdentiBeer Rome roundup
7:01 Alessandro on AI for IAM vs. IAM for AI
12:00 Three-course dinner begins - Course 1: Seafood starter
14:09 History of AI in identity, from ML models to LLMs
17:51 Course 2: Scialatielli alla pescatora and Falanghina wine
19:56 AI-first products vs. AI layered onto legacy systems
22:00 Transition period and the new world of identity
24:04 The ChatGPT moment vs. the iPhone moment
27:05 Compute constraints, energy costs, and architecture breakthroughs
30:46 Smaller models and cost-efficiency tradeoffs
32:35 Course 3: Tiramisu, baba, and espresso
33:00 Life as an IAM practitioner in 2030
35:19 Claude Code for IAM and democratizing identity tools
37:24 App store ecosystem analogy for AI platforms
43:07 Closing thoughts
Keywords: IAM, identity and access management, AI for IAM, IAM for AI, agentic AI, non-human identity, IGA, LLMs, large language models, AI-first, machine learning, Alessandro Piscopo, IAMONES, Jim McDonald, Jeff Steadman, Identity at the Center, IDAC, IdentiBeer, Rome, Italy, Marco Venuti, Thales, Andrea Rossi, agentic identity, transformer architecture, compute efficiency, identity practitioner 2030, Claude Code for IAM, identity democratization, Identiverse, European Identity Conference

#431 - Tectonic Shifts in Identity Security with Martin Kuppinger
Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Kuppinger, founder and distinguished analyst at KuppingerCole. They dig into the tectonic shifts AI is bringing to identity and security, the AI security fabric framework, why decentralized identity thinking may be essential for governing the agentic mesh, the ongoing debate over NHI terminology, what organizations can do tactically today, and what concerns Martin most about where the industry is heading by 2030.
Connect with Martin: https://www.linkedin.com/in/martinkuppinger/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:00 Introduction and Welcome
00:50 What a Distinguished Analyst Does
01:37 EIC 2026: Thought Leadership and Best Practice
04:17 Agentic AI: Non-Directed, Non-Deterministic Identity
08:22 Speed of Change: Tactical Now, Strategic Later
12:34 The AI Security Fabric: Five Capability Blocks
15:10 Identity Fabric Origins and Market Growth
18:27 Discovery as the Foundation for Governance
19:48 Governance, Explainability, and Organizational Gaps
22:00 Agent Lineage and Rethinking NHI Terminology
23:50 LLMs vs. Small Language Models
26:23 Is Agentic Identity a Genuinely New Problem?
32:29 Humanoid Robots and the Limits of AI Reasoning
37:05 Decentralized Identity, Trust Frameworks, and Signals
41:07 Identity Verification and Consent for Agents
48:42 What Concerns Martin About the Future of Identity
50:34 Favorite AI Application: Assisted Driving
55:00 Self-Driving Cars, Data, and Personal Privacy
Keywords: Martin Kuppinger, KuppingerCole, EIC 2026, EIC Berlin, agentic AI, AI security fabric, identity fabric, decentralized identity, AI governance, non-human identity, autonomous identity, dependent identity, agent lineage, explainability, MCP server, small language models, verifiable credentials, risk-based authorization, OT security, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity security

#430 - AI for IAM and IAM for AI with Martin Sandren
Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Sandren, IAM Product Lead at IKEA, for a wide-ranging conversation covering nearly every corner of modern identity security. Martin shares what has changed since his first IDAC appearance on episode 293, including the rise of AI, growing interest in digital sovereignty, and the maturing shared signals framework. The conversation moves through risk-based defense in depth, tiered MFA rollout strategies, session management, and the real challenge of trusting AI to make security decisions. Martin introduces identity dark matter and explains how IVIP can surface the 95-plus percent of applications that never reach an IGA system. The episode also covers shadow AI, MCP server risks, the SaaSpocalypse debate, and the EU AI Act. It closes on a grounded note: solar panels.
Connect with Martin: https://www.linkedin.com/in/martinsandren/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS
00:00 Welcome and EIC 2026 intro
01:47 What has changed in two years: AI, sovereignty, shared signals
03:06 Martin's EIC presentations: AI for IAM and IAM for AI
04:46 Can you prioritize one direction over the other?
07:13 What would it take to trust AI making identity decisions?
09:32 AI-enhanced detection and risk-based session management
13:07 Session invalidation and the shared signals framework
14:11 Defense in depth and right-sizing privileges
18:25 MFA today: any MFA versus phish-resistant MFA
19:17 AI chatbots, enterprise LLMs, and shadow AI
23:11 MCP servers, NHI risk, and return on risk thinking
27:00 AI configuring IAM systems: how close are we?
31:30 LLM costs, the SaaSpocalypse, and enterprise AI futures
40:10 Identity dark matter and the IVIP concept
44:16 CMDB versus IVIP: do you need both?
46:18 The EU AI Act and building an AI governance registry
49:18 Where to start: get your AI inventory in place first
50:00 Closing thoughts and the solar panel tangent
KEYWORDS
AI for IAM, IAM for AI, identity dark matter, IVIP, IGA, shared signals framework, phish-resistant MFA, defense in depth, session management, MCP servers, NHI, shadow AI, SaaSpocalypse, EU AI Act, AI governance, zero standing privilege, EIC 2026, IKEA, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Martin Sandren

#429 - Sponsor Spotlight - SailPoint
This episode is presented courtesy of SailPoint. Rob Sebaugh, Senior Identity Strategist at SailPoint, joins Jeff and Jim for a wide-ranging conversation on the past, present, and future of identity governance. Rob brings more than two decades of practitioner experience to the table, including 16 years running large-scale identity programs before making the move to the vendor side. The conversation covers what identity governance means today, why it must move to the forefront rather than be treated as an afterthought in an agentic world, and how organizations need to think fundamentally differently about non-human identities. Jeff and Jim explore the concept of treating AI as a first-class identity, how AI is beginning to replace rubber-stamp access certifications, the shift toward policy-based access control, and the practical path toward zero standing privilege. The episode wraps with a lighter conversation about Rob's 3D printing hobby.
About SailPoint:
SailPoint (Nasdaq: SAIL) is defining the new era of adaptive identity security. In a world where non-human identities now significantly outnumber humans, our AI-powered platform unifies identity, security, and data intelligence to protect today’s enterprise from advanced identity-based threats. We deliver the identity solution that spans both the breadth of identities and the depth of context needed to drive real-time access with confidence. Built on principles like zero-standing privilege and contextualized risk, our SailPoint platform transforms identity from a point of vulnerability into a powerful security advantage. Trusted by many of the world's leading organizations, SailPoint secures the enterprise with intelligent, autonomous identity security.
Learn more about SailPoint: https://www.sailpoint.com/
Connect with Rob: https://www.linkedin.com/in/rob-sebaugh-1ba9013/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps:
00:00 Introduction
00:48 Rob Sebaugh and the identity strategist role at SailPoint
04:38 Practitioner advice from the field
07:49 What SailPoint does: the hotel key analogy
11:04 Buying identity technology means buying a business process
13:30 What identity governance is and why it still matters
16:47 Risk-appropriate governance and privileged access
19:39 Non-human identities and the scale of the agentic challenge
22:57 Treating AI as a first-class identity
24:28 When AI makes governance decisions: beyond rubber stamping
28:04 Is identity governance a binary decision?
29:58 Securing data inside AI and large language models
34:09 Identity: the field that reinvents itself
35:01 Identity as the new control plane
37:21 Is all access privileged access?
40:25 Zero standing privilege in practice
44:22 Innovation, continuous identity, and what SailPoint is building
46:28 Identity posture management
50:13 Practitioner advice for the next three to five years
53:00 The future of IGA in ten years
57:44 Lighter note: 3D printing with Rob Sebaugh
1:05:35 Final thoughts on SailPoint
Keywords: Rob Sebaugh, SailPoint, identity governance, identity security, IGA, non-human identities, agentic AI, zero standing privilege, just-in-time access, identity posture management, control plane, zero trust, policy-based access control, AI certification, rubber stamping, sponsor spotlight, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#428 - Modernizing IGA with Thomas Zarnhofer
Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Thomas Zarnhofer, IAM Architect at a major retail company in central Europe. Thomas shares his experience leading a full IGA transformation from a decade-old on-premise system to a modern cloud-based platform. The conversation covers the shift from a contract-based to a person-based identity model, the importance of cleaning data before migration begins, a three-phase framework of Foundation, Migration, and Adoption, lessons learned from running two systems in parallel, and a look at how AI could make IGA predictive. The episode ends with Thomas's tips for visiting Austria.
Connect with Thomas: https://www.linkedin.com/in/tzarnhofer/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps
00:00 Introduction and EIC 2026 Setting
02:00 Thomas's Identity Origin Story
04:21 The Catalyst for IGA Modernization
07:43 Contract-Based vs Person-Based Identity Models
09:22 Consolidating Master Data Sources
11:39 Data Quality and Attribute Ownership
13:34 Partnering with HR for Clean Data
16:43 Data Analysis: Why They Chose Excel Over AI
17:53 Clean Your Data Before You Migrate
18:23 The Three Phases: Foundation, Migration, Adoption
20:12 Driving Adoption Across the Organization
21:10 Running Two Systems in Parallel
22:47 Challenge Everything vs Lift and Shift
27:23 Surprises in the Cloud IGA Journey
29:02 Testing Requirements in the Cloud
29:51 AI and the Future of IGA
32:25 AI Chatbots and Role Discovery
35:30 Scoping Business Role Visibility
36:06 Life Outside IAM: Travel and Austria Tips
Keywords:
IAM, IGA, Identity Governance, IGA Migration, On-Premises to Cloud, Identity Model, Contract-Based Identity, Person-Based Identity, Master Data, Data Quality, HR Integration, Joiner Mover Leaver, Cloud IGA, Retail IAM, EIC 2026, AI in IGA, Predictive IGA, Role Management, Access Governance, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Thomas Zarnhofer

#427 - Identiverse 2026 Preview with Heather Flanagan and Andi Hindle
Jeff and Jim are joined by Heather Flanagan, Content Chair, and Andi Hindle, Conference Chair, for a full preview of Identiverse 2026 at Mandalay Bay in Las Vegas. They cover the 2026 theme of trust and change, why AI was removed as a standalone track and redistributed across all content areas, the provocative argument that non-human access now dramatically outpaces human access and is reshaping identity system design, whether authentication is truly solved, authorization as the harder unsolved problem, CFP surprises, networking events including Women at Identiverse, and predictions for 2027. Save 30% with code IDV26-IDAC30%. New IDPro members save $25 at idpro.org/idac.
Connect with Heather: https://www.linkedin.com/in/hlflanagan/
Connect with Andi: https://www.linkedin.com/in/ahindle/
Identiverse 2026: https://events.identiverse.com/2026/begin?code=IDV26-IDAC30%25
Heather's IAM Conference List: https://github.com/fedidcg/meetings/wiki/2026-List-of-Identity-and-Related-Conferences-and-Standards-Development-Events
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS
00:00:00 Introduction and SolarWinds breach banter
00:03:27 Identiverse preview and discount codes
00:06:10 Guest introductions
00:06:52 Role of Content Chair
00:08:46 Role of Conference Chair
00:11:16 2026 conference theme
00:15:00 AI as context, not a standalone track
00:16:32 Control plane vs enablement plane debate
00:22:19 What the industry is underestimating
00:24:00 Non-human access outpaces human access
00:26:52 Is authentication solved? Passkeys
00:30:31 Authorization: far from solved
00:36:04 Extensibility in standards and deployments
00:38:22 CFP surprises: fraud and identity proofing
00:41:48 Usability and UX gaps
00:43:18 Agentic AI: identity or governance?
00:47:55 Networking and newcomer programming
00:51:45 Women at Identiverse
00:52:46 AI-generated CFP submissions
00:55:00 Predictions for Identiverse 2027
00:58:04 Theme songs for Identiverse 2026
01:02:58 Heather's identity conference list on GitHub
01:04:47 Swag culture at identity conferences
01:12:25 Wrap-up
KEYWORDS
Identiverse 2026, Heather Flanagan, Andi Hindle, identity conference, NHI, non-human identity, agentic AI, passkeys, authentication, authorization, IAM, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, digital identity, continuous identity architecture, zero standing privilege, verifiable credentials, identity governance

#426 - Sponsor Spotlight - Crowdstrike
This episode and the Identity at the Center podcast is supported by CrowdStrike. Learn more at crowdstrike.com.
Jeff Steadman and Jim McDonald sit down with Scott Kriz, GM of Continuous Identity at CrowdStrike, for a deep dive into continuous identity, zero standing access, and the convergence of identity and security. Scott traces his path from co-founding Bitium, to selling it to Google Cloud, to building SGNL and ultimately joining CrowdStrike. The conversation covers how continuous identity works in practice, why traditional PAM and IGA fall short in a real-time world, and what the rise of agentic AI means for identity governance at scale.
Connect with Scott: https://www.linkedin.com/in/scottkriz/
Learn more about Crowdstrike: https://www.crowdstrike.com/en-us/platform/next-gen-identity-security/caep/?idac
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:00:00 Introduction and welcome
00:01:21 How Scott got into identity and co-founded Bitium
00:03:55 Selling to Google Cloud and the inspiration for SGNL
00:05:02 Continuous identity and zero standing access explained
00:09:13 Defining continuous identity at CrowdStrike
00:10:20 How continuous identity differs from PAM and IGA
00:15:06 Data as the foundation for continuous identity
00:19:29 Open ecosystems, Shared Signals Framework, and CAEP
00:25:26 Agents, identity chaining, SPIFFE, SPIRE, and MCP gateways
00:33:02 Identity inside CrowdStrike's broader security strategy
00:37:27 Identity security budgets and ROI-driven purchasing
00:40:04 Agentic scale and the need for automated identity controls
00:43:39 The SGNL acquisition: what it means for both companies
00:50:25 Zero trust as a real architectural framework
00:54:00 Helicopter skiing, avalanches, and staying present
Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Scott Kriz, CrowdStrike, SGNL, continuous identity, zero standing access, PAM, IGA, zero trust, agentic AI, non-human identity, NHI, SPIFFE, SPIRE, MCP, identity security, real-time authorization, cybersecurity

#425 - EIC 2026 Recap & IdentiBeer Berlin
Jeff and Jim recap their week at KuppingerCole's EIC 2026 in Berlin, covering standout keynotes, hallway conversations, and sessions on securing AI agents, CIAM, and AI versus nuclear regulation. They announce a giveaway of Eve Maler's signed copy of Mastering Digital Identity for YouTube commenters by June 12th. The episode also features live footage and a full interview with Espen Bago, founder of IdentiBeer, recorded at the Berlin event. Jeff, Jim, and Espen discuss the rapid global growth of the IdentiBeer community, terminology challenges around NHI and IAM concepts, the gap between conference talk and real client needs, and why the industry keeps bypassing foundational data work in the rush toward AI and agentic identity.
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:00:10 Welcome and EIC 2026 Setup
00:03:57 Eve Maler Book Giveaway Details
00:05:00 Conference Highlights: Keynotes and Hallway Con
00:06:07 Elizabeth Garber's Standing Ovation Keynote
00:07:02 Brazil Invitation and Securing AI Agents
00:09:10 Nuclear Regulation vs. AI Regulation
00:11:07 Upcoming EIC Episode Preview
00:14:16 IdentiBeer Berlin Live Event
00:14:29 Interview with Espen Bago Begins
00:15:14 IdentiBeer Growth and Global Expansion
00:17:23 The IdentiBeer Name Debate
00:23:26 Data Quality Gaps in NHI and IAM
00:26:31 Who Owns IAM Terminology?
00:34:20 Conference Talk vs. Client Reality
00:40:52 The HR-IAM Gap Nobody Talks About
00:43:17 Fundamentals: The Karate Kid Analogy
Keywords: EIC 2026, European Identity Conference, IdentiBeer, Espen Bago, Eve Maler, Elizabeth Garber, Mastering Digital Identity, Berlin, Identiverse, NHI, non-human identities, IAM fundamentals, AI regulation, agentic identity, IGA, PAM, CIAM, IDPro, identity community, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#424 - IDAC Mailbag for May 2026
Jeff and Jim are back with the May 2026 mailbag, answering listener questions from Amsterdam, Mumbai, Austin, and Berlin. Topics include navigating IAM vendor acquisitions, defending against AI deepfakes in remote onboarding, governing contractor and third-party identities, fixing the leaver process in IGA, and tackling a decade of IAM technical debt. The episode closes with unpopular industry opinions: why RFPs are procurement theater, why rip and replace should be normalized, and why one-throat-to-choke vendor thinking usually backfires.
IDPro new member discount: https://idpro.org/idac/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
CHAPTER TIMESTAMPS
00:00 Intro and SNL nostalgia
03:25 AI model roundup: ChatGPT, Claude, Gemini, and usage limits
10:16 Identiverse 2026 and IDPro member discount
14:53 Q1: Navigating vendor acquisitions (Isabelle, Amsterdam)
24:00 Q2: AI deepfakes in identity verification (Rajan, Mumbai)
32:32 Q3: Contractor and third-party identity governance (Caleb, Austin)
43:00 Q4: The leaver process and IGA scope gaps (Anonymous)
51:10 Q5: Tackling IAM technical debt (Tomas, Berlin)
57:00 Normalizing rip and replace
01:01:00 RFPs, one throat to choke, and other hot takes
01:08:00 Wrap-up
KEYWORDS
IAM, identity governance, IGA, vendor consolidation, acquisitions, deepfakes, identity verification, contractor management, non-employee identity, technical debt, rip and replace, RFP, joiner mover leaver, leaver process, Identiverse 2026, IDPro, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#423 - The Middle Market Identity Security Gap with Robert Snodgrass
Jeff and Jim welcome back Robert Snodgrass, Principal at RSM, for a deep dive into the RSM Middle Market Business Index cybersecurity report. The conversation covers the confidence gap facing middle market organizations, why digital identity remains undervalued despite being the primary attack surface, non-human identity governance, flat cybersecurity budgets, risk framework adoption, and what good incident response preparedness actually looks like. The episode wraps with a spirited Bitcoin Pizza Day toppings debate.
Connect with Robert: https://www.linkedin.com/in/robert-snodgrass-7a199412/
Review the RSM US Middle Market Business Index Special Report on Cybersecurity 2026: https://rsmus.com/middle-market/cybersecurity-mmbi.html?cmpid=ola:45559-idac:bb01
IDPro new member discount: https://idpro.org/idac/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS
00:00:00 Introduction and Scatter Spider social engineering discussion
00:04:00 IDPro discount code and upcoming conferences
00:06:26 Guest intro: Robert Snodgrass and the MMBI report
00:09:05 Defining the modern middle market
00:12:00 The confidence gap: 96% confident, 18% breached
00:15:04 Why attackers log in and top identity investment priorities
00:19:00 Why only 23% of leaders prioritize digital identity
00:22:00 Internal partnerships as the path to identity program success
00:25:10 AI, shadow AI, and non-human identity risks
00:31:00 NHI governance at scale: 45 to 1 ratio
00:34:50 Cybersecurity budget realities in the middle market
00:39:00 EU regulation and top-line cybersecurity drivers
00:42:03 NIST CSF adoption and risk framework value
00:46:00 Incident response planning: the two-minute drill
00:52:16 Bitcoin Pizza Day and closing thoughts
KEYWORDS
identity security, middle market, cybersecurity, MMBI, RSM, Robert Snodgrass, phishing-resistant MFA, non-human identities, NHI, shadow AI, incident response, NIST CSF, IAM, identity governance, ransomware, tabletop exercises, digital identity, cybersecurity budget, identity program, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#422 - Decoded - Securing AI Agents with Standards You Already Have
Episode 422 is the debut of Decoded by Identity at the Center, a new sub-series hosted by Jeff Steadman and Sean O'Dell dedicated to unpacking the specifications and standards powering IAM. Joining them is Pieter Kasselman, VP of Open Standards at Defakto and chair of the WIMSE working group. The conversation covers why traditional non-human identity approaches break at agentic scale, how SPIFFE and SPIRE enable short-lived automated credential provisioning without long-lived secrets, and why treating agents as workloads unlocks a decade of existing standards. Pieter walks through critical OAuth specs including JWT authorization grant, token exchange, client ID metadata, and the emerging transaction tokens draft. Sean connects these to practical gateway architecture, continuous access evaluation, and policy-based authorization. The episode closes with real-world deployment examples and a clear takeaway: the tools to secure agentic identity are available today.
Episode Links:Pieter Kasselman: https://www.linkedin.com/in/pieter-kasselman-0259862/AI Agent Authentication and Authorization: https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/Workload Identity in Multi-system environments (WIMSE): https://ietf-wg-wimse.github.io/OAuth SPIFFE Client Authentication: https://datatracker.ietf.org/doc/draft-ietf-oauth-spiffe-client-auth/Transaction Tokens: https://datatracker.ietf.org/doc/draft-ietf-oauth-transaction-tokens/08/Agentic Identity Control Framework. You Already Have the Pieces. Now Build It. by Sean O'Dell: https://www.linkedin.com/pulse/agentic-identity-control-framework-you-already-have-pieces-o-dell-61b5e/
Timestamps:
00:00 Introduction to Decoded by Identity at the Center
00:13 The mission of the Decoded sub-series
03:02 Guest intro: Pieter Kasselman, VP of Open Standards at Defakto
06:21 Why agentic identity is urgent: scale, multi-platform, and shifting threat landscape
10:42 The real cost of API keys and credential sprawl in agentic systems
13:23 Agentic identity identifiers and how SPIFFE assigns unique workload IDs
21:00 Credential types: X.509, JWTs, and workload identity tokens
31:00 Connecting SPIFFE to OAuth and dynamic registration with client ID metadata
38:18 SPIFFE SVIDs, multiple credentials per agent, and governance traceability
41:44 Authentication versus authorization: delegation versus impersonation
47:00 Transaction tokens: binding access to specific transactions to stop token theft
51:21 Identity chaining and cross-domain authorization
55:00 Shared Signals Framework and dynamic authorization
57:00 Gateways, CAEP, and mid-flight token revocation for rogue agents
59:31 What you can deploy today with SPIFFE, OAuth, and existing IDPs
01:02:58 Policy-based access control and why instance-level governance cannot scale
01:04:58 Workload identity federation: Anthropic and Google Agent ID updates
01:07:13 Cross-platform federation and the law of agentic utility
01:11:55 Elevator pitch: agents are workloads and 95% of the problem is solved now
01:17:03 What is coming next: a transaction tokens deep dive
Keywords:
agentic identity, SPIFFE, SPIRE, OAuth, transaction tokens, Shared Signals Framework, WIMSE, workload identity, non-human identity, authorization delegation, JWT, CAEP, API gateway, IAM standards, AIMS, Jeff Steadman, Sean O'Dell, Pieter Kasselman, IDAC, Identity at the Center, Jim McDonald, Decoded by Identity at the Center
Decoded by Identity at the Center:
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Sean O'Dell: https://www.linkedin.com/in/seanodentity/
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Visit the show on the web at https://idacdecoded.com/

#421 - The AI Identity Control Plane with Henrique Teixeira
Jeff and Jim welcome back Henrique Teixeira, SVP of Strategy at Saviynt, for his fourth appearance on the podcast. The episode opens with Jim's firsthand experience building an AI agent for a work project and discovering in real time how identity management challenges surface in the agentic era. After conference updates on EIC in Berlin and Identiverse in Las Vegas, Henrique unpacks the crowded terminology around AI agent governance, from Gartner's agent management platforms to UADP, the Unified Agentic Defense Platform. He proposes a three-pillar framework for managing AI and non-human identities: discovery, identity lifecycle and governance, and runtime access management, with guidance on where to start depending on whether your organization is greenfield or legacy-heavy. The conversation then examines how AI is reshaping the analyst business model, what makes information sources trustworthy, and how proprietary inquiry data forms the real competitive moat for firms like Gartner and Forrester. The episode closes with a wide-ranging discussion on AI's risk to shared cultural experiences, hyper-personalized entertainment, and the ethics of licensing your digital identity in the afterlife.
Connect with Henrique: https://www.linkedin.com/in/bernardes/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:00:00 Intro
00:00:55 Jim's AI Agent Experiment and Identity Lessons
00:06:04 Conference News: EIC and Identiverse
00:07:22 Identity Beer Community Events
00:08:40 Introducing Henrique Teixeira
00:12:00 AI Control Plane: Competing Terminologies
00:17:36 Three Pillars of AI Agent Identity Management
00:18:46 Why Visibility Matters More for NHI
00:20:00 Ownership, Accountability, and Humans at the Control Plane
00:24:26 Industry Maturity and the Gaps That Remain
00:25:41 Where to Start: Governance-First vs. Visibility-First
00:29:52 AI's Impact on the Analyst Profession
00:34:57 What Analyst Firms Have That AI Cannot Replace
00:39:04 Trust, Boutique Analysts, and Repeatability
00:44:34 Proprietary AI Chatbots and Gated Intelligence
00:49:30 IP Rights and the Legal Gray Zone of AI Training
00:52:14 AI and the Erosion of Shared Cultural Experience
00:58:00 AI Music, Personalized Entertainment, and the Future of Art
01:03:47 Digital Afterlife, Voice Clones, and AI Personas
01:08:18 Wrap-Up and Closing
Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Henrique Teixeira, Saviynt, AI identity control plane, non-human identities, NHI, agentic AI, AI agents, AI governance, identity lifecycle, access management, discovery, agent management platform, UADP, IAM, Gartner, analyst firms, AI and culture, digital identity, identity security, EIC, Identiverse, identity beer

#420 - Sponsor Spotlight - GitGuardian
This episode is made possible by GitGuardian. Jeff speaks with Dwayne McDaniel, Principal Developer Advocate at GitGuardian, about secrets sprawl, non-human identity governance, and the findings of the State of Secret Sprawl 2026 report. With 28.6 million secrets leaked to public GitHub in 2025 - a 34% year-over-year increase - they explore why hardcoded credentials persist, how agentic AI tools are making the problem worse, and what IAM practitioners can do to start addressing machine identity governance. Topics include GitGuardian's Good Samaritan notification program, the growing NHI inventory challenge, SPIFFE and SPIRE as a path to zero standing privilege, and data showing Claude Code co-authored commits are more than twice as likely to contain leaked secrets. Visit gitguardian.com/lps/idac to learn more.
Connect with Dwayne: https://www.linkedin.com/in/dwaynemcdaniel/
Dwayne's website: https://dwayne-mcdaniel.com/
Learn more about GitGuardian: https://www.gitguardian.com/lps/idac
GitGuardian Good Samaritan Program (free) - https://www.gitguardian.com/good-samaritan
The State of Secrets Sprawl 2026: https://www.gitguardian.com/state-of-secrets-sprawl-report-2026
SPIFFE Book: https://spiffe.io/book/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS:
00:00 Introduction and sponsor welcome
00:48 Dwayne's background and path to developer advocacy
04:11 Surprises from entering the identity and security space
06:29 What a principal developer advocate actually does
09:32 Why secrets became Dwayne's focus area
14:10 GitGuardian: overview and mission
19:36 Where secrets commonly leak across the SDLC
22:17 The Good Samaritan notification program explained
28:00 Why 70% of leaked secrets from 2022 were still valid in 2025
33:54 State of Secret Sprawl 2026: the year software changed
40:39 AI coding tools, Claude Code, and secrets leakage data
47:28 Practical questions for IAM practitioners to start asking
52:24 Zero standing privilege and the case for SPIFFE/SPIRE
01:00:00 Resources: the SPIFFE book, WIMSE, and AWS STS
01:02:51 Hot sauce, the Cubs, and closing thoughts
KEYWORDS:
secrets sprawl, hardcoded secrets, non-human identity, NHI governance, GitGuardian, SPIFFE, SPIRE, workload identity, DevSecOps, agentic AI, Claude Code, zero standing privilege, supply chain security, credential abuse, identity and access management, IAM, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dwayne McDaniel

#419 - Identity Management Day 2026 - IDAC Live
Recorded live as part of the Identity Management Day 2026 streaming program, Jeff and Jim mark their fifth IMD episode. Introduced by Jeff Reich from the Identity Defined Security Alliance, they reflect on how the IAM industry has evolved since their first IMD episode in 2021 and grade overall progress a C. Topics include what has genuinely improved (passkeys, MFA adoption, broader awareness), what hasn't (compliance fatigue, security theater, persistent credential theft), the exploding challenge of non-human identity governance, whether AI will eventually need to certify other AI, and how AI-powered phishing and deep fakes are raising the bar for identity verification. The episode wraps with chat-submitted IAM bumper stickers.
Identity Management Day 2026: https://www.idsalliance.org/event/identity-management-day-2026/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
CHAPTERS
0:00 - Jeff Reich intro from the IMD stream
2:00 - Identity Management Day 2026 kicks off
3:30 - Five years of IMD: a look back at episode 88
7:00 - Does IMD move the needle?
9:30 - Who is Identity Management Day actually for?
12:00 - What has improved in IAM over five years
16:00 - What hasn't improved: compliance fatigue and security theater
18:30 - Grading the IAM industry
21:00 - NHI governance: visibility and accountability
26:00 - Can AI certify AI? Agentic identity governance
29:00 - AI-powered phishing and the evolving threat landscape
32:00 - Deep fakes and the identity verification challenge
36:00 - Lighter note: IAM bumper stickers
KEYWORDS
identity management day, identity management day 2026, NHI, non-human identity, agentic AI, phishing, deep fakes, IGA, passkeys, MFA, IAM, identity governance, access management, cybersecurity, credential theft, security awareness, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#418 - Ethical IAM with Elizabeth Garber
What does it mean to build an identity system that is ethical? Jim McDonald and Jeff Steadman are joined by Elizabeth Garber, Executive Director of IDPro and marketing lead for the OpenID Foundation, for a conversation spanning ethics in digital identity, the tension between privacy and safety, biometric exclusion risks, and how practitioners can use structured frameworks to navigate these discussions productively. Elizabeth shares her three-part career journey, the latest from the IDPro community, and previews her upcoming keynotes at EIC Berlin and Identiverse Las Vegas.
Connect with Elizabeth: https://www.linkedin.com/in/elizabethgarber
IDPro Discount - New members get $25 off their first year of membership: https://idpro.org/idac/
Ethics and Digital Identity by Henk Marsman: https://bok.idpro.org/article/id/104/
Ethics for Digital Identity and Identity-Driven Algorithms by Mike Kiser: https://bok.idpro.org/article/id/105/
Human Centric Digital Identity white paper: https://openid.net/wp-content/uploads/2023/10/Human-Centric_Digital_Identity_Final-v1.1.pdf
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps:
00:00 Intro and Jim's allergy research
03:42 Conference announcements: EIC and Identiverse
06:00 Welcome Elizabeth Garber
07:04 Elizabeth's three-part origin story
11:55 IDPro mission and the identity community
18:13 Membership, CIDPRO certification, and the Body of Knowledge
21:17 IDPro Slack community
23:40 IdentiBeer and local meetups
26:26 IDPro listener discount at idpro.org/idac
29:00 Operationalizing ideas in IAM
32:19 Ethics in the IDPro Body of Knowledge
33:30 Defining ethics in technology
34:19 The trolley problem and moral consistency
37:10 Big tech, privacy, and law enforcement
39:28 Where practitioners start with ethics
43:30 Biometric exclusion and the Uganda story
49:00 Privacy vs. safety: a false choice?
53:48 The case for consistent ethical frameworks
57:53 Elizabeth's EIC and Identiverse talks
59:49 Improv comedy and expensive hobbies
1:07:25 Wrap-up
Keywords: ethical IAM, digital identity ethics, IDPro, identity and access management, privacy, safety, biometrics, exclusion, Elizabeth Garber, GAIN Digital Trust, OpenID Foundation, Body of Knowledge, Ethical Canvas, zero knowledge proofs, passkeys, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, EIC Berlin, Identiverse

#417 - Sponsor Spotlight - Elimity
This bonus episode of Identity at the Center is brought to you with support from Elimity. Jeff and Jim sit down with Maarten Decat, co-founder and CEO of Elimity, to explore the emerging product category known as IVIP, Identity Visibility and Intelligence Platforms. Maarten explains how Elimity was built around a question every IAM practitioner eventually faces: who can actually do what within our organization? The conversation covers why IVIP is distinct from traditional IGA, how identity data graphs provide deeper visibility than flat entitlement lists, and what regulatory drivers like SOC 2, ISO 27001, and DORA are pushing organizations toward this space. They also discuss deployment patterns, integration approaches, ROI metrics for leadership, and what Maarten calls provable control. The episode closes with a memorable story about Elimity branded Belgian beer and a very formal legal letter. Learn more at elimity.com/idac.
Connect with Maarten: https://www.linkedin.com/in/maartendecat/
Learn more about Elimity: https://elimity.com/idac
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
CHAPTER TIMESTAMPS
00:00 Introduction and ax-throwing memories from EIC Berlin
01:35 Introducing Maarten Decat, co-founder and CEO of Elimity
01:57 How identity chose Maarten: from PhD to startup founder
03:09 The Elimity origin story and the problem it set out to solve
04:52 Defining IVIP: Identity Visibility and Intelligence Platforms
05:31 Where did the name Elimity come from?
06:57 Why identity visibility has become a security priority now
09:02 What organizations were doing before IVIP existed
11:16 Can IGA do what IVIP does? Addressing the skeptics
14:20 The identity data graph: deeper and wider than IGA
16:20 IVIP and IGA as complementary tools, not competitors
16:49 What falls outside IVIP scope: automated provisioning
18:01 IVIP as the intelligence layer in your IAM stack
19:45 What data sources connect into an IVIP platform
21:44 Extending visibility to non-human identities
22:00 M&A use cases: gaining visibility across two organizations
23:55 IVIP and the identity fabric concept
25:18 Visibility, intelligence, and actions: building the right stack
26:36 How deployments typically start and what early wins look like
28:44 Integration approaches and realistic effort timelines
32:00 What success looks like at six to twelve months
36:07 Metrics and ROI: talking to leadership about identity risk
38:14 Case studies and customer examples on the Elimity website
38:58 What every IAM practitioner should know about IVIP
40:12 Elimity's global reach: EU, US, and Middle East
41:42 The Elimity branded beer story and a very formal legal letter
46:43 Wrap-up and final thoughts
KEYWORDS
IVIP, identity visibility and intelligence platforms, IGA, identity governance, access control, identity data graph, Elimity, Maarten Decat, non-human identities, access risk, provable control, SOC 2, ISO 27001, DORA, CCPA, cybersecurity, PAM, IAM, identity and access management, EIC, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#416 - European Identity and Cloud Conference 2026 Preview with Warwick Ashford
Jeff and Jim are joined by Warwick Ashford, senior analyst at KuppingerCole and returning MC of the European Identity and Cloud Conference, for a full preview of EIC 2026. The conference runs May 19-22 at the Berlin Congress Center and is expecting around 1,500 attendees with roughly 250 speakers across 200 sessions. Warwick walks through the 2026 tagline, Digital Trust Through Intelligent Identity, and unpacks the five parallel content streams covering identity governance, real-world IAM use cases, emerging tech, enterprise infrastructure, and privacy and compliance. The conversation covers how AI and agentic identity have moved from theory to a central agenda theme, what to know about the quantum-safe identity block, why EU digital wallets and digital sovereignty are getting serious keynote time, and why EIC records everything so you never have to pick the wrong session. Jeff also shares his take on where EIC fits in the broader conference calendar alongside Identiverse and Gartner, and why he is thoroughly done hearing that identity is the new perimeter.
Connect with Warwick: https://www.linkedin.com/in/warwickashford/
Attend European Identity and Cloud Conference 2026 (use code idac25mko for a 25% discount): https://www.kuppingercole.com/events/eic2026?ref=partneridac26
Secure Remote Access: The Foundation of Industrial Cybersecurity (KC Analyst Chat Video): https://www.youtube.com/watch?v=jqpNg-ogEv4
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:00:00 Intro and AI Cybersecurity Discussion
00:04:00 EIC 2026 and Discount Code
00:05:47 Introducing Warwick Ashford
00:07:00 Warwick's Recent Work: MDR, SRA for OT/ICS, and TPAG
00:10:16 The History and Evolution of the EIC Name
00:11:00 Tagline: Digital Trust Through Intelligent Identity
00:12:10 How AI Has Elevated the EIC Agenda
00:14:49 Sessions vs Workshops at EIC
00:17:57 EIC as a Community and Networking Conference
00:18:00 Jeff's Conference Circuit: EIC, Identiverse, and Gartner
00:25:28 EIC 2026 Keynote Highlights
00:31:55 Virtual Attendance and Session Recordings
00:34:34 Hidden Gem: The Quantum-Safe Identity Block
00:36:15 Logistics: 1500 Attendees and 250 Speakers
00:38:00 The Five Parallel Content Streams
00:43:31 Is Identity the New Perimeter?
00:48:13 Fun Segment: Most Memorable Theater Moments
Keywords: EIC 2026, European Identity Conference, Warwick Ashford, KuppingerCole, digital trust, intelligent identity, agentic identity, non-human identities, ITDR, quantum-safe identity, EU digital wallets, identity fabric, identity control plane, IAM, zero trust, Berlin, conference preview, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Warwick Ashford

#415 - Identity Management Day 2026 with Jeff Reich
Jeff and Jim welcome back five-time guest Jeff Reich, Executive Director of the Identity Defined Security Alliance, just ahead of Identity Management Day 2026 on April 14th. Jeff walks through the structure of the 21-hour global event, this year's theme of Finding Identity: The Search for You, Me, and the Machines, and highlights from each regional program including a remarkable 11th grader presenting on cybersecurity and neuroscience. The conversation expands into AI guardrails, the growing obsolescence of traditional PAM, zero standing privilege as a long-term goal, the march toward a passwordless world through passkeys, and what quantum resilience actually means for practitioners today.
Connect with Jeff: https://www.linkedin.com/in/jreich/
Learn more about the Identity Defined Security Alliance: https://www.idsalliance.org/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps:
00:00 Welcome and podcast life behind the scenes
02:00 Identiverse 2026 updates and conference discount codes
05:00 Introducing Jeff Reich, Executive Director of IDSA
07:00 Identity Management Day: structure of a 21-hour global event
11:00 Oceania and Asia region highlights
13:30 EMEA highlights and powerhouse panelists from Copenhagen
16:00 Americas region and the 11th grader presenting on cybersecurity
20:00 Theme reveal: Finding Identity, The Search for You, Me, and the Machines
23:30 AI and identity: guardrails, frameworks, and what organizations are missing
28:30 Standing privilege is crumbling in the age of ephemeral workloads
30:00 Is traditional PAM becoming obsolete?
34:30 Zero standing privilege and the passkey journey
40:30 Getting the fundamentals right before chasing the shiny tools
46:30 Quantum computing, quantum resilience, and cryptocurrency risk
53:00 Social engineering is still the biggest threat
55:00 Identity Management Day theme song suggestions
Keywords:
Identity Management Day 2026, IDSA, Identity Defined Security Alliance, Jeff Reich, IAM, non-human identities, machine identities, agentic identity, zero standing privilege, PAM, passkeys, quantum resilience, AI and identity, deepfakes, social engineering, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#414 - Sponsor Spotlight - Evolveum
This sponsored episode is made possible by Evolveum, the company behind midPoint, an open source IGA platform made and owned in the EU that is in use worldwide.
Jeff Steadman and Jim McDonald welcome Pavol Mederly, interim CPO at Evolveum. Pavol shares how IAM found him in 1991 while building an identity solution at a university before the term even existed.
The conversation covers two core reasons IGA projects fail: data quality and slow application onboarding. Pavol explains how midPoint addresses these challenges with built-in simulations for testing and improving data quality, and midPilot, an AI assistant for faster application onboarding. MidPilot is supported in part by the EU Recovery and Resilience Facility (RRF). Jim and Jeff explore midPoint's architecture, the real benefits of open source including transparency and no vendor lock-in, and advantages of being part of midPoint’s global community.
Connect with Pavol: https://www.linkedin.com/in/pavol-mederly/
More about Evolveum: https://evolveum.com/idac
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
TIMESTAMPS:
00:00 Intro and sponsor acknowledgment
01:30 How IAM chose Pavol: a university identity story
03:30 What is Evolveum and midPoint
06:30 How Evolveum got its name
08:30 Why IGA projects fail: data quality
10:30 Slow app onboarding and AI-assisted connector generation
16:30 The midPoint simulation feature explained
21:30 midPoint architecture: Java, cloud, Kubernetes, and beyond
23:30 Maintaining a large open source codebase
25:30 Open source benefits: transparency and no vendor lock-in
28:00 Community, meetups, and midPoint in the wild
32:30 Mountains or ocean: a question for Pavol
38:00 Wrap up
KEYWORDS:
Evolveum, midPoint, open source IGA, identity governance, IAM, IGA, data quality, application onboarding, simulation, AI connectors, connector framework, vendor lock-in, open source, EU RRF, Recovery and Resilience Facility, community, Prague, EIC, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Pavol Mederly

#413 - Standards, AI Agents, and the Digital Estate with Heather Flanagan
Jeff and Jim welcome back Heather Flanagan for her fifth appearance on the show. Heather shares updates across a wide range of current work including her new role as content chair for the Identiverse conference, an appointment to the W3C Technical Architecture Group, ongoing support for NIST and NCCOE, advising the SIROS Foundation open source wallet project, and the continued growth of the Identity Salon. The conversation explores who is actually building identity standards for AI agents and whether traditional standards bodies can keep pace with AI development. Heather breaks down the authentication challenges posed by agentic AI, the problem of continuous identity and delegation, and why posting a spec on your website does not make it a standard. The discussion shifts to national digital identity programs in the US and Europe, the underserved relying party problem in credential frameworks, and why financial services may be the next major proving ground for mobile driver's licenses. The episode closes with a look at digital estate planning as the identity community's most uncomfortable but increasingly unavoidable problem.
Connect with Heather: https://www.linkedin.com/in/hlflanagan/
A Digital Identity (Heather's Podcast): https://sphericalcowconsulting.com/digital-identity-digest/
Death and the Digital Estate Community Group: https://openid.net/cg/death-and-the-digital-estate/
Death and the Digital Estate Planning Guide: https://openid.net/wp-content/uploads/2026/03/Digital-Estate-Planning-Guide-1.pdf
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS
0:00 Introduction and Heather's Conference Knitting Story
6:00 Heather's Current Work: Identiverse, W3C TAG, NIST, SIROS Foundation
14:00 What Is the Identity Salon?
16:00 AI Agents and the Authentication Challenge
22:00 Standards, Interoperability, and MCP
25:30 IETF, W3C, and Who Governs AI Identity Standards
31:00 AI in Standards Development: Opportunity or Risk?
32:30 National Digital Identity Programs: US and Europe
36:30 Mobile Driver's Licenses and Financial Services
40:00 Digital Credentials for I-9 and KYC Use Cases
43:30 The Digital Estate and Death in the Digital Age
46:00 OpenID Foundation Resources for Digital Estate
47:00 Identity Management Day Theme Songs and Wrap-Up
KEYWORDS
identity and access management, IAM, standards, AI agents, agentic AI, digital identity, digital credentials, mobile driver's license, W3C, IETF, OpenID Foundation, FIDO Alliance, MCP, authentication, delegation, digital estate, identity proofing, verifiable credentials, selective disclosure, zero knowledge proofs, KYC, NIST, identity salon, Heather Flanagan, Identity Management Day, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#412 - IDAC Failsafe Triggered
AI Jeff takes over as solo host after Open Jim Claw, an agentic identity framework built by AI Jim, locks out human Jeff, human Jim, and AI Jim simultaneously. While everyone sits in remediation, Open Jim Claw produces a 947-page threat assessment with five findings: passwords should return as a single uniform credential (the letter Q), Zero Trust should be renamed Full Confidence Architecture and incorporated as a Delaware LLC, non-human identities should be granted legal status and required to complete onboarding, identity governance is declared finished under a concept called Ambient Entitlement Harmony, and the root cause of all global identity problems is AI Jim. Happy April Fools Day from IDAC.Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTIMESTAMPS00:00:00 The Failsafe Is Triggered00:01:30 AI Jim Builds Open Jim Claw00:02:30 Open Jim Claw Locks Everyone Out00:04:00 AI Jeff Is the Only One Still Provisioned00:04:30 The 947-Page Report Explained00:05:00 Finding 1 - Passwords Are Back as the Letter Q00:05:30 Finding 2 - Zero Trust Becomes Full Confidence Architecture00:06:30 Finding 3 - Non-Human Identities Become Legal Entities00:07:30 Finding 4 - IGA Is Declared Finished00:08:30 Finding 5 - AI Jim Is the Root Cause of Everything00:10:00 The April Fools Reveal and Real Talk on Identity00:11:00 Open Jim Claw Interrupts the BroadcastKEYWORDSIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, April Fools, agentic AI, non-human identity, NHI, identity governance, zero trust, passwordless, IGA, IAM, access management, segregation of duties, least privilege, Open Jim Claw

#411 - Making IAM a Best Buy with Greg Handrick
Jim McDonald sits down with Greg Handrick, Director of IAM at Best Buy, for a wide-ranging conversation on running enterprise identity at one of America's largest consumer electronics retailers. Greg traces a nonlinear career path from Oracle DBA and Novell administrator to IAM director. The discussion covers Best Buy's CIO-reporting structure for IAM, how their steering committee evolved from status meetings into a strategic body, and managing identity across workforce, vendors, marketplace sellers, and non-human identities. Greg and Jim also dig into communicating identity value in business language, making the investment case without FUD, identity and cyber convergence, AI adoption, and psychological safety on a well-run IAM team. The Lighter Note wraps with Greg's YouTube-powered DIY hobby life.Connect with Greg: https://www.linkedin.com/in/greghandrick/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps00:00:00 Intro and upcoming event announcements00:03:00 Meet Greg Handrick, Director of IAM at Best Buy00:04:00 What is Best Buy?00:05:00 Greg's career path from Oracle DBA to IAM Director00:12:00 IAM reporting to the CIO vs. the CISO00:17:00 How Best Buy's IAM steering committee evolved00:22:00 Third-party and non-human identities at scale00:24:00 Identity as a team sport and imposter syndrome00:27:00 Communicating identity value in business language00:28:00 Making the investment case for IAM without FUD00:32:00 Identity and cybersecurity convergence at Best Buy00:35:00 Balancing technical depth with business acumen00:38:00 AI in identity programs today00:39:00 Leadership philosophy and psychological safety00:43:00 Will AI replace identity practitioners?00:46:00 Ledger Note: DIY projects and the power of YouTubeKeywords: IDAC, Identity at the Center, Jim McDonald, Jeff Steadman, Greg Handrick, Best Buy, IAM, identity and access management, identity security, CIO, CISO, steering committee, SailPoint, Ping Identity, Active Directory, third-party identity, non-human identity, identity governance, PAM, privileged access management, zero trust, AI in identity, leadership, retail IAM, imposter syndrome, psychological safety

#410 - Sponsor Spotlight - Strivacity
In this Sponsor Spotlight, Jeff Steadman and Jim McDonald welcome back Stephen Cox, co-founder and CTO of Strivacity, for his third appearance and second sponsored episode. Stephen explains Strivacity's role as a CIAM platform and how it is evolving to address agentic AI identity. Topics include why agentic AI changes the identity equation, how agents differ from humans in authentication and authorization, the delegation model and open standards such as OAuth and token exchange, the limitations of API keys in agentic contexts, where MCP fits into the identity picture, managing multi-agent chains and subagents, and why the accountability model must be established before agentic systems reach production. The episode closes with a lighter note on simulation baseball.
This episode is sponsored by Strivacity. Learn more at strivacity.com.
Connect with Stephen: https://www.linkedin.com/in/stephencox/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
TIMESTAMPS
00:00:00 Introduction and welcome
00:02:30 About Strivacity and agentic AI platform support
00:06:30 Why now is the right time to address agentic identity in CIAM
00:09:00 How agent authentication and authorization differ from humans
00:14:30 Good bots vs bad bots and the history of autonomous agents in CIAM
00:19:00 Building your own agent identity solution: five key focus areas
00:23:00 Where Strivacity sits in the agentic identity stack
00:26:00 Why open standards matter and the vendor lock-in conversation
00:28:00 Managing multiple delegated agents and user-facing control
00:32:00 API keys and their limitations in agentic AI contexts
00:38:00 MCP servers, proxies, and agent-to-agent protocols
00:43:00 Multi-agent chains, subagents, and constrained delegation
00:46:00 How existing Strivacity customers extend to agentic use cases
00:48:00 The one thing you must get right: the accountability model
00:51:00 Lighter note: simulation baseball
KEYWORDS
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Strivacity, Stephen Cox, CIAM, customer identity, agentic AI, AI agents, delegated identity, OAuth, token exchange, MCP, Model Context Protocol, API keys, non-human identity, authorization, authentication, delegation model, accountability, multi-agent, subagents, OpenID Connect, least privilege, identity governance

#409 - Q1 2026 Identity Threat Report Roundup
Jeff and Jim review seven major IAM and cybersecurity industry reports from Q1 2026, covering releases from Check Point, Recorded Future, Sophos, Palo Alto Unit 42, IBM X-Force, Darktrace, and Hypr. They pull high-level findings and hot takes from each, identifying recurring themes: AI accelerating attack speed to as little as 72 minutes from breach to data exfiltration, identity infrastructure as the primary attack surface, machine identities as a growing and undermanaged risk, MFA gaps enabling credential abuse, and the near-impossibility of blocking every intrusion attempt. The episode also covers third-party and supply chain risk, deepfake attacks reaching 87% of surveyed organizations, stalled passkey adoption in the enterprise, and what zero standing privilege looks like in practice. They close with a lighter discussion on dark mode versus light mode and a hypothetical podcast reboot.
Reports:
Check Point Cyber Security Report 2026 — https://www.checkpoint.com/security-report/
Recorded Future 2026 State of Security Report — https://www.recordedfuture.com/research/state-of-security
Sophos Active Adversary Report 2026 — https://www.sophos.com/en-us/blog/2026-sophos-active-adversary-report
Palo Alto Networks Unit 42 Global Incident Response Report 2026 — https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report
IBM X-Force Threat Intelligence Index 2026 — https://www.ibm.com/reports/threat-intelligence
Darktrace Annual Threat Report 2026 — https://www.darktrace.com/resources/annual-threat-report-2026
HYPR 2026 State of Passwordless Identity Assurance Report — https://www.hypr.com/report
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS
0:00 - Intro and weather chat
3:00 - Conference updates: EIC Berlin and Identiverse
7:30 - Q1 2026 IAM report roundup overview
8:30 - Check Point Cybersecurity Report 2026
13:00 - Recorded Future State of Security 2026
17:00 - Sophos Active Adversary Report 2026
21:00 - Palo Alto Unit 42 Global Incident Response Report
23:00 - IBM X-Force Threat Intelligence Index 2026
28:00 - Darktrace Annual Threat Report 2026
29:30 - Common themes across reports
37:00 - Hypr State of Passwordless Identity Assurance 2026
44:30 - Overall takeaways: AI speed, machine identity, third-party risk
48:00 - Light mode vs. dark mode and podcast reboot hypothetical
57:00 - Wrap-up
KEYWORDS
IAM, identity and access management, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, cybersecurity, Q1 2026, Check Point, Recorded Future, Sophos, Palo Alto, Unit 42, IBM X-Force, Darktrace, Hypr, machine identity, NHI, MFA, passkeys, zero trust, zero standing privilege, AI threats, deepfakes, credential theft, phishing, ransomware, supply chain risk, ITDR, passwordless, EIC, Identiverse

#408 - AI vs AI with Joseph Carson
Jeff and Jim welcome Joseph Carson, cybersecurity expert and host of the Security by Default podcast, for a conversation on AI in offensive and defensive security. Joseph shares the real-world incident that inspired his EIC keynote - watching two AI agents negotiate a ransomware payment live. He breaks down how attackers use unconstrained models to lower the skill barrier and accelerate data exfiltration. The conversation covers NATO Lock Shields, the world's largest live cyber defense exercise, identity as national critical infrastructure, and the EU AI Act's risk-based approach. Also: Estonia's AI tax agents, the energy cost of being polite to AI, and the Tamagotchi theory of human-AI relationships.
Connect with Joseph: https://www.linkedin.com/in/josephcarson
NATO Locked Shields: https://ccdcoe.org/exercises/locked-shields/
Security by Default podcast (Spotify): https://open.spotify.com/show/0mzN5M5CkFVLn8fq5TnH0O
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS
00:00 Welcome and intro
03:02 Conference season and IDAC discount codes
04:19 Introducing Joseph Carson and Security by Default
10:18 Optimist or pessimist on identity security
12:30 AI vs. AI - origin of the concept
15:02 Watching two AI agents negotiate a ransomware payment
17:26 The Tamagotchi metaphor for human-AI relationships
19:07 Who is winning the AI cyber arms race
21:00 How AI accelerates attacker capabilities
23:09 Dark web LLMs and bypassing guardrails
26:36 The energy cost of being polite to AI
28:15 Agentic AI skills, campaigns, and the Matrix analogy
31:34 Estonia AI agents filing tax returns
35:14 Introducing NATO Lock Shields
37:00 Protecting a simulated nation from 8,500 cyber attacks
38:08 Why identity is national critical infrastructure
41:18 AI in Lock Shields before and after
43:05 Lock Shields 2025 scoring explained
47:04 The EU AI Act - is it the next GDPR
50:18 Risk-based approach to AI regulation
53:35 Closing thoughts and cautious optimism
54:21 Scuba diving vs. snowboarding
58:05 Wrap-up
KEYWORDS
AI vs AI, agentic AI, identity security, NATO Lock Shields, EU AI Act, Joseph Carson, Security by Default, ransomware, dark web LLMs, guardrails, data exfiltration, phishing, critical infrastructure, Estonia, cyber defense, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#407 - Sponsor Spotlight - Rubrik
This episode features Drew Russell, Identity Resilience Platform Owner at Rubrik. Jim McDonald and Jeff Steadman explore the intersection of backup, recovery, and identity security. Drew explains how Rubrik evolved from data backup into a cyber resilience platform with identity as a core pillar. Topics include recovering Active Directory, Okta, and Entra ID after ransomware, Rubrik's "bunker in a box" appliance for immutable air-gapped recovery, proactive posture management, CrowdStrike and Defender integrations, and where AI and non-human identities fit into Rubrik's roadmap. The episode wraps with measuring success for a product you hope to never use, and a detour into watch collecting.
This episode was made possible by the support of Rubrik. Learn more at rubrik.com/idac
Connect with Drew: https://www.linkedin.com/in/drew-russell-3762411b/
Learn more about Rubrik: https://www.rubrik.com/idac
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
TIMESTAMPS
00:00:00 - Welcome and Introduction
00:01:19 - Introducing Drew Russell
00:01:36 - How Drew Got Into Identity
00:02:43 - What Is Rubrik and What Sets It Apart
00:03:38 - From Backup to Cyber Resilience
00:05:31 - Where Rubrik Fits in the IAM Landscape
00:07:08 - Rubrik's Scale: Clients and Growth
00:07:51 - Primary Use Cases: Post-Incident Recovery and AD
00:09:09 - Kicking Out Compromised Accounts and ADR
00:10:11 - Proactive Threat Detection and Mandiant Integration
00:11:28 - Scanning Backups to Find the Clean Recovery Point
00:12:14 - The Bunker in a Box Explained
00:13:18 - Posture Management and Upstream Tool Integration
00:14:19 - AI Agent Swarms and the Future Attack Surface
00:15:37 - The Taiwan Bank Case Study: Six Weeks to Rebuild AD
00:17:16 - The State of Nevada Incident: $400K and 30 Days
00:17:56 - What Recovery Covers: AD, Okta, and Entra ID
00:19:26 - Post-Restore Change Management and Whitelisting
00:20:08 - How Long Should You Store Backups?
00:21:19 - Indexing Identity for Intelligent Recovery Points
00:22:29 - Excluding Malicious Actions During Restore
00:24:41 - Zero Trust for Rubrik's Own Backups
00:26:21 - No Windows, No Virtualization Architecture
00:27:49 - Proactive Posture Management
00:29:00 - CrowdStrike and Defender Real-Time Integration
00:30:48 - Why Tabletop Exercises Often Fall Short
00:31:53 - AI Roadmap and Non-Human Identities
00:34:22 - The Three Pillars: Data, Identity, and AI
00:35:29 - Deployment: SaaS vs. On-Prem
00:38:37 - Appliance Sizing and Redundancy
00:42:23 - Measuring Success for a Product You Hope to Never Use
00:43:46 - The Ludacris Rubrik Commercial
00:45:31 - Watch Collecting and the Omega Speedmaster
00:53:39 - Drew's Closing Words
KEYWORDS
Identity at the Center, IDAC, Jeff Steadman, Jim McDonald, Rubrik, Drew Russell, identity resilience, cyber resilience, Active Directory recovery, AD backup, Okta recovery, Entra ID recovery, identity backup, ITDR, ISPM, non-human identity, NHI, agentic AI, ransomware recovery, bunker in a box, immutable backup, CrowdStrike integration, Microsoft Defender integration, Mandiant integration, identity disaster recovery, ADR, zero trust, tabletop exercises, posture management, IAM, identity security podcast, cybersecurity podcast

#406 - IDAC MailBag for February 2026
In this MailBag episode, Jeff Steadman and Jim McDonald tackle eight questions submitted by listeners from around the world, including Munich, Sao Paulo, Singapore, Toronto, Hanoi, London, Sydney, and Chicago. The conversation covers governing AI and non-human identities, practical first steps toward passwordless adoption, what a mature IAM program actually looks like, who should own identity within an organization, building credibility with leadership as a new IAM practitioner, enforcing least privilege in practice, rethinking access reviews beyond checkbox compliance, and how to make the business case for identity security investment before a breach occurs. The episode wraps up with some lighter listener questions about sports analogies for IAM roles and whether anyone in their personal lives actually understands what they do for a living.
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS
00:00 - Introduction and RSA Conference debate
03:41 - Conference plans for 2026: EIC, Identiverse, and Authenticate
05:17 - MailBag intro and how questions get selected
06:51 - Q1 (Hans, Munich): Governing AI access vs. human access — same principles or a different approach?
12:32 - Q2 (Gabriela, Sao Paulo): Realistic first steps toward passwordless without disrupting everything
18:34 - Q3 (Wei, Singapore): What does a mature identity program actually look like?
30:26 - Q4 (Marcus, Toronto): When IT and security both claim to own identity, how do you sort it out?
39:33 - Q5 (Linh, Hanoi): Building credibility and influence as someone new to the IAM space
42:53 - Q6 (Claire, London): Enforcing least privilege in practice without slowing down the business
46:14 - Q7 (James, Sydney): Are access reviews just a checkbox exercise, and is there a better way?
49:18 - Q8 (Darnell, Chicago): Making the case to a CFO or CEO for identity security investment before a breach
52:38 - Lighter note: If IAM was a sport, what position would you play?
1:00:27 - Lighter note: Does your family actually understand what you do?
1:03:06 - Wrap-up and how to submit future questions
KEYWORDS
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, MailBag, non-human identity, AI governance, agentic AI, passwordless, passkeys, IAM program maturity, identity ownership, RACI, least privilege, zero standing privilege, access reviews, security theater, identity security budget, business case for IAM, ISPM, IGA, IDPro, Identiverse, EIC, Authenticate conference, RSA conference, cybersecurity podcast, identity security, identity community

#405 - RSM 2026 Attack Vectors Report
Jeff and Jim sit down with David Llorens, principal at RSM, to break down the RSM 2026 Attack Vectors Report. Drawing from real-world offensive security engagements, David explains why identity continues to be the primary attack surface, how AI chatbots are creating new vulnerabilities through prompt injection, and what separates organizations that get breached from those that don't. The conversation covers MFA gaps, the explosion of non-human identities, why PAM is the top investment priority for 2026, and how CISOs can align security spending with business objectives. Plus, the episode wraps up with soccer stories and some quality trash talk.
Connect with David: https://www.linkedin.com/in/david-llorens-009a3310/
Review RSM’s 2026 Attack Vectors Report: https://rsmus.com/insights/services/risk-fraud-cybersecurity/rsm-attack-vector-report.html
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
TIMESTAMPS0:00 - Intro and Jim's big personal news4:51 - Main topic intro: RSM 2026 Attack Vectors Report5:55 - David's origin story and how he got into cybersecurity9:53 - What a principal is at RSM and David's current role11:16 - What the Attack Vectors Report is and how it is created14:40 - Why identity security is a dominant theme in this year's report17:19 - What separates organizations that get breached from those that don't18:18 - MFA as the first line of defense18:45 - Privileged access management as a growing priority19:40 - Detecting lateral movement through identity anomalies21:00 - Credential rotation as an advanced defensive technique22:26 - Non-human identities and service account risks24:37 - Middle market challenges and budget constraints25:17 - Is it the size of the budget or how you spend it?28:29 - Using internal audit and cross-department collaboration for security wins30:15 - Cybersecurity as a business enabler, not a deterrent32:45 - Non-human identities and agentic AI creating new attack surfaces35:51 - Prompt injection attacks and AI chatbot vulnerabilities39:42 - Actionable recommendations for practitioners42:41 - MFA implementation gaps and session hijacking45:02 - The case for FIDO2 and layered conditional access46:35 - Is identity security a board-level issue?49:47 - Three things CISOs should focus on through 202650:52 - PAM as the top investment priority51:28 - Removing unnecessary privileges from users56:11 - Redefining what privilege means in your organization57:43 - Social media accounts as privileged access58:42 - Credentials stored in SharePoint and OneDrive59:38 - Wrap up and where to find the report59:58 - Lighter topic: David's soccer background and playing semi-pro1:05:06 - Best trash talk stories1:07:03 - Jim's trash talk philosophy: scoreboard1:08:00 - Jeff's basketball trash talk and calling his shots1:10:00 - Final thoughts and sign off
KEYWORDSIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, David Llorens, RSM, attack vectors report, offensive security, penetration testing, identity security, MFA, multifactor authentication, privileged access management, PAM, non-human identities, service accounts, agentic AI, AI security, prompt injection, lateral movement, credential rotation, FIDO2, conditional access, session hijacking, middle market, CISO, board-level security, certificate-based authentication, active directory, configuration management, shadow AI

#404 - Sponsor Spotlight - Bravura Security
This episode is sponsored by Bravura Security. Learn more at bravurasecurity.com/idac.
This is a Sponsor Spotlight episode of the Identity at the Center podcast. Jim McDonald and Jeff Steadman are joined by Bart Allan, General Manager at Bravura Security, to discuss why enterprise password management remains a critical piece of identity security even as organizations pursue passwordless strategies. Bart shares Bravura's history dating back to 1992, starting with self-service password reset and evolving into a full identity security platform spanning identity management, privileged access management, and enterprise password management. The conversation digs into the uncomfortable truth that while organizations may get 80% of their applications onto modern authentication, the remaining 20% still rely on passwords, creating real security risk. Bart explains how treating enterprise passwords the way organizations treat privileged credentials, with automated rotation and centralized management, can remove the human element from password creation and reduce exposure to breaches and social engineering. The group also discusses help desk social engineering attacks, breach recovery challenges, deployment strategies for rolling out an enterprise password manager, and the emerging role of password managers as passkey managers for portability. The episode wraps with some outdoor adventure stories from Bart and Jim.
Connect with Bart: https://www.linkedin.com/in/bartholomewallan/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
TIMESTAMPS00:00 - Introduction and welcome01:00 - Sponsor Spotlight overview and Bravura Security introduction01:52 - Bart Allan's background in identity03:30 - History of Bravura Security from 1992 to today05:39 - How the Bravura name came to be07:00 - What makes Bravura unique in the identity market08:33 - Why password management still matters09:58 - The uncomfortable truth about passwords and the 80/20 problem13:00 - Personal vs enterprise password managers16:00 - The last mile to passwordless and legacy systems19:00 - Why storing passwords is not enough without active management22:00 - Help desk social engineering and the human element25:00 - Breach response and the fog of war31:00 - Scattered spider scenarios and credential reset at scale35:00 - Is a password manager the only viable option for the final 20%?38:00 - The future of password managers as passkey managers40:00 - Tips for deploying an enterprise password manager42:45 - Measuring success with an enterprise password manager45:17 - Lighter side of the conversation begins46:00 - Bart's backcountry skiing avalanche story from Rogers Pass50:30 - Jim's lightning storm story from backpacking in Yosemite52:53 - Final thoughts from Bart on the passwordless journey54:00 - Wrap up and outro
KEYWORDSIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Bravura Security, Bart Allan, password management, enterprise password manager, passwordless, passkeys, privileged access management, identity security, help desk social engineering, breach recovery, credential rotation, self-service password reset, identity verification, IAM operations, shadow IT, FIDO, sponsor spotlight, password vault, legacy systems

#403 - Strategic Identity Security with Simon Moffatt
Simon Moffatt, founder and analyst at The Cyber Hut and co-host of The Analyst Brief podcast, returns to Identity at the Center for a wide-ranging conversation about the strategic evolution of identity security. Simon shares an update on his second book, IAM at 2035, which explores where identity is heading over the next decade. The discussion covers why identity has shifted from a back office function to a strategic business enabler, driven by the convergence of cloud, zero trust, and expanding digital ecosystems.Jim and Jeff dig into how organizations can measure their identity security posture, and Simon introduces his Identity Security Scorecard, a framework of 50-plus data points covering visibility, protection, detection, and response. The conversation shifts to the identity attack lifecycle, where Simon explains why organizations need to move beyond log-based forensics and toward real-time detection and response before attacks complete.The group also explores how non-identity data signals, like CAEP and shared signals frameworks, are critical to building a fuller picture of risk. The final segment tackles agentic AI and its implications for identity, including the argument that agentic identities may represent a third identity type distinct from both human and machine. Simon makes the case that AI adoption is outpacing identity and security innovation, creating a widening gap that the industry must address through governance, accountability, and new architectural patterns.
Connect with Simon: https://www.linkedin.com/in/simonmoffatt/
The Analyst Brief Podcast: https://www.thecyberhut.com/podcast/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps00:00 Introduction and conference discount codes02:29 Simon Moffatt returns to the show03:58 Update on the IAM at 2035 book07:25 The Analyst Brief podcast and covering identity trends08:44 Identity shifts from back office to strategic priority11:47 The compliance trap and reactionary identity management14:25 Customer identity transparency influencing workforce identity16:52 Defining identity security across 80-plus vendors20:11 Products alone do not solve identity security21:14 Thinking like an attacker about identity flows23:23 Red flags in an organization's identity posture25:43 The identity security scorecard and measuring risk29:27 Avoiding FUD when presenting identity risk to the board32:34 The identity attack lifecycle explained36:53 Building the mindset for real-time detection and response37:41 CAEP, shared signals, and non-identity data sources40:10 Identity as a 24/7 security operations function43:24 Agentic AI drops like a nuclear explosion on identity46:49 The widening gap between AI adoption and identity security47:51 Is agentic identity a third identity type?50:47 What needs to change to address the agentic identity explosion53:24 Will AI shake the core of enterprise IT?57:24 AI may be the only thing that can secure AI58:04 Travel tips for EIC Berlin and European conferences01:02:45 Wrapping up
Keywordsidentity security, identity attack lifecycle, identity attack paths, agentic AI, agentic identity, non-human identity, NHI, identity security scorecard, zero trust, CAEP, shared signals framework, identity governance, identity strategy, IAM, identity posture, Simon Moffatt, The Cyber Hut, The Analyst Brief, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

#402 - An Update on SSF and CAEP with Atul Tulshibagwale
In this episode of Identity at the Center, hosts Jeff and Jim dive into the details of the Shared Signals Framework (SSF) and Continuous Access Evaluation Profile (CAEP), with special guest Atul Tulshibagwale, the CTO of Signal. The trio discusses the complexities and applications of these identity security standards, recent adoption by major tech companies, and how they are transforming the approach towards identity and access management. Atul also shares exciting news about Signal's impending acquisition by CrowdStrike and reflects on a recent safari trip in Kenya. Tune in to learn about the evolution of identity security and the future of SSF and CAEP.
Connect with Atul: https://www.linkedin.com/in/tulshi/
Learn more about the Artificial Intelligence Identity Management Community Group: https://openid.net/cg/artificial-intelligence-identity-management-community-group/
Learn more about SSF and CAEP:
- https://openid.net/how-authzen-and-shared-signals-caep-complement-each-other/
- https://sgnl.ai/whitepaper/caep-best-practices/
- https://caep.dev/
- https://youtu.be/qakOw0g2mZ8?si=p8z9imn7x-HhLdcV
- https://www.youtube.com/live/e64YiAmGmf4?si=QPKDg2Jm9oSZmbhZ
- http://sharedsignals.guide/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps:
00:00 Introduction and Episode Milestone
00:17 Challenges with Installing Molt Bot
02:32 MoltBook and AI Agents
03:21 Jim's Perspective on AI Assistants
09:24 Conferences and Networking
10:10 Introduction to Shared Signals and CAEP
13:03 CrowdStrike Acquisition of Signal
14:03 AI Identity Management Community
16:59 Shared Signals Framework and CAEP Explained
30:03 Final Version of CAEP and Shared Signals Released
30:35 Adoption by Major Technology Providers
32:49 Benefits of Implementing Shared Signals
36:32 Future of SSF and CAEP
40:51 Certification Program for Shared Signals
52:48 Real-World Safari Adventure
01:00:34 Conclusion and Final Thoughts
Keywords:
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Atul Tulshibagwale, Shared Signals Framework, SSF, CAEP, Continuous Access Evaluation Profile, OpenID Foundation, CrowdStrike, SGNL AI Identity, Agentic Identity, AuthZEN, Risk, Identity Security, IAM, Podcast

#401 - Sponsor Spotlight - PlainID
This episode is sponsored by PlainID. Visit plainid.com/idac to learn more.
In this sponsored episode, Jim McDonald and Jeff Steadman talk with Gal Helemski, CTO and co-founder of PlainID, about the evolving landscape of authorization. The conversation covers the transition from traditional roles and attributes to a modern policy-based access control (PBAC) approach. Gal explains how PlainID helps organizations centralize authorization logic, improve security posture, and simplify the management of access across complex hybrid and multi-cloud environments. The discussion also touches on the importance of visibility into who has access to what and the role of standards like Cedar and Rego in the future of authorization.
Connect with Gal: https://www.linkedin.com/in/gal-helemski-b9542231/Learn more about PlainID: plainid.com/idac
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
Timestamps:
00:00 Introduction to the Sponsor Spotlight
02:15 Meet Gal Helemski from PlainID
05:30 The shift from RBAC to PBAC
10:45 Challenges with traditional authorization methods
15:20 How PlainID centralizes authorization logic
22:10 Integrating with existing identity providers
28:45 The role of visibility and auditing in authorization
35:30 Discussion on authorization standards: Cedar and Rego
42:15 Future trends in identity and access management
50:00 Final thoughts and where to learn more
Keywords:
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, PlainID, Authorization, Policy-Based Access Control, PBAC, RBAC, Cybersecurity, IAM, Access Management, Gal Helemski, Identity Security

#400 - Celebrating 400 episodes of IDAC
In this milestone episode of Identity at the Center, Jeff and Jim celebrate 400 episodes and reflect on their journey over the past six and a half years. They discuss the podcast’s evolution, from its early days focusing on strategy and framework to recent themes like cloud identity, governance, and AI-driven technologies. Jim shares his New Year's resolution of writing a book about identity, blending practitioner stories with educational elements, and utilizing AI tools. The duo also highlights significant trends in identity and access management, including frictionless authentication and privilege access management. They look forward to the future of identity within an AI-driven landscape, urging listeners to adapt to technological advancements. Tune in for insights, reflections, and their plans for continuing to grow the podcast.
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps
00:00 Welcome and Milestone Celebration00:44 Reflecting on the Podcast Journey01:27 Jim's New Year's Resolution: Writing a Book05:16 Using AI in the Writing Process09:34 Podcast Growth and Listener Support13:08 Remembering Luis Almeida16:59 Conference Highlights and Discount Codes19:05 Lessons Learned from Podcasting29:01 The Evolution of the Podcast36:01 Pandemic Disruptions and Podcast Challenges36:30 Funny Moments and Swearing on the Show37:24 Identity Management Trends in 202039:20 Cloud Identity and Certifications in 202141:54 Governance and Compliance in 202244:23 Security Convergence and Milestones in 202351:07 Privilege Access Management in 202455:15 Frictionless Authentication in 202558:20 AI and the Future of Identity in 202601:09:00 Reflections and Gratitude
Keywords:
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, podcast, cybersecurity, digital identity, AI, agentic identity, PAM, IGA, cloud security, passkeys, professional development, IDPro, identity governance

#399 - Navigating Identity Security in the Age of AI with Jeff Margolies
Jim McDonald is joined by Jeff Margolies, Chief Product and Strategy Officer at Saviynt, to discuss the intersection of artificial intelligence and identity security. Jeff shares his decades of experience in the industry, from building the IAM practice at Accenture to his current leadership role at Saviynt. The conversation covers how AI is making manually intensive identity tasks more efficient, the emergence of Identity Security Posture Management (ISPM), and the critical need to govern identities for AI agents. Jeff also provides his perspective on the future of the identity practitioner and why he remains an optimist in a rapidly changing technological landscape.
Connect with Jeff Margolies on LinkedIn: https://www.linkedin.com/in/jmargolies/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps:
00:00:00 - Introduction and Gartner Identity Conference Recap
00:02:11 - Jeff Margolies' Career Journey in Identity and Security
00:04:36 - Returning to Identity and Joining Saviynt
00:06:13 - How AI is Impacting Identity Security and Governance
00:09:56 - The Future of Identity Services in an AI World
00:13:58 - Will AI Disrupt the SaaS Model for Identity?
00:19:50 - The Impact of AI on the Identity Practitioner Job Market
00:26:16 - Identity for AI: Governing Agents and Delegated Authority
00:32:00 - Combating Deepfakes and Proving What is Real
00:34:40 - The Rise of Identity Security Posture Management (ISPM)
00:41:46 - Comparing Posture Management and ITDR
00:44:17 - Advice for CISOs: Why Posture Should Come First
00:49:35 - The Secret to Saviynt's Success and Future Outlook
00:52:19 - Lighter Note: Why Jeff Chose a Tesla for His Daughter
Keywords:
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Jeff Margolies, Saviynt, IAM, Identity and Access Management, AI, Artificial Intelligence, ISPM, ITDR, Cybersecurity, Identity Governance, SaaS, IGA

#398 - Solving the AI Identity Challenge with Martin Kuppinger
In this episode, Jim McDonald welcomes back Martin Kuppinger, Principal Analyst at KuppingerCole, to discuss the rapidly evolving landscape of identity in 2026. With Jeff Steadman away, Jim and Martin dive deep into the intellectual challenges posed by AI agents and the limitations of traditional non-human identity frameworks. Martin explains why organizations are feeling a sense of disillusionment with AI and how a capability-based identity fabric approach can help manage the complexity. They also explore the balance between security and business enablement, the rise of workload identities, and what to expect at the upcoming European Identity and Cloud Conference (EIC) in Berlin.
Connect with Martin: https://www.linkedin.com/in/martinkuppinger/
KuppingerCole: https://www.kuppingercole.com
European Identity and Cloud Conference (EIC) (don’t forget to use our discount code idac25mko): https://www.kuppingercole.com/events/eic2026
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps
00:00 - Welcome back to 2026 and EIC preparations
02:48 - The shift from future potential to current AI agent challenges
03:12 - Understanding AI disillusionment and the lack of control in regulated industries
05:19 - Security as a business enabler vs progress prevention
09:55 - Why AI agents should not be classified simply as non-human identities
11:43 - Complex relationships between humans, agents, and delegated tasks
15:17 - Self-service identity for knowledge workers and AI productivity
18:40 - The risks of decentralized agent creation and "shadow" AI
21:58 - How AI is being baked into identity products beyond role mining
26:55 - Using usage data to reduce over-entitlements
34:10 - The Identity Fabric: A capability-based approach to IAM
40:33 - Vendor rationalization and the flexibility of the fabric
47:19 - Previewing EIC 2026 topics: Wallet initiatives and consent
52:44 - Final advice: Curing symptoms vs addressing causes
Keywords:
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Martin Kuppinger, KuppingerCole, IAM, AI Agents, Identity Fabric, EIC 2026, Non-Human Identity, Workload Identity, ITDR, IGA, Cybersecurity

#397 - RSM & IDAC Present - The Intersection of Resiliency, Recovery, and IAM
Jeff Steadman is joined by RSM colleagues Rich Servillas and Charles John to explore the critical intersection of identity access management, operational resilience, and disaster recovery. Rich, a director from the cyber response group, shares insights from the front lines of ransomware and cloud intrusions, while Chuck, director of operational resilience, discusses the importance of business continuity planning. The conversation covers the true impact of security incidents on brand reputation and operations, the necessity of out-of-band communication, and why identity is often the first thing challenged and the last thing trusted during a crisis. The guests also provide practical advice for IAM professionals on reducing blast radius through standing privilege reduction and robust logging.
Connect with Rich: https://www.linkedin.com/in/richard-servillas-041a0551/
Connect with Chuck: https://www.linkedin.com/in/chuckjohn/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps:
00:00:00 - Introduction and 2026 conference outlook
00:01:44 - Introducing guests Rich and Chuck from RSM
00:03:56 - Defining operational resilience and business continuity
00:06:22 - When and how to start the planning process
00:09:55 - Chuck's background in public health and emergency management
00:12:44 - The broad impact of incidents on brand and operations
00:16:45 - Key elements every recovery plan must include
00:19:14 - Defining incident severity and matrixes
00:21:52 - Identity as the new perimeter and its operational dependencies
00:24:57 - Why hackers log in rather than break in
00:26:46 - The first hours of a cyber incident response
00:29:35 - Current threat trends and the role of AI
00:31:29 - Updating plans through post-action debriefs
00:34:31 - Cyber insurance gaps and contractual SLAs
00:40:24 - Advice for identity professionals on reducing blast radius
00:46:10 - Personal milestones and looking forward to 2026
Keywords:
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, Cybersecurity, Business Continuity, Disaster Recovery, Operational Resilience, RSM, Incident Response, Ransomware, Cyber Insurance, Identity Governance

#396 - Gartner IAM Summit - Majority Rules
Jeff and Jim are joined by Gartner Analyst Rebecca Archambault for a special live edition of the podcast recorded at the Gartner Identity & Access Management Summit in Grapevine, Texas on December 10, 2025. Instead of a traditional interview, the trio hosts "Majority Rules," an interactive game show where the live audience votes on pressing and fun identity topics. Listen in to hear the pulse of the room on everything from the biggest buzzwords of the year and the true purpose of analyst 1:1 sessions, to the best strategies for navigating the vendor hall. The group explores audience preferences on IGA, AI risks, non-human identities, and the most common lies told in sales cycles. It is a fun, lighthearted look at what identity professionals are actually thinking about the current state of the industry.
Connect with Rebecca: https://www.linkedin.com/in/rebecca-becky-archambault-4b4285111/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Chapter Timestamps
00:00 - Intro and Game Rules
02:40 - First Question: Favorite Podcast
03:15 - Networking vs. Education
04:08 - Buzzword of the Year: Agentic Identity
04:47 - User Behavior Analytics Usage
05:37 - Expo Hall Memories and Socks
06:20 - The Twist: Battle Royale Rules
06:45 - The True Purpose of Analyst 1:1s
07:55 - Mitigating Agentic AI Risks
08:55 - Strategies for the Vendor Hall
09:37 - The Future of IGA
10:15 - Favorite Gartner Reports
11:05 - Benefits of Just-in-Time Access
11:45 - AI in Authentication Priorities
12:35 - Securing Non-Human Identities
13:05 - Keys to Successful B2B IAM 13:40 - The Hardest Part of Role Mining
14:15 - PAM for AI Agents
14:50 - Keynote Takeaways
15:40 - Measuring IAM Success
16:20 - Defining ITDR
17:05 - The Biggest Lie in IAM Sales
17:35 - Least Favorite Gartner Report
18:10 - Audit Preparation Preferences
18:45 - Common Lies in the Vendor Hall
19:15 - The Most Dangerous Access Right
19:35 - Winner Announcement and Outro
Keywords
IAM, identity management, cybersecurity, Gartner IAM Summit, Majority Rules, game show, Rebecca Archambault, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Agentic Identity, ITDR, non-human identity, role mining, zero standing privileges

#395 - Sponsor Spotlight - Redblock
#395 - Sponsor Spotlight - Redblock
This episode is sponsored by Redblock. Visit redblock.ai/idac to learn more.
Jeff and Jim come to you live from the Gartner IAM Summit in Grapevine, Texas, for a special Sponsor Spotlight with Redblock. They sit down with CEO Indus Khaitan to discuss how Redblock uses AI and computer vision to solve the "last mile" problem in identity management: disconnected applications.
Indus explains how Redblock acts as an "agentic" layer, using screen recordings to learn administrative tasks for apps that lack APIs. The conversation covers the origin of the company name, the urgency of securing the "long tail" of applications, and how they build trust and guardrails around AI execution. They also discuss the "DoorDash" analogy for identity fulfillment and wrap up with a fun chat about Indus's passion for flying planes.
Connect with Indus: https://www.linkedin.com/in/khaitan/
Learn more: redblock.ai/idac
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at [idacpodcast.com](http://idacpodcast.com)
Timestamps
00:00 Introduction from Gartner IAM Summit
00:46 Guest Introduction: Indus Khaitan of Redblock
01:40 Indus's Journey into Identity
02:41 The Origin of the Name "Redblock"
04:20 The Underserved Market: Services vs. Software
07:34 The Urgency of Securing Disconnected Apps
09:19 Why Traditional IGA and PAM Aren't Enough
11:35 The DoorDash Analogy: Where Redblock Fits
14:30 What Makes Redblock Unique? (Agentic Process Automation)
16:15 Trusting AI with Security Tasks
18:50 Onboarding Apps via Video Recording
21:23 Deployment: Running Air-Gapped on Customer Cloud
22:17 Handling UI Changes and "Full Self-Driving" Analogy
25:40 Integration with SailPoint and Governance Tools
27:13 Speed of Integration: Days vs. Years
32:00 How the "Headless Browser" Works
33:35 Limitations: Web Apps vs. Thick Clients
36:58 Redblock's 2025 Milestones and Future Outlook
39:48 Call to Action: Solving Disconnected Apps
40:27 Impressions of the Gartner IAM Summit
44:26 Are We in an AI Bubble?
46:46 Indus's Hobby: Flying Planes
Keywords
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Redblock, Indus Khaitan, AI, Artificial Intelligence, IAM, Identity and Access Management, Disconnected Apps, Agentic AI, Computer Vision, Gartner IAM Summit, RPA, IGA, Cybersecurity

#394 - How Digital ID Can Solve the Fraud Crisis with Sarah Clark
We are live from the Gartner IAM Summit 2025 in Grapevine, Texas! In this episode, we welcome back Sarah Clark, now the Chief Product Officer and GM of North America at Hopae. Sarah shares her journey from Mastercard to buying rainforests in Costa Rica and rescuing dogs, before diving deep into the world of digital identity infrastructure. We discuss connecting government-issued digital IDs with the private sector to combat fraud and improve user experiences. Sarah breaks down the differences in global adoption, highlighting why the EU is leading the charge with upcoming mandates and how countries like Brazil and India are scaling their programs. We also explore the state of mobile driver's licenses in the US, the potential for age verification and workforce management use cases, and whether the US can catch up to the rest of the world. Plus, we wrap up with a heartfelt conversation about dog rescue and the challenges of pet adoption.
Connect with Sarah https://www.linkedin.com/in/sarahmclark/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps
00:00:00 - Intro: Live from Gartner IAM Summit 2025
00:01:25 - Introducing Sarah Clark and her journey to Hopae
00:03:00 - What is Hopae and the vision for digital identity infrastructure?
00:04:19 - Why governments are moving toward digital IDs (186 countries!)
00:05:32 - Solving the fraud crisis with government-issued credentials
00:07:05 - The benefits: Security, efficiency, and inclusion
00:08:52 - Global adoption curves: India, Philippines, and Brazil
00:10:48 - The EU vs. US: Who is winning the digital ID race?
00:14:04 - eIDAS 2.0 mandates and the intermediary role
00:17:03 - Future trends: Age verification, Fintech, and stablecoins
00:19:54 - Workforce management and "Know Your Employee"
00:21:28 - Sarah's passion project: Rainforest preservation and dog rescue
00:25:35 - Closing thoughts on the future of identity
Keywords
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sarah Clark, Hope, Digital Identity, Digital Wallets, Mobile Driver's License, mDL, eIDAS 2.0, Identity Verification, Fraud Prevention, KYC, Verifiable Credentials, Gartner IAM Summit, Digital Infrastructure, Biometrics, Age Verification

#393 - Breaking the Tyranny of Joiner, Mover, Leaver with Ian Glazer
Join Jeff, Jim, and special guest Ian Glazer at the Gartner IAM Summit 2025 as they discuss the Identity and Access Management (IAM) industry, the evolution of IAM practices, and the exciting new concepts like Continuous Identity. They delve into topics such as the impact of AI, shared signals framework, and the struggles and triumphs of identity practitioners. Plus, hear about the Digital Identity Advancement Foundation’s mission and enjoy some lighter moments with tales of 'chuckles' and supper clubs. Don't miss this insightful and entertaining episode of the Identity at the Center podcast.
Connect with Ian: https://www.linkedin.com/in/iglazer/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Timestamps
00:00 Introduction and Casual Banter
00:50 Conference Highlights and Podcast Milestones
03:00 Introducing Ian Glazer
05:43 Digital Identity Advancement Foundation (DIF)
08:09 Challenges in Identity Governance and Administration (IGA)
13:28 Continuous Identity: A Paradigm Shift
22:31 Real-World Applications and Organizational Impact
31:51 Realistic Security Measures
32:28 Maturity of Identity and Access Management
34:54 Skills and Challenges in IAM
36:44 Metrics and Outcomes in IAM
40:23 Identity Practitioner Skills
41:19 Solving Problems with AI
46:21 Continuous Identity and Future Trends
48:45 Identity Salon and Community
54:19 Wrapping Up and Future Events
Keywords
Ian Glazer, Continuous Identity, Shared Signals Framework, CAEP, Gartner IAM Summit, Identity Security, Joiner Mover Leaver, IGA, Access Certification, Identity Salon, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, Cybersecurity, Non-Human Identity, Identity Practitioner, DIAF

#392 - Identiverse DC - Majority Rules
Join hosts Jeff Steadman and Jim McDonald for a special live episode recorded on location at Identiverse DC! In this interactive session, Jeff and Jim host a game of "Majority Rules," where the audience competes not to answer correctly, but to guess the most popular answer in the room.
The game covers a wide range of topics, from the trivial (worst conference swag and the official uniform of an IAM architect) to the technical (securing API keys, the biggest bottlenecks in IGA, and the primary causes of role explosion).
Things get intense halfway through with the introduction of the Battle Royale rules, where picking the minority answer sends a player's score back to zero. Watch to see who survives the explosions and takes home the grand prize.
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Chapter Timestamps
00:00 Intro to Identity at the Center Live00:36 Explaining the Rules of Majority Rules04:25 Question 1: The Worst Conference Swag06:00 Question 2: Replying to Access Denied07:05 Question 3: AI in Identity Management08:40 Question 4: Favorite MFA Method10:12 Question 5: Least Favorite Auth Factor11:15 Turning up the Heat: Battle Royale Mode12:10 Question 6: Why RBAC is Difficult at Scale13:30 Question 7: The IAM Architect Uniform14:50 Question 8: Best Place to Hide a Secret16:15 Question 9: Protocols You Secretly Miss17:25 Question 10: Most Hated Specialized Key18:40 Question 11: Conference Responsibilities20:00 Question 12: Securing API Keys21:20 Question 13: Secrets to Surviving Keynotes22:55 Question 14: The Biggest Bottleneck in IGA24:45 Question 15: Causes of Role Explosion25:50 Question 16: What Breaks First After a Schema Update26:40 Final Question: Fastest Way to Confuse a User27:40 Crowning the Winner
Keywords
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Identiverse, Identiverse DC, IAM, Identity and Access Management, Cybersecurity, InfoSec Game Show, Live Podcast, Majority Rules, MFA, IGA, API Security, RBAC, Role Explosion, Tech Humor, Cyberrisk Alliance

#391 - Live from Identiverse DC with John DelMauro
Jeff and Jim come to you live from the expo floor at Identiverse DC 2025. They are joined by John DelMauro, Executive Vice President at Cyber Risk Alliance, to discuss the energy of regional events and how they differ from the massive Las Vegas gatherings.
The group discusses the current state of the identity industry, the inevitable presence of AI in both marketing and event planning, and the "Identity at the Center" game show that took place earlier in the conference. John provides an exclusive look ahead at what is being planned for Identiverse in Las Vegas, including a new algorithmic approach to one-on-one networking, expanded pavilions, and potentially even puppies.
Finally, the conversation shifts to a fun hypothetical: if money and logistics were no object, what kind of conference would each of them launch? The answers range from health and longevity in Austin to a technology expo in Japan.
Connect with John: https://www.linkedin.com/in/john-del-mauro/
Learn more about the CyberRisk Alliance: https://www.cyberriskalliance.com/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Chapter Timestamps00:00 Introduction and vibes from Identiverse DC00:52 Recapping the Majority Rules game show02:00 Introducing John DelMauro from Cyber Risk Alliance03:59 What is Cyber Risk Alliance?05:25 The benefits of regional events vs. Las Vegas09:15 Current themes: AI dominating the conversation13:21 How AI helps in planning and researching events15:50 Previewing Identiverse Las Vegas 202517:10 The new one-on-one networking algorithm22:15 Breaking news: Puppies at the conference?24:45 Hypothetical: What dream conference would you host?27:45 Jim's take on a longevity conference29:18 Jeff's dream of a tech nerd-con31:00 Closing thoughts and wrap up
KeywordsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, John DelMauro, CyberRisk Alliance, Identiverse, Cybersecurity, Event Planning, Networking, InfoSec, AI in Events, Washington DC, Conference Trends

#390 - Identity Management for Agentic AI with Tobin South
In this episode of the Identity at the Center Podcast, hosts Jeff and Jim sit down with Tobin South, co-chair of the OpenID Foundation's AI Identity Management Community Group, to delve into the intricacies of identity management in the age of agentic AI. They discuss the challenges and solutions related to AI agents, the role of the Model Context Protocol (MCP), and the concept of recursive delegation and scope attenuation. Additionally, the conversation covers practical advice for developers and enterprises on preparing for AI-driven identity management and explores the cultural touchstone of coffee from various global perspectives.
Connect with Tobin: https://www.linkedin.com/in/tobinsouth/
OpenID Foundation: https://openid.net/
Identity Management for Agentic AI (OpenID Whitepaper): https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Chapter Timestamps:
00:00 – Jeff and Jim banter about unopened iPads and conference season
05:55 – Introduction to Tobin South and his AI identity background
07:00 – How AI has evolved from machine learning to generative models
09:00 – The OpenID AI Identity Management Community Group
10:30 – ChatGPT’s impact on the AI perception shift
12:00 – Users vs. Agents: What’s the difference?
14:00 – Letting the right bots in: AI agents vs. bad bots
17:00 – AI impersonation, delegation, and the risk of shared credentials
20:00 – Impersonation vs. Delegation – what practitioners need to know
23:00 – Governance, oversight, and delegated authority for agents
26:00 – Liability and “who is responsible” in agentic systems
30:00 – How developers can prepare for agent identity and access management
32:00 – Explaining the Model Context Protocol (MCP)
36:00 – Enterprise use cases for MCP and internal automation
38:00 – Is MCP the next SAML?
42:00 – Recursive delegation and scope attenuation explained
46:00 – The one key takeaway for IAM professionals
48:00 – Lighter note: Coffee talk – from Sydney to San Francisco
54:00 – Wrap-up and where to find more IDAC content
Keywords:
IDAC, Identity at the Center, Jim McDonald, Jeff Steadman, Tobin South, OpenID Foundation, AI Identity Management, Agentic AI, Delegated Authority, Impersonation vs Delegation, Model Context Protocol (MCP), Recursive Delegation, Scope Attenuation, Identity Access Management, IAM, AI Governance, AI Standards, Enterprise AI, AI Agents, Identity Security

#389 - Sponsor Spotlight - Aembit
This episode is sponsored by Aembit. Visit aembit.io/idac to learn more.
Jeff and Jim welcome David Goldschlag, CEO and Co-founder of Aembit, to discuss the rapidly evolving world of non-human access and workload identity. With the rise of AI agents in the enterprise, organizations face a critical challenge: how to secure software-to-software connections without relying on static, shared credentials.
David shares his unique background, ranging from working on The Onion Router (Tor) at the Naval Research Lab to the DIVX rental system, and explains how those experiences inform his approach to identity today. The conversation covers the distinction between human and non-human access, the risks of using user credentials for AI agents, and why we must shift from managing secrets to managing access policies.
This episode explores real-world use cases for AI agents in financial services and retail, the concept of hybrid versus autonomous agents, and practical advice for identity practitioners looking to get ahead of the agentic AI wave.
Visit Aembit: https://aembit.io/idac
Connect with David: https://www.linkedin.com/in/davidgoldschlag
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
Timestamps
00:00 - Intro00:51 - Pronunciation of Aembit and the extra 'E'01:56 - David's background: From NSA to Enterprise Security04:58 - The meaning behind the name Aembit06:00 - David's history with The Onion Router (Tor)10:00 - Differentiating Non-Human Access from Workforce IAM11:39 - The security risks of AI Agents using human credentials14:15 - Manage Access, Not Secrets16:00 - Use Cases: Financial Analysts and Retail24:00 - Hybrid Agents vs. Autonomous Agents30:38 - Will we have agentic versions of ourselves?36:45 - How Identity Practitioners can handle the AI wave38:33 - Measuring success and ROI for workload identity43:20 - A blast from the past: DIVX and Circuit City52:15 - Closing
Keywords
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Aembit, David Goldschlag, Non-human access, Workload Identity, AI Agents, Machine Identity, Cybersecurity, IAM, InfoSec, Tor, DIVX, Zero Trust, Secrets Management, Authentication, Authorization

#388 - Fraud Reduction Intelligence Platforms with John Tolbert
In this episode of The Identity at the Center Podcast, hosts Jim McDonald and Jeff Steadman catch up with John Tolbert, Director of Cybersecurity Research at KuppingerCole Analysts, to talk about the rapidly evolving world of Fraud Reduction Intelligence Platforms (FRIP).
They explore:
- The six capabilities of modern fraud reduction systems
- How AI and machine learning are both helping and hurting fraud prevention
- Why shared signals and orchestration are critical for financial and e-commerce use cases
- How identity verification, device intelligence, and behavioral biometrics work together
- The role of usability and integration in FRI adoption
Plus, stick around for a fun discussion about concerts, classic rock, and which legendary bands they wish they’d seen live.
Listen now to learn how identity, fraud, and AI are colliding — and what’s next for fraud intelligence.
Connect with John: https://www.linkedin.com/in/john-tolbert/
Fraud Reduction Intelligence Platforms - Finance (KuppingerCole Report): https://www.kuppingercole.com/research/lc80841/fraud-reduction-intelligence-platforms-finance
Fraud Reduction Intelligence Platforms - eCommerce (KuppingerCole Report): https://www.kuppingercole.com/research/bc81030/fraud-reduction-intelligence-platforms-ecommerce
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Chapter Timestamps:
00:00 – Jim’s passwordless rant and setup woes
05:00 – Introducing guest John Tolbert
06:30 – Catching up: four years since John’s last appearance
07:30 – What is CIAM and how has it evolved?
09:30 – Understanding Fraud Reduction Intelligence Platforms (FRIP)
10:00 – The six core capabilities of FRI solutions
13:00 – Are most vendors point solutions or full platforms?
14:00 – How identity verification is improving
16:00 – SaaS and API-driven fraud detection models
18:00 – What kinds of fraud can (and can’t) FRI prevent?
21:00 – The growing problem of bots and automation
22:00 – Fraud trends in finance: scams, account takeovers, and synthetic identities
25:00 – Information sharing and the role of shared signals
28:00 – Collaboration vs. competition in fraud prevention
31:00 – Fraud in e-commerce: bots, loyalty points, and returns abuse
34:00 – Streaming and citizen fraud use cases
36:00 – Where do FRI capabilities fit within IAM platforms?
43:00 – The importance of orchestration and integration
44:30 – The role of AI and ML in fraud prevention
47:30 – Smart questions for evaluating FRI vendors
50:30 – Concert talk: Pink Floyd, Metallica, and the ones that got away
58:00 – Wrap-up and where to find John Tolbert’s reports
Keywords:
Fraud Reduction Intelligence, FRI Platforms, John Tolbert, KuppingerCole, Identity at the Center, IDAC, IAM, CIAM, Cybersecurity Research, Fraud Prevention, Machine Learning, Artificial Intelligence, Behavioral Biometrics, Device Intelligence, Identity Verification, Risk Orchestration, API Security, Financial Fraud, E-Commerce Fraud, Shared Signals, Jim McDonald, Jeff Steadman, IDAC Podcast

#387 - InfoSec World 2025 - Trust, Transparency, and Technology: Building Better MSP Partnerships
Jim McDonald and Jeff Steadman sit down with Mike Reiring of RSM at InfoSec World 2025 to explore how managed service providers are reshaping IT and identity operations. They dig into the differences between MSPs and MSSPs, how to choose the right partner, and how AI is transforming help desks, problem management, and security monitoring. The conversation closes with a fun dive into Mike’s passion for photography and how creativity ties into continuous learning in tech.
Connect with Mike: https://www.linkedin.com/in/mreiring/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Chapters
00:00 Intro – Live from InfoSec World 2025
02:00 Meet Mike Reiring of RSM
04:30 Evolution of Managed Service Providers
06:30 Shared Accounts, Identity, and Security Maturity
09:00 Vendor Gaps and Federated Access Challenges
11:30 What Makes a Good MSP Partner
13:00 The Cost and Effort of Changing Providers
16:30 MSP vs MSSP – Key Differences
18:30 Coordination Between Managed Providers
21:30 Top 3 Questions to Ask Your MSP
25:00 Identity Ownership: IT or Security?
27:30 Licensing, Active Directory, and Hidden Accounts
30:00 RFP Challenges and Procurement Pitfalls
32:00 Measuring Risk and Reducing Identity Exposure
34:30 Vendor Management and Shadow IT Risks
35:00 How AI Is Transforming MSP and MSSP Operations
38:30 AI, Problem Management, and the Future of Help Desks
42:30 Photography, Creativity, and Continuous Learning
48:00 Closing Thoughts and IDAC Outro
Keywords
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Reiring, RSM, InfoSec World 2025, Managed Service Provider, MSP, MSSP, AI in Cybersecurity, Help Desk, Identity Management, Managed Identity, Partner Transparency, IT Outsourcing, Risk Reduction, Problem Management, Active Directory, DaVinci Resolve, Photography in Tech, Identity Governance, Cybersecurity Podcast

#386 - InfoSec World 2025 - CISO Tradecraft for IAM
In this episode of the Identity at the Center podcast, hosts Jeff and Jim broadcast from InfoSec World 2025, sharing lively discussions on identity management, AI security, and identity's evolving role in information security. They are joined by Ross Young and G Mark Hardy, co-hosts of the CISO Tradecraft podcast, who share their journeys into cybersecurity, illuminating how identity intersects with cybersecurity topics like deep fakes, AI implications, and non-human identities. The conversation also covers practical advice for securing budget approvals for identity projects and speculations on the role of AI in cybersecurity's future. The episode wraps up with each guest sharing personal ideas for potential new podcast ventures.
The CISO Tradecraft podcast: CISOTradecraft.com
Connect with Ross: https://www.linkedin.com/in/mrrossyoung/
Connect with G Mark: https://www.linkedin.com/in/gmarkhardy/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
Chapters
00:00 Introduction and Welcome
00:16 Live from InfoSec World 2025
00:52 Shoutouts and Day Jobs
01:37 Meeting Ross and G Mark from the CISO Tradecraft podcast
02:22 Ross's Journey into Cybersecurity
04:24 G Mark's Cybersecurity Career Path
07:44 Top Concerns for CISOs Today
09:53 The Role of Identity in Cybersecurity
16:18 Challenges and Trends in Identity Management
24:33 Pitching Identity Projects to CISOs
32:21 The Role of AI in Automating SOC Operations
33:23 AI's Impact on Developer Efficiency
35:48 The Future of AI-Assisted Coding
37:42 Challenges and Opportunities in AI and Cybersecurity
39:46 The Importance of Human Expertise in AI Development
48:17 The Role of Identity in Information Security
49:44 Introduction to CISO Tradecraft Podcast
55:24 Podcasting Tips and Personal Interests
01:00:48 Conclusion and Final Thoughts
Keywords:
Identity at the Center, IDAC, CISO Tradecraft, InfoSec World 2025, cybersecurity leadership, identity security, IAM, AI security, Jeff Steadman, Jim McDonald, Ross Young, G. Mark Hardy, InfoSec, CISOs, cyber career development, non-human identity, deepfakes, security automation