Choosing identity and access management software should begin with a close look at your organisation's existing IT setup. The solution needs to work with the applications and systems already in place, while making it easy for users to access the resources they need and helping you meet security and compliance requirements. Factors such as the applications you use, how users authenticate, how identities are managed, and where the solution will be deployed can all affect your choice of an IAM solution. Looking at these requirements first gives you a more practical way to compare solutions and find one that fits your organisation, rather than choosing based on the number of features a product offers.
Key Takeaways
- Assess your organisation’s requirements, including its existing applications, systems, users and identity needs.
- Evaluate authentication and application support, including SSO, MFA, passwordless authentication and support for modern and legacy applications.
- Look at identity governance and integration, including lifecycle management, access certification, role management, SoD and integration with enterprise or home-grown applications.
- Consider deployment, compliance and support, including on-premises, cloud or hybrid options, audit requirements, implementation services and ongoing support.
Key Factors to Consider When Evaluating Enterprise IAM Software
1. Start With Your Enterprise IAM Requirements
Before comparing identity and access management software, first look at what your organisation needs from it. Which applications need to be covered? Who uses them? How is access managed today, and what happens when someone's role changes or they leave?
The requirements will vary from one organisation to another. You may only need authentication and application access, or you may also need access approvals, access reviews, role management and Segregation of Duties. Having a clear list of requirements makes it easier to compare IAM solutions.
2. Evaluate Authentication and Access Capabilities
Every time a user logs in, the IAM system needs to verify that they are who they claim to be. The method used can vary depending on the application and the level of security required.
Some features to look for are:
- Single Sign-On (SSO) for using multiple applications with one login
- Multi-Factor Authentication (MFA) for an extra verification step
- Passwordless authentication, including WebAuthn
- Context-based authentication using details such as location, time and device
- Support for the authentication protocols already used by your applications
IamLogic Access Manager supports SSO, SAML 2.0, OpenID Connect, OAuth2 and RADIUS. It also offers adaptive MFA and passwordless authentication through WebAuthn. Its policies can use location, network, time and device information when handling a login.
3. Check Application Compatibility
Take a look at the full application environment before choosing an IAM solution. Most organisations have a mix of newer applications, older systems and software built internally.
Older applications may not support modern authentication methods. Some may also need a different way of connecting to the IAM platform.
Check whether the solution can support modern and legacy applications, home-grown systems and applications that require alternative integration methods. This can save problems later, especially when older systems are still used for important business processes.
4. Assess Identity Governance Capabilities
Getting users through the login screen is only one part of access management. You also need to keep track of what they can access and what happens to that access when their role changes.
Depending on your requirements, you may need:
- Joiner-Mover-Leaver lifecycle management
- User provisioning and deprovisioning
- Access requests and approvals
- Access certification
- Role management and role mining
- Segregation of Duties (SoD) controls
For example, an employee may have access to several systems when they join the company. If they move to another team, some of that access may need to be changed. When they leave, it needs to be removed.
IamLogic IGA supports these lifecycle processes, as well as access certification, role management, role mining and SoD controls. SoD can help keep conflicting activities apart, such as initiating a payment and approving it.
5. Review Integration and Extensibility
IAM software has to connect with the systems that are already part of your IT environment. These may include directories, business applications, databases, APIs and internally developed applications.
Before choosing a platform, find out:
- Which of your existing systems can be connected?
- Can custom integrations be built?
- What happens when an application has no API?
- Can new connectors be added later?
This matters because application environments are rarely uniform. One system may have a standard API, while another may need a completely different approach. The IAM platform needs to handle those differences without making every new integration a separate project.
6. Consider Deployment and Infrastructure
Think about where the IAM software will run and how it will fit with your existing setup.
Depending on your organisation, you may need an on-premises, cloud or hybrid deployment. High availability and disaster recovery may also be requirements for critical environments.
Your infrastructure, security needs and operational setup should guide the choice. The deployment model should fit into your current environment rather than create unnecessary complexity.
7. Evaluate Compliance and Audit Capabilities
User access needs to be traceable. If someone asks who has access to a system, why they have it or when that access was removed, you should be able to find the answer.
Useful records and reports can include:
- Access certification results
- SoD status
- Deprovisioning records
- Orphan account information
- Access records
- Approval and request history
- Audit trails and compliance reports
The information you need will depend on your organisation and the regulations it follows. Make sure the identity and access management software you choose can provide the records needed for your audits and compliance processes.
8. Review Implementation and Support
The product is not the only thing to consider. IAM projects can involve application integrations, connector development, configuration and ongoing administration.
Before choosing a provider, check what help is available for:
- Connector development
- IAM consulting and services
- Implementation
- Technical support
- High availability and disaster recovery
- Ongoing administration
IamLogic provides IAM consulting and services, including connector development. Its product information also highlights 24×7 support and HA/DR capabilities.
These services can make a difference once the platform moves from evaluation to actual implementation and day-to-day use.
The Bottom Line
Evaluating identity and access management software requires looking at how well it fits your organisation’s applications, infrastructure and access requirements. Authentication, application compatibility, identity governance, integration, deployment and compliance all need to be considered before making a decision.
A thorough evaluation can help you identify an IAM solution that works with your current environment and provides the capabilities needed to manage identities and access across the enterprise.
IamLogic brings Access Manager and IamLogic IGA together to address these different aspects of identity management. Access Manager covers authentication and application access, while IGA supports identity lifecycle management, access certification, role management, role mining and Segregation of Duties. Together, these capabilities provide organisations with a broader approach to managing identities and access across their environment.
FAQ
FAQs on Evaluating Enterprise IAM Software
What should you consider when evaluating enterprise IAM software?
Consider authentication, application compatibility, identity lifecycle management, access governance, integrations, deployment options, compliance requirements and ongoing support.
What features should enterprise IAM software include?
Key capabilities to evaluate include SSO, MFA, passwordless authentication, context-based authentication, application integration, identity lifecycle management, access certification, role management and SoD controls.
Should enterprise IAM software support legacy applications?
Yes. If an organisation relies on legacy applications, it is important to check whether the IAM software can manage applications that do not support modern authentication protocols.
What is the difference between IAM and IGA?
IAM focuses on authentication and access, while IGA focuses on governing identities and access throughout their lifecycle, including provisioning, access reviews, roles and SoD.
What deployment options should you consider for enterprise IAM software?
Organisations should consider whether they need an on-premises, cloud or hybrid deployment based on their existing infrastructure and requirements.
Why are integrations important when choosing an IAM solution?
Enterprise IAM software needs to work with the applications, directories and systems already used by the organisation. Extensibility is also important when applications require custom integration.