Identity at the Center

Identity at the Center

Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what?

  1. vor 1 Tag

    #437 - Identiverse 2026 - Pam Dingle

    Live from the IDAC booth at Identiverse 2026, Jeff and Jim sit down with Pam Dingle, Director of Identity Standards at Microsoft, to unpack agentic identity. Pam breaks down assistive versus autonomous agents, walks through where standards like SPIFFE and OAuth hold up, and explains the difference between delegation, impersonation, and partition. The conversation also covers credential discovery risk, shared signals and revocation, what enterprises should prioritize now, and the value of hallway conversations at Identiverse. Connect with Pam: https://www.linkedin.com/in/pameladingle/ OAuth Actor Profile for Delegation: https://www.ietf.org/archive/id/draft-mcguinness-oauth-actor-profile-00.html Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com Timestamps: 00:00 Intro and Identiverse 2026 vibes 04:01 Defining agentic identity 07:06 Has the earth really shifted 11:38 An old problem thats been bejeweled 15:13 From Nulli Secundus to Microsoft 16:00 How standards are holding up 19:27 Client ID metadata and just in time trust 21:41 Shared signals and the revocation problem 24:43 Deploying agentic identity at scale 28:11 Registries at scale 29:04 Delegation authorization and attenuation 32:33 Delegation vs impersonation vs partition 36:03 The one thing you can fix right now 37:56 Favorite hallway conversation 42:29 The solar system of hallway conversations 45:51 Remembering Kim Cameron 48:00 New voices to watch 52:08 Wrap up and thank you Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Pam Dingle, Pamela Dingle, Microsoft, Identiverse 2026, agentic identity, agentic AI, non-human identity, delegation, impersonation, SPIFFE, OAuth, identity standards, IAM, digital identity, workload identity

  2. vor 6 Tagen

    #436 - Sponsor Spotlight - P0 Security

    In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, covering how it applies to humans, non-human identities, and AI agents alike. The conversation digs into the difference between authentication and authorization, why zero standing privilege is more achievable now than before agentic adoption took hold, and how dynamic, evidence-based policies can reduce reliance on manual approvals. Greg also shares real examples, including row-level access control for data lakes and a CRM mishap that shows how easily agents can misinterpret intent. The episode closes with a look at where enterprise AI agent governance may be headed over the next few years, plus a lighter conversation about explaining IAM to a 10-year-old. This episode is made possible through the generous support of P0 Security as part of IDAC's nonprofit Sponsor Spotlight series. Learn more at p0.dev/idac. Connect with Greg (Gergely): https://www.linkedin.com/in/gergely-danyi/ Learn more about P0: https://p0.dev/idac/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00 - Introduction and sponsor acknowledgment 01:13 - Greg Danyi's path into IAM 02:18 - What P0 Security solves for 03:21 - Where P0 fits versus PAM and IGA 04:46 - Agentic identity as a driver of adoption 05:27 - MCP servers and unpredictable agent actions 07:10 - Defining runtime access control 08:50 - How authentication and authorization work together 09:07 - Standing access versus expressed intent 10:16 - Zero standing privilege in practice 12:27 - Agentic identity as a distinct identity class 19:24 - Automated evidence for approvals 20:42 - Walking through a support agent example 22:13 - Row-level access control for data lakes 23:35 - Dynamic roles explained 29:55 - CRUD risks and underestimated concerns 31:32 - Human intent and giving agents clear direction 36:32 - Where enterprise AI agent governance is headed 39:36 - Advice for CIOs and CISOs getting started 41:15 - Explaining IAM to a 10-year-old 42:29 - Board games, dice, and calculated risk 44:00 - Closing thoughts and where to learn more Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Greg Danyi, P0 Security, runtime access control, agentic identity, zero standing privilege, non-human identity, authentication, authorization, IAM podcast

  3. 20. Juli

    #435 - Majority Rules: IDAC Live at Identiverse 2026

    Jim McDonald and Jeff Steadman took the Identity at the Center podcast live at Identiverse 2026 in Las Vegas for a crowd-sourced game show called Majority Rules. Identity professionals competed in real time, picking answers to IAM and conference questions in a race to predict the majority. With a prize pool of over $5,000 for the top ten scorers, the stakes were high and the honesty was brutal. The episode also marks a milestone: IDAC hitting two million downloads. Thanks to Shirley Han and the CyberRisk Alliance team, and to sponsors Hyper, Red Block, SlashId, Rubrik, Stratacity, FusionAuth, Nexus, CrowdStrike, Hush Security, PlainId, RSM, and CyberRisk Alliance. Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 0:00 Introduction and Two Million Downloads Milestone 1:00 Sponsor and Event Team Recognition 3:00 How to Play Majority Rules 4:00 Warm-Up Round Begins 6:00 Battle Royale Mode Explained 8:30 Decentralized Identity and the LDAP Reality 10:30 Las Vegas Evening Entertainment 11:30 Top Identity Trends at Identiverse 2026 12:30 Access Certification and the 4:55 PM Click 13:30 Classic Vegas and Expo Hall Favorites 14:50 PAM Strategies and the Post-it Note 16:00 Conference Navigation and Footwear Survival 18:00 Identity Log Monitoring Chaos 19:30 Hallway Track Conversations 20:30 Cloud Entitlements and Everyone Gets Root 21:00 Sleep Habits at a Security Conference 22:00 Business Cards in 2026 23:00 Legacy App Strategy and Thoughts and Prayers 24:45 Las Vegas Dining Preferences 25:30 Winners Announced and Closing Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Identiverse, Identiverse 2026, Majority Rules, live event, game show, IAM, identity and access management, decentralized identity, LDAP, SSO, PAM, privileged access management, cloud entitlements, ISPM, access certification, Las Vegas, cybersecurity, conference

  4. 13. Juli

    #434 - Identiverse 2026 - IdentiBeer Las Vegas

    Recorded the night before Identiverse 2026 at BrewDog in Las Vegas, Jeff hosts a roundtable of IdentiBeer chapter leaders and community members from around the world. Espen Bago (Oslo), Marco Venuti (Rome and Milan), Heiko Klarl (Munich), Craig Ramsay (Nashville), Tina Srivastava and Elie Azerad (San Francisco), Bertrand Carlier (Paris, in planning), Ole Shved (Detroit, forming), and Roland Baum (Frankfurt) share what makes IdentiBeer work, how chapters get started, and what draws people in. First-time Identiverse attendee Varshith Reddy joins mid-conversation for some live conference tips. The group celebrates going 35 minutes without mentioning AI and closes with everyone's drink of choice and an impromptu MFA rap. Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 0:00 Welcome and intro 0:41 What is IdentiBeer? Espen Bago explains 2:31 Marco Venuti and the Italian chapters 5:07 Could there be an IdentiBeer conference? 6:03 Heiko Klarl and IdentiBeer Munich 7:09 Craig Ramsay and the new Nashville chapter 9:53 Beer is just clickbait and vendor neutrality 12:45 Tina Srivastava and the IDPro Slack connection 13:18 Ole Shved and the future Detroit chapter 14:14 Advice for new chapter organizers 16:33 Keep the momentum: do another one soon 17:01 What draws people to IdentiBeer? 17:37 The IdentiBeer charter and inclusivity 18:20 Elie Azerad and the San Francisco chapter 21:08 Tina and the South Bay satellite idea 25:50 Bertrand Carlier and plans for Paris 29:31 Varshith Reddy: tips for first-time Identiverse attendees 34:12 35 minutes without saying AI 36:20 Roland Baum and the Frankfurt Identivier 39:06 What is your drink of choice? 40:48 Tina's MFA rap and closing thoughts Keywords: IdentiBeer, Identiverse 2026, IAM community, Identity and Access Management, Jeff Steadman, Jim McDonald, IDAC, Identity at the Center, Espen Bago, Marco Venuti, Heiko Klarl, Craig Ramsay, Tina Srivastava, Elie Azerad, Bertrand Carlier, Ole Shved, Roland Baum, Varshith Reddy, IDPro, community building, vendor neutral, IAM networking, Las Vegas

  5. 8. Juli

    #433 - Sponsor Spotlight - FusionAuth

    Jim McDonald sits down with Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, for an in-depth conversation on customer identity and access management. Dan explains how FusionAuth views authentication as the front door to any application and why control, deployment flexibility, and developer ownership are central to their approach. The discussion covers progressive registration, friction vs. usability, customization options, identity standards, the build vs. buy debate, risk-based MFA, and how AI agents will shape the future of customer identity. This episode and others is made possible with support from FusionAuth. Learn more at fusionauth.io/idac. Connect with Dan: https://www.linkedin.com/in/mooreds/ Learn more about FusionAuth: https://fusionauth.io/idac Blog article mentioned: https://bobdahacker.com/blog/fifa-hack Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00:00 Introduction 00:01:18 What is FusionAuth? 00:03:15 Dan's identity origin story 00:04:19 Developer focus and ethos 00:06:54 Authentication as the front door 00:10:00 Balancing friction and usability 00:15:24 Customization in CIAM 00:18:10 What sets FusionAuth apart 00:20:33 FusionAuth's customer sweet spot 00:25:48 Deployment flexibility and the control spectrum 00:30:19 Common challenges in CIAM 00:33:06 Build vs. buy for authentication 00:36:00 Omni-channel authentication 00:40:27 Why identity standards matter 00:42:07 Risk-based MFA and intelligent challenges 00:45:00 AI agents and the future of CIAM 00:49:23 Closing thoughts 00:51:35 Vacation roundup Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Moore, FusionAuth, CIAM, customer identity, authentication, access management, IAM, identity standards, MFA, risk-based authentication, progressive registration, OAuth, OIDC, SAML, AI agents, deployment flexibility, build vs buy, Sponsor Spotlight

  6. 6. Juli

    #432 - IdentiBeer Rome and 3 Courses of IAM with Alessandro Piscopo

    Jim McDonald takes the Identity at the Center podcast on the road to Rome, Italy, for a special two-part episode. The first segment is an IdentiBeer roundup where Jim gathers quick-fire takes from practitioners in the Italian IAM community, including Andrea Rossi and Alessandro Piscopo of IAMONES and Marco Venuti of Thales on the biggest trends shaping identity today. The second segment is a three-course meal where Jim sits down with Alessandro Piscopo, Head of AI and Co-founder at IAMONES, to discuss AI and identity over food and wine. Across a seafood starter, scialatielli alla pescatora, and tiramisu, the conversation covers the history of AI in identity, why LLMs represent a revolution rather than an evolution, the AI-first product philosophy versus retrofitting AI onto legacy systems, compute and architecture constraints facing large language models, and what life looks like for the IAM practitioner in 2030. Alessandro envisions an identity equivalent of Claude Code, a specialized AI tool that democratizes identity expertise the way coding assistants have transformed software development. 0:00 Intro and IdentiBeer Rome roundup 7:01 Alessandro on AI for IAM vs. IAM for AI 12:00 Three-course dinner begins - Course 1: Seafood starter 14:09 History of AI in identity, from ML models to LLMs 17:51 Course 2: Scialatielli alla pescatora and Falanghina wine 19:56 AI-first products vs. AI layered onto legacy systems 22:00 Transition period and the new world of identity 24:04 The ChatGPT moment vs. the iPhone moment 27:05 Compute constraints, energy costs, and architecture breakthroughs 30:46 Smaller models and cost-efficiency tradeoffs 32:35 Course 3: Tiramisu, baba, and espresso 33:00 Life as an IAM practitioner in 2030 35:19 Claude Code for IAM and democratizing identity tools 37:24 App store ecosystem analogy for AI platforms 43:07 Closing thoughts Keywords: IAM, identity and access management, AI for IAM, IAM for AI, agentic AI, non-human identity, IGA, LLMs, large language models, AI-first, machine learning, Alessandro Piscopo, IAMONES, Jim McDonald, Jeff Steadman, Identity at the Center, IDAC, IdentiBeer, Rome, Italy, Marco Venuti, Thales, Andrea Rossi, agentic identity, transformer architecture, compute efficiency, identity practitioner 2030, Claude Code for IAM, identity democratization, Identiverse, European Identity Conference

  7. 29. Juni

    #431 - Tectonic Shifts in Identity Security with Martin Kuppinger

    Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Kuppinger, founder and distinguished analyst at KuppingerCole. They dig into the tectonic shifts AI is bringing to identity and security, the AI security fabric framework, why decentralized identity thinking may be essential for governing the agentic mesh, the ongoing debate over NHI terminology, what organizations can do tactically today, and what concerns Martin most about where the industry is heading by 2030. Connect with Martin: https://www.linkedin.com/in/martinkuppinger/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00 Introduction and Welcome 00:50 What a Distinguished Analyst Does 01:37 EIC 2026: Thought Leadership and Best Practice 04:17 Agentic AI: Non-Directed, Non-Deterministic Identity 08:22 Speed of Change: Tactical Now, Strategic Later 12:34 The AI Security Fabric: Five Capability Blocks 15:10 Identity Fabric Origins and Market Growth 18:27 Discovery as the Foundation for Governance 19:48 Governance, Explainability, and Organizational Gaps 22:00 Agent Lineage and Rethinking NHI Terminology 23:50 LLMs vs. Small Language Models 26:23 Is Agentic Identity a Genuinely New Problem? 32:29 Humanoid Robots and the Limits of AI Reasoning 37:05 Decentralized Identity, Trust Frameworks, and Signals 41:07 Identity Verification and Consent for Agents 48:42 What Concerns Martin About the Future of Identity 50:34 Favorite AI Application: Assisted Driving 55:00 Self-Driving Cars, Data, and Personal Privacy Keywords: Martin Kuppinger, KuppingerCole, EIC 2026, EIC Berlin, agentic AI, AI security fabric, identity fabric, decentralized identity, AI governance, non-human identity, autonomous identity, dependent identity, agent lineage, explainability, MCP server, small language models, verifiable credentials, risk-based authorization, OT security, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity security

  8. 22. Juni

    #430 - AI for IAM and IAM for AI with Martin Sandren

    Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Sandren, IAM Product Lead at IKEA, for a wide-ranging conversation covering nearly every corner of modern identity security. Martin shares what has changed since his first IDAC appearance on episode 293, including the rise of AI, growing interest in digital sovereignty, and the maturing shared signals framework. The conversation moves through risk-based defense in depth, tiered MFA rollout strategies, session management, and the real challenge of trusting AI to make security decisions. Martin introduces identity dark matter and explains how IVIP can surface the 95-plus percent of applications that never reach an IGA system. The episode also covers shadow AI, MCP server risks, the SaaSpocalypse debate, and the EU AI Act. It closes on a grounded note: solar panels. Connect with Martin: https://www.linkedin.com/in/martinsandren/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com TIMESTAMPS 00:00 Welcome and EIC 2026 intro 01:47 What has changed in two years: AI, sovereignty, shared signals 03:06 Martin's EIC presentations: AI for IAM and IAM for AI 04:46 Can you prioritize one direction over the other? 07:13 What would it take to trust AI making identity decisions? 09:32 AI-enhanced detection and risk-based session management 13:07 Session invalidation and the shared signals framework 14:11 Defense in depth and right-sizing privileges 18:25 MFA today: any MFA versus phish-resistant MFA 19:17 AI chatbots, enterprise LLMs, and shadow AI 23:11 MCP servers, NHI risk, and return on risk thinking 27:00 AI configuring IAM systems: how close are we? 31:30 LLM costs, the SaaSpocalypse, and enterprise AI futures 40:10 Identity dark matter and the IVIP concept 44:16 CMDB versus IVIP: do you need both? 46:18 The EU AI Act and building an AI governance registry 49:18 Where to start: get your AI inventory in place first 50:00 Closing thoughts and the solar panel tangent KEYWORDS AI for IAM, IAM for AI, identity dark matter, IVIP, IGA, shared signals framework, phish-resistant MFA, defense in depth, session management, MCP servers, NHI, shadow AI, SaaSpocalypse, EU AI Act, AI governance, zero standing privilege, EIC 2026, IKEA, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Martin Sandren

Info

Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what?