This is sort of based on an ongoing conversation at work, but I’m curious: what is everyone imagining identity looks like after Active Directory falls? It may not ever go away, but it’s already on life support. Entra is not the same thing, and I don’t think it will enjoy the same market domination as the on-prem product.
I do not have any particular product in mind, but the last few years have all pointed us (back) 1 direction:
Agentic systems exacerbating identity issues
Poorly controlled VSCode and Chrome extensions in marketplaces and within organizations
3rd party and supply chain compromises
Living off Trusted Sites, Tunnels and RMMs
Every Dragos report Dad-ing us on East-West controls
Limitations of SIEMs, RBA and UEBA
Welcome back ZTA, old friend!
Because LLMs suck the air out of every room, machine learning gets put in a corner, but it is also making (quiet) strides. We’re much better suited today for reliable behavioral controls, just-in-time access workflows, risk-based analytics/alerting, and I’d like to think we all got a little better with certs.
And unfortunately that 25 year old hierarchal database with decades of data quality issues stands in our way.
AD is most orgs’ root of much tech debt. I await the day we no longer have the CMDB problem in IAM and this bromide finally ends:
LLMs may in fact exacerbate this issue as well, as agentic work needs to occur under the guise of some identity. Is it the operator? A service account? a gMSA? AD is ill-equipped to represent the nature of agents. If they aren’t going away, they must be dealt with, which means a new and better means of identity management.
For my part, I imagine a future state where your core identity warehouse is some flavor of SCIM, accompanied by an AD “emulation layer” for anything that still requires a traditional domain.