
Hosted by Identity at the Center · EN

In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, covering how it applies to humans, non-human identities, and AI agents alike. The conversation digs into the difference between authentication and authorization, why zero standing privilege is more achievable now than before agentic adoption took hold, and how dynamic, evidence-based policies can reduce reliance on manual approvals. Greg also shares real examples, including row-level access control for data lakes and a CRM mishap that shows how easily agents can misinterpret intent. The episode closes with a look at where enterprise AI agent governance may be headed over the next few years, plus a lighter conversation about explaining IAM to a 10-year-old. This episode is made possible through the generous support of P0 Security as part of IDAC's nonprofit Sponsor Spotlight series. Learn more at p0.dev/idac.Connect with Greg (Gergely): https://www.linkedin.com/in/gergely-danyi/Learn more about P0: https://p0.dev/idac/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Introduction and sponsor acknowledgment01:13 - Greg Danyi's path into IAM02:18 - What P0 Security solves for03:21 - Where P0 fits versus PAM and IGA04:46 - Agentic identity as a driver of adoption05:27 - MCP servers and unpredictable agent actions07:10 - Defining runtime access control08:50 - How authentication and authorization work together09:07 - Standing access versus expressed intent10:16 - Zero standing privilege in practice12:27 - Agentic identity as a distinct identity class19:24 - Automated evidence for approvals20:42 - Walking through a support agent example22:13 - Row-level access control for data lakes23:35 - Dynamic roles explained29:55 - CRUD risks and underestimated concerns31:32 - Human intent and giving agents clear direction36:32 - Where enterprise AI agent governance is headed39:36 - Advice for CIOs and CISOs getting started41:15 - Explaining IAM to a 10-year-old42:29 - Board games, dice, and calculated risk44:00 - Closing thoughts and where to learn moreKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Greg Danyi, P0 Security, runtime access control, agentic identity, zero standing privilege, non-human identity, authentication, authorization, IAM podcast

Jim McDonald and Jeff Steadman took the Identity at the Center podcast live at Identiverse 2026 in Las Vegas for a crowd-sourced game show called Majority Rules. Identity professionals competed in real time, picking answers to IAM and conference questions in a race to predict the majority. With a prize pool of over $5,000 for the top ten scorers, the stakes were high and the honesty was brutal. The episode also marks a milestone: IDAC hitting two million downloads. Thanks to Shirley Han and the CyberRisk Alliance team, and to sponsors Hyper, Red Block, SlashId, Rubrik, Stratacity, FusionAuth, Nexus, CrowdStrike, Hush Security, PlainId, RSM, and CyberRisk Alliance.Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com0:00 Introduction and Two Million Downloads Milestone1:00 Sponsor and Event Team Recognition3:00 How to Play Majority Rules4:00 Warm-Up Round Begins6:00 Battle Royale Mode Explained8:30 Decentralized Identity and the LDAP Reality10:30 Las Vegas Evening Entertainment11:30 Top Identity Trends at Identiverse 202612:30 Access Certification and the 4:55 PM Click13:30 Classic Vegas and Expo Hall Favorites14:50 PAM Strategies and the Post-it Note16:00 Conference Navigation and Footwear Survival18:00 Identity Log Monitoring Chaos19:30 Hallway Track Conversations20:30 Cloud Entitlements and Everyone Gets Root21:00 Sleep Habits at a Security Conference22:00 Business Cards in 202623:00 Legacy App Strategy and Thoughts and Prayers24:45 Las Vegas Dining Preferences25:30 Winners Announced and ClosingKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Identiverse, Identiverse 2026, Majority Rules, live event, game show, IAM, identity and access management, decentralized identity, LDAP, SSO, PAM, privileged access management, cloud entitlements, ISPM, access certification, Las Vegas, cybersecurity, conference

Recorded the night before Identiverse 2026 at BrewDog in Las Vegas, Jeff hosts a roundtable of IdentiBeer chapter leaders and community members from around the world. Espen Bago (Oslo), Marco Venuti (Rome and Milan), Heiko Klarl (Munich), Craig Ramsay (Nashville), Tina Srivastava and Elie Azerad (San Francisco), Bertrand Carlier (Paris, in planning), Ole Shved (Detroit, forming), and Roland Baum (Frankfurt) share what makes IdentiBeer work, how chapters get started, and what draws people in. First-time Identiverse attendee Varshith Reddy joins mid-conversation for some live conference tips. The group celebrates going 35 minutes without mentioning AI and closes with everyone's drink of choice and an impromptu MFA rap.Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com0:00 Welcome and intro0:41 What is IdentiBeer? Espen Bago explains2:31 Marco Venuti and the Italian chapters5:07 Could there be an IdentiBeer conference?6:03 Heiko Klarl and IdentiBeer Munich7:09 Craig Ramsay and the new Nashville chapter9:53 Beer is just clickbait and vendor neutrality12:45 Tina Srivastava and the IDPro Slack connection13:18 Ole Shved and the future Detroit chapter14:14 Advice for new chapter organizers16:33 Keep the momentum: do another one soon17:01 What draws people to IdentiBeer?17:37 The IdentiBeer charter and inclusivity18:20 Elie Azerad and the San Francisco chapter21:08 Tina and the South Bay satellite idea25:50 Bertrand Carlier and plans for Paris29:31 Varshith Reddy: tips for first-time Identiverse attendees34:12 35 minutes without saying AI36:20 Roland Baum and the Frankfurt Identivier39:06 What is your drink of choice?40:48 Tina's MFA rap and closing thoughtsKeywords: IdentiBeer, Identiverse 2026, IAM community, Identity and Access Management, Jeff Steadman, Jim McDonald, IDAC, Identity at the Center, Espen Bago, Marco Venuti, Heiko Klarl, Craig Ramsay, Tina Srivastava, Elie Azerad, Bertrand Carlier, Ole Shved, Roland Baum, Varshith Reddy, IDPro, community building, vendor neutral, IAM networking, Las Vegas

Jim McDonald sits down with Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, for an in-depth conversation on customer identity and access management. Dan explains how FusionAuth views authentication as the front door to any application and why control, deployment flexibility, and developer ownership are central to their approach. The discussion covers progressive registration, friction vs. usability, customization options, identity standards, the build vs. buy debate, risk-based MFA, and how AI agents will shape the future of customer identity. This episode and others is made possible with support from FusionAuth. Learn more at fusionauth.io/idac.Connect with Dan: https://www.linkedin.com/in/mooreds/Learn more about FusionAuth: https://fusionauth.io/idacBlog article mentioned: https://bobdahacker.com/blog/fifa-hackConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00:00 Introduction00:01:18 What is FusionAuth?00:03:15 Dan's identity origin story00:04:19 Developer focus and ethos00:06:54 Authentication as the front door00:10:00 Balancing friction and usability00:15:24 Customization in CIAM00:18:10 What sets FusionAuth apart00:20:33 FusionAuth's customer sweet spot00:25:48 Deployment flexibility and the control spectrum00:30:19 Common challenges in CIAM00:33:06 Build vs. buy for authentication00:36:00 Omni-channel authentication00:40:27 Why identity standards matter00:42:07 Risk-based MFA and intelligent challenges00:45:00 AI agents and the future of CIAM00:49:23 Closing thoughts00:51:35 Vacation roundupKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Moore, FusionAuth, CIAM, customer identity, authentication, access management, IAM, identity standards, MFA, risk-based authentication, progressive registration, OAuth, OIDC, SAML, AI agents, deployment flexibility, build vs buy, Sponsor Spotlight

Jim McDonald takes the Identity at the Center podcast on the road to Rome, Italy, for a special two-part episode. The first segment is an IdentiBeer roundup where Jim gathers quick-fire takes from practitioners in the Italian IAM community, including Andrea Rossi and Alessandro Piscopo of IAMONES and Marco Venuti of Thales on the biggest trends shaping identity today. The second segment is a three-course meal where Jim sits down with Alessandro Piscopo, Head of AI and Co-founder at IAMONES, to discuss AI and identity over food and wine.Across a seafood starter, scialatielli alla pescatora, and tiramisu, the conversation covers the history of AI in identity, why LLMs represent a revolution rather than an evolution, the AI-first product philosophy versus retrofitting AI onto legacy systems, compute and architecture constraints facing large language models, and what life looks like for the IAM practitioner in 2030. Alessandro envisions an identity equivalent of Claude Code, a specialized AI tool that democratizes identity expertise the way coding assistants have transformed software development.0:00 Intro and IdentiBeer Rome roundup7:01 Alessandro on AI for IAM vs. IAM for AI12:00 Three-course dinner begins - Course 1: Seafood starter14:09 History of AI in identity, from ML models to LLMs17:51 Course 2: Scialatielli alla pescatora and Falanghina wine19:56 AI-first products vs. AI layered onto legacy systems22:00 Transition period and the new world of identity24:04 The ChatGPT moment vs. the iPhone moment27:05 Compute constraints, energy costs, and architecture breakthroughs30:46 Smaller models and cost-efficiency tradeoffs32:35 Course 3: Tiramisu, baba, and espresso33:00 Life as an IAM practitioner in 203035:19 Claude Code for IAM and democratizing identity tools37:24 App store ecosystem analogy for AI platforms43:07 Closing thoughtsKeywords: IAM, identity and access management, AI for IAM, IAM for AI, agentic AI, non-human identity, IGA, LLMs, large language models, AI-first, machine learning, Alessandro Piscopo, IAMONES, Jim McDonald, Jeff Steadman, Identity at the Center, IDAC, IdentiBeer, Rome, Italy, Marco Venuti, Thales, Andrea Rossi, agentic identity, transformer architecture, compute efficiency, identity practitioner 2030, Claude Code for IAM, identity democratization, Identiverse, European Identity Conference

Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Kuppinger, founder and distinguished analyst at KuppingerCole. They dig into the tectonic shifts AI is bringing to identity and security, the AI security fabric framework, why decentralized identity thinking may be essential for governing the agentic mesh, the ongoing debate over NHI terminology, what organizations can do tactically today, and what concerns Martin most about where the industry is heading by 2030.Connect with Martin: https://www.linkedin.com/in/martinkuppinger/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 Introduction and Welcome00:50 What a Distinguished Analyst Does01:37 EIC 2026: Thought Leadership and Best Practice04:17 Agentic AI: Non-Directed, Non-Deterministic Identity08:22 Speed of Change: Tactical Now, Strategic Later12:34 The AI Security Fabric: Five Capability Blocks15:10 Identity Fabric Origins and Market Growth18:27 Discovery as the Foundation for Governance19:48 Governance, Explainability, and Organizational Gaps22:00 Agent Lineage and Rethinking NHI Terminology23:50 LLMs vs. Small Language Models26:23 Is Agentic Identity a Genuinely New Problem?32:29 Humanoid Robots and the Limits of AI Reasoning37:05 Decentralized Identity, Trust Frameworks, and Signals41:07 Identity Verification and Consent for Agents48:42 What Concerns Martin About the Future of Identity50:34 Favorite AI Application: Assisted Driving55:00 Self-Driving Cars, Data, and Personal PrivacyKeywords: Martin Kuppinger, KuppingerCole, EIC 2026, EIC Berlin, agentic AI, AI security fabric, identity fabric, decentralized identity, AI governance, non-human identity, autonomous identity, dependent identity, agent lineage, explainability, MCP server, small language models, verifiable credentials, risk-based authorization, OT security, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity security

Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Sandren, IAM Product Lead at IKEA, for a wide-ranging conversation covering nearly every corner of modern identity security. Martin shares what has changed since his first IDAC appearance on episode 293, including the rise of AI, growing interest in digital sovereignty, and the maturing shared signals framework. The conversation moves through risk-based defense in depth, tiered MFA rollout strategies, session management, and the real challenge of trusting AI to make security decisions. Martin introduces identity dark matter and explains how IVIP can surface the 95-plus percent of applications that never reach an IGA system. The episode also covers shadow AI, MCP server risks, the SaaSpocalypse debate, and the EU AI Act. It closes on a grounded note: solar panels.Connect with Martin: https://www.linkedin.com/in/martinsandren/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTIMESTAMPS00:00 Welcome and EIC 2026 intro01:47 What has changed in two years: AI, sovereignty, shared signals03:06 Martin's EIC presentations: AI for IAM and IAM for AI04:46 Can you prioritize one direction over the other?07:13 What would it take to trust AI making identity decisions?09:32 AI-enhanced detection and risk-based session management13:07 Session invalidation and the shared signals framework14:11 Defense in depth and right-sizing privileges18:25 MFA today: any MFA versus phish-resistant MFA19:17 AI chatbots, enterprise LLMs, and shadow AI23:11 MCP servers, NHI risk, and return on risk thinking27:00 AI configuring IAM systems: how close are we?31:30 LLM costs, the SaaSpocalypse, and enterprise AI futures40:10 Identity dark matter and the IVIP concept44:16 CMDB versus IVIP: do you need both?46:18 The EU AI Act and building an AI governance registry49:18 Where to start: get your AI inventory in place first50:00 Closing thoughts and the solar panel tangentKEYWORDSAI for IAM, IAM for AI, identity dark matter, IVIP, IGA, shared signals framework, phish-resistant MFA, defense in depth, session management, MCP servers, NHI, shadow AI, SaaSpocalypse, EU AI Act, AI governance, zero standing privilege, EIC 2026, IKEA, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Martin Sandren

This episode is presented courtesy of SailPoint. Rob Sebaugh, Senior Identity Strategist at SailPoint, joins Jeff and Jim for a wide-ranging conversation on the past, present, and future of identity governance. Rob brings more than two decades of practitioner experience to the table, including 16 years running large-scale identity programs before making the move to the vendor side. The conversation covers what identity governance means today, why it must move to the forefront rather than be treated as an afterthought in an agentic world, and how organizations need to think fundamentally differently about non-human identities. Jeff and Jim explore the concept of treating AI as a first-class identity, how AI is beginning to replace rubber-stamp access certifications, the shift toward policy-based access control, and the practical path toward zero standing privilege. The episode wraps with a lighter conversation about Rob's 3D printing hobby.About SailPoint:SailPoint (Nasdaq: SAIL) is defining the new era of adaptive identity security. In a world where non-human identities now significantly outnumber humans, our AI-powered platform unifies identity, security, and data intelligence to protect today’s enterprise from advanced identity-based threats. We deliver the identity solution that spans both the breadth of identities and the depth of context needed to drive real-time access with confidence. Built on principles like zero-standing privilege and contextualized risk, our SailPoint platform transforms identity from a point of vulnerability into a powerful security advantage. Trusted by many of the world's leading organizations, SailPoint secures the enterprise with intelligent, autonomous identity security.Learn more about SailPoint: https://www.sailpoint.com/Connect with Rob: https://www.linkedin.com/in/rob-sebaugh-1ba9013/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps:00:00 Introduction00:48 Rob Sebaugh and the identity strategist role at SailPoint04:38 Practitioner advice from the field07:49 What SailPoint does: the hotel key analogy11:04 Buying identity technology means buying a business process13:30 What identity governance is and why it still matters16:47 Risk-appropriate governance and privileged access19:39 Non-human identities and the scale of the agentic challenge22:57 Treating AI as a first-class identity24:28 When AI makes governance decisions: beyond rubber stamping28:04 Is identity governance a binary decision?29:58 Securing data inside AI and large language models34:09 Identity: the field that reinvents itself35:01 Identity as the new control plane37:21 Is all access privileged access?40:25 Zero standing privilege in practice44:22 Innovation, continuous identity, and what SailPoint is building46:28 Identity posture management50:13 Practitioner advice for the next three to five years53:00 The future of IGA in ten years57:44 Lighter note: 3D printing with Rob Sebaugh1:05:35 Final thoughts on SailPointKeywords: Rob Sebaugh, SailPoint, identity governance, identity security, IGA, non-human identities, agentic AI, zero standing privilege, just-in-time access, identity posture management, control plane, zero trust, policy-based access control, AI certification, rubber stamping, sponsor spotlight, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Thomas Zarnhofer, IAM Architect at a major retail company in central Europe. Thomas shares his experience leading a full IGA transformation from a decade-old on-premise system to a modern cloud-based platform. The conversation covers the shift from a contract-based to a person-based identity model, the importance of cleaning data before migration begins, a three-phase framework of Foundation, Migration, and Adoption, lessons learned from running two systems in parallel, and a look at how AI could make IGA predictive. The episode ends with Thomas's tips for visiting Austria.Connect with Thomas: https://www.linkedin.com/in/tzarnhofer/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps00:00 Introduction and EIC 2026 Setting02:00 Thomas's Identity Origin Story04:21 The Catalyst for IGA Modernization07:43 Contract-Based vs Person-Based Identity Models09:22 Consolidating Master Data Sources11:39 Data Quality and Attribute Ownership13:34 Partnering with HR for Clean Data16:43 Data Analysis: Why They Chose Excel Over AI17:53 Clean Your Data Before You Migrate18:23 The Three Phases: Foundation, Migration, Adoption20:12 Driving Adoption Across the Organization21:10 Running Two Systems in Parallel22:47 Challenge Everything vs Lift and Shift27:23 Surprises in the Cloud IGA Journey29:02 Testing Requirements in the Cloud29:51 AI and the Future of IGA32:25 AI Chatbots and Role Discovery35:30 Scoping Business Role Visibility36:06 Life Outside IAM: Travel and Austria TipsKeywords:IAM, IGA, Identity Governance, IGA Migration, On-Premises to Cloud, Identity Model, Contract-Based Identity, Person-Based Identity, Master Data, Data Quality, HR Integration, Joiner Mover Leaver, Cloud IGA, Retail IAM, EIC 2026, AI in IGA, Predictive IGA, Role Management, Access Governance, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Thomas Zarnhofer

Jeff and Jim are joined by Heather Flanagan, Content Chair, and Andi Hindle, Conference Chair, for a full preview of Identiverse 2026 at Mandalay Bay in Las Vegas. They cover the 2026 theme of trust and change, why AI was removed as a standalone track and redistributed across all content areas, the provocative argument that non-human access now dramatically outpaces human access and is reshaping identity system design, whether authentication is truly solved, authorization as the harder unsolved problem, CFP surprises, networking events including Women at Identiverse, and predictions for 2027. Save 30% with code IDV26-IDAC30%. New IDPro members save $25 at idpro.org/idac.Connect with Heather: https://www.linkedin.com/in/hlflanagan/Connect with Andi: https://www.linkedin.com/in/ahindle/Identiverse 2026: https://events.identiverse.com/2026/begin?code=IDV26-IDAC30%25Heather's IAM Conference List: https://github.com/fedidcg/meetings/wiki/2026-List-of-Identity-and-Related-Conferences-and-Standards-Development-EventsConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTIMESTAMPS00:00:00 Introduction and SolarWinds breach banter00:03:27 Identiverse preview and discount codes00:06:10 Guest introductions00:06:52 Role of Content Chair00:08:46 Role of Conference Chair00:11:16 2026 conference theme00:15:00 AI as context, not a standalone track00:16:32 Control plane vs enablement plane debate00:22:19 What the industry is underestimating00:24:00 Non-human access outpaces human access00:26:52 Is authentication solved? Passkeys00:30:31 Authorization: far from solved00:36:04 Extensibility in standards and deployments00:38:22 CFP surprises: fraud and identity proofing00:41:48 Usability and UX gaps00:43:18 Agentic AI: identity or governance?00:47:55 Networking and newcomer programming00:51:45 Women at Identiverse00:52:46 AI-generated CFP submissions00:55:00 Predictions for Identiverse 202700:58:04 Theme songs for Identiverse 202601:02:58 Heather's identity conference list on GitHub01:04:47 Swag culture at identity conferences01:12:25 Wrap-upKEYWORDSIdentiverse 2026, Heather Flanagan, Andi Hindle, identity conference, NHI, non-human identity, agentic AI, passkeys, authentication, authorization, IAM, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, digital identity, continuous identity architecture, zero standing privilege, verifiable credentials, identity governance