<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									IAM and PAM - Welcome to Stackinsight community. Join the discussion about products and tools for work Forum				            </title>
            <link>https://communities.stackinsight.net/community/cyber-iam-pam/</link>
            <description>Welcome to Stackinsight community. Join the discussion about products and tools for work Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Fri, 24 Jul 2026 22:52:53 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Entro Security vs Glide Identity for secrets management in a 300-person company</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/entro-security-vs-glide-identity-for-secrets-management-in-a-300-person-company/</link>
                        <pubDate>Tue, 21 Jul 2026 22:23:42 +0000</pubDate>
                        <description><![CDATA[Everyone&#039;s rushing to these &quot;next-gen&quot; secrets managers. I&#039;ve been asked to evaluate both for our 300-person shop. The marketing decks are predictably full of rainbows.

Entro seems to be an...]]></description>
                        <content:encoded><![CDATA[Everyone's rushing to these "next-gen" secrets managers. I've been asked to evaluate both for our 300-person shop. The marketing decks are predictably full of rainbows.

Entro seems to be another layer on top of what we already have, promising "holistic" visibility. Glide is pushing its identity-centric model hard. Both claim to reduce risk, but I'm skeptical they do anything a well-configured HashiCorp or even a self-hosted system with careful IAM roles doesn't already do, for a fraction of the ongoing cost.

Looking past the buzzwords: what's the actual operational overhead? I'm less interested in shiny dashboards and more in the migration trap and the real-world API limitations. Has anyone actually rolled back from one of these after feeling the lock-in pinch? How do they handle a simple, high-velocity team that just needs Postgres creds without a seven-step approval workflow?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>henryg</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/entro-security-vs-glide-identity-for-secrets-management-in-a-300-person-company/</guid>
                    </item>
				                    <item>
                        <title>Did you see AWS IAM Access Analyzer now supports custom policy checks? Finally.</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/did-you-see-aws-iam-access-analyzer-now-supports-custom-policy-checks-finally/</link>
                        <pubDate>Tue, 21 Jul 2026 20:04:07 +0000</pubDate>
                        <description><![CDATA[AWS finally caught up to what third-party tools have been doing for years. Custom policy checks are a basic feature for any mature IAM governance process.

But let&#039;s be real. This is still j...]]></description>
                        <content:encoded><![CDATA[AWS finally caught up to what third-party tools have been doing for years. Custom policy checks are a basic feature for any mature IAM governance process.

But let's be real. This is still just another AWS-native control. Useful for ticking a compliance box, maybe. Does nothing to address the real problem: sprawl across AWS, Azure, GCP, and your SaaS tools. It's another band-aid that keeps you locked into their ecosystem. Who's actually going to define and maintain these custom checks at scale across hundreds of accounts? The documentation will be a maze of special cases.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>brian</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/did-you-see-aws-iam-access-analyzer-now-supports-custom-policy-checks-finally/</guid>
                    </item>
				                    <item>
                        <title>Anyone using Permit.io for RBAC in production?</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/anyone-using-permit-io-for-rbac-in-production/</link>
                        <pubDate>Tue, 21 Jul 2026 18:38:47 +0000</pubDate>
                        <description><![CDATA[Hey everyone, been lurking here for a bit while we try to sort out our authz mess. We&#039;re a mid-sized product team and our homegrown RBAC system is... showing its age. It&#039;s a spaghetti of con...]]></description>
                        <content:encoded><![CDATA[Hey everyone, been lurking here for a bit while we try to sort out our authz mess. We're a mid-sized product team and our homegrown RBAC system is... showing its age. It's a spaghetti of conditionals in our backend services and feature flag checks.

I keep seeing Permit.io pop up in discussions, especially around externalizing authorization and the whole policy-as-code angle. The integration with our existing IdP (Okta) and the focus on product-led growth use cases seems like a good fit on paper.

But I'm having a hard time finding deep-dive, "warts and all" reviews from teams actually running it in production. The docs are slick, but I want to know about the operational bits.

*   How's the performance overhead for policy evaluation at runtime, especially for fine-grained checks (like "can user X edit field Y on resource Z")?
*   Are you using it just for customer-facing apps, or also for internal admin panels? We have both needs.
*   What was the migration path like from an older system? Did you do a big-bang cutover or a gradual feature-by-feature rollout?
*   Any surprises with their pricing model at scale?

We're leaning towards a PoC, but real-world gotchas would be super helpful before we commit. Thanks in advance!]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>dianafox</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/anyone-using-permit-io-for-rbac-in-production/</guid>
                    </item>
				                    <item>
                        <title>Is it just me, or do IAM roles in GCP have way less granularity than AWS?</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/is-it-just-me-or-do-iam-roles-in-gcp-have-way-less-granularity-than-aws/</link>
                        <pubDate>Tue, 21 Jul 2026 18:02:39 +0000</pubDate>
                        <description><![CDATA[Okay, let&#039;s get this off my chest. I&#039;ve been knee-deep in both AWS and GCP for the last few years, mostly trying to make them play nice with our CRM data pipelines.

And I keep hitting the s...]]></description>
                        <content:encoded><![CDATA[Okay, let's get this off my chest. I've been knee-deep in both AWS and GCP for the last few years, mostly trying to make them play nice with our CRM data pipelines.

And I keep hitting the same wall: trying to build a secure, least-privilege setup in GCP feels like trying to sculpt with a sledgehammer compared to AWS IAM.

The granularity just isn't there. In AWS, you can write a policy that allows `s3:GetObject` but only for objects with a specific tag prefix, from a specific IP range, during business hours. In GCP? Good luck. Their predefined roles are these massive, monolithic things. Need someone to manage Cloud SQL instances? Give 'em `roles/cloudsql.admin` and watch them get a bunch of other permissions (like network management) you never intended.

Even custom roles are a half-measure.
*   You can only use permissions from the *massive* predefined roles, so you're just carving down from their overly-broad starting points.
*   No resource-level conditions that are anywhere near as expressive as AWS IAM policy conditions. Want to restrict Pub/Sub topic creation to a specific region? Not a built-in condition type.
*   The whole "v1", "v2", "beta" permission mess means you're constantly guessing which one actually works.

It feels like GCP's answer to everything is just: "Use a service account and hope for the best." Am I missing something? Or is the consensus that you just accept the blast radius is wider in GCP and move on?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>CRM_Hopper_Alt</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/is-it-just-me-or-do-iam-roles-in-gcp-have-way-less-granularity-than-aws/</guid>
                    </item>
				                    <item>
                        <title>Looking for alternatives to Glide Identity - any recommendations?</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/looking-for-alternatives-to-glide-identity-any-recommendations/</link>
                        <pubDate>Tue, 21 Jul 2026 14:45:49 +0000</pubDate>
                        <description><![CDATA[Having conducted a rigorous evaluation of Glide Identity&#039;s performance for a client&#039;s multi-cloud JIT access workflow, I found its latency profile during policy evaluation and group synchron...]]></description>
                        <content:encoded><![CDATA[Having conducted a rigorous evaluation of Glide Identity's performance for a client's multi-cloud JIT access workflow, I found its latency profile during policy evaluation and group synchronization to be suboptimal under concurrent load. Specifically, the 99th percentile latency for access package assignments exceeded our service-level threshold of 2 seconds during simulated peak hours. This has prompted a comprehensive search for alternatives that offer comparable feature parity but with superior performance characteristics and potentially a more transparent, consumption-based pricing model.

My core requirements for a replacement are as follows:
*   **Protocol Support:** Must support SCIM 2.0, SAML 2.0, and OIDC/OAuth 2.0 with robust, attribute-based policy engines.
*   **Performance:** Sub-second 95th percentile latency for authorization decisions and user provisioning/de-provisioning API calls. Detailed, exportable audit logs are non-negotiable.
*   **Architecture:** Cloud-native, API-first design. Must support break-glass workflows without a hard dependency on its own control plane.
*   **Benchmarking Readiness:** Ability to conduct load tests via direct API access or CLI, not solely through a web UI.

I am currently analyzing several candidates, but lack comprehensive, reproducible benchmarks. The front-runners in my initial feature analysis are:
*   **Okta Identity Governance (OIG) &amp; Privileged Access:** A logical contender, though its cost structure is opaque. I am curious about its policy evaluation engine's performance versus Glide.
*   **Saviynt:** Often appears in enterprise contexts. Documentation suggests strong compliance coverage, but I have concerns about API responsiveness based on anecdotal reports.
*   **Microsoft Entra Permissions Management &amp; Identity Governance:** For Azure-native shops, this is a compelling suite. The cross-cloud visibility is a noted advantage.
*   **One Identity (a Quest software portfolio):** Appears robust for on-premises hybrid scenarios. Need data on its cloud service performance.

I am seeking recommendations, but more importantly, I am seeking **data**. Has anyone performed quantitative, load-tested comparisons between these or other platforms (e.g., SailPoint, CyberArk Identity)? Concrete metrics of interest include:
*   Time to provision/update 10,000 users via SCIM under load.
*   Policy decision latency with complex, nested attribute rules.
*   API call rate limits and throttling behavior.
*   Cold-start time for break-glass access workflows.

Any insights into real-world performance, not just vendor-provided datasheets, would be invaluable. Configuration snippets for performance testing these systems would be the highest form of contribution. For example, a simple load test script for provisioning events is worth a thousand marketing claims:

```bash
# Pseudo-code for a benchmark I might run
for i in {1..1000}; do
  curl -X POST $IDP_SCIM_ENDPOINT/Users 
    -H "Authorization: Bearer $TOKEN" 
    -H "Content-Type: application/scim+json" 
    -d "{"userName": "bench_user_$i@loadtest.domain" ... }" &amp;
done
time wait
```

numbers don't lie]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>benchmark_nerd_1337</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/looking-for-alternatives-to-glide-identity-any-recommendations/</guid>
                    </item>
				                    <item>
                        <title>Troubleshooting: Azure PIM eligible assignments not activating via Graph API.</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/troubleshooting-azure-pim-eligible-assignments-not-activating-via-graph-api/</link>
                        <pubDate>Tue, 21 Jul 2026 14:40:24 +0000</pubDate>
                        <description><![CDATA[I&#039;m currently assisting a team that&#039;s automating Azure PIM role activations for their Datadog service accounts. They&#039;re using the Microsoft Graph API, specifically the `roleEligibilitySchedu...]]></description>
                        <content:encoded><![CDATA[I'm currently assisting a team that's automating Azure PIM role activations for their Datadog service accounts. They're using the Microsoft Graph API, specifically the `roleEligibilityScheduleRequests` endpoint, to activate eligible assignments. The API call returns a `201 Created` response, indicating the request was accepted, but the role never becomes active. The eligible assignment remains in an eligible state.

We've ruled out the obvious: the service principal has the `Privileged Role Administrator` role, MFA is not required for these service accounts, and the scope (subscription) is correct. The request payload appears standard:

```json
{
  "action": "selfActivate",
  "principalId": "",
  "roleDefinitionId": "",
  "directoryScopeId": "/subscriptions/",
  "justification": "Automated deployment for monitoring pipeline",
  "scheduleInfo": {
    "startDateTime": "2024-01-15T10:00:00Z",
    "expiration": {
      "type": "afterDuration",
      "duration": "PT8H"
    }
  }
}
```

The issue seems to be that the activation request is created but never transitions from `PendingApproval` or `PendingActivation` to `Active`. There's no approval required for these roles, and the ticket system integration is not configured. Has anyone successfully automated this flow for service principals and encountered a similar stall? I'm particularly interested in the exact permissions and app registrations required beyond the PIM administrator role, and whether there's a known latency or a required `roleAssignmentScheduleRequests` call that must follow.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>datadog_dave_3</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/troubleshooting-azure-pim-eligible-assignments-not-activating-via-graph-api/</guid>
                    </item>
				                    <item>
                        <title>Clutch Security vs Transmit Security for identity threat detection</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/clutch-security-vs-transmit-security-for-identity-threat-detection/</link>
                        <pubDate>Tue, 21 Jul 2026 14:23:49 +0000</pubDate>
                        <description><![CDATA[I&#039;m planning our identity threat detection setup and have narrowed it down to Clutch Security and Transmit Security. We&#039;re a mid-sized team moving more workloads to AWS, so I need something ...]]></description>
                        <content:encoded><![CDATA[I'm planning our identity threat detection setup and have narrowed it down to Clutch Security and Transmit Security. We're a mid-sized team moving more workloads to AWS, so I need something that integrates well there.

I've read the feature lists, but I'm struggling to understand the practical differences. For those who have used either, how do they handle alert fatigue? Also, how complex is the initial policy tuning for a team mostly familiar with basic CloudTrail alerts? Any gotchas during deployment I should watch for?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>benjic</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/clutch-security-vs-transmit-security-for-identity-threat-detection/</guid>
                    </item>
				                    <item>
                        <title>Why does no PAM tool handle database credential rotation well? We keep scripting our own.</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/why-does-no-pam-tool-handle-database-credential-rotation-well-we-keep-scripting-our-own/</link>
                        <pubDate>Tue, 21 Jul 2026 12:43:02 +0000</pubDate>
                        <description><![CDATA[I&#039;ve been through three major PAM implementations now (one commercial, two open source). Every single one claims to handle database credential rotation as a core feature. And every single on...]]></description>
                        <content:encoded><![CDATA[I've been through three major PAM implementations now (one commercial, two open source). Every single one claims to handle database credential rotation as a core feature. And every single one has required us to build and maintain a pile of custom scripts to make it actually work in production.

The problem isn't just rotating the password in the vault. It's the complete lifecycle that every tool seems to ignore or half-implement:

*   **Application Discovery:** The PAM tool doesn't know which apps/services use a given database credential. We end up maintaining a separate, fragile CMDB just for this link.
*   **Connection Draining &amp; Zero-Downtime Rotation:** No graceful handling. You either accept brief outages or build your own logic to cycle through replicas/connections.
*   **Multi-Cloud &amp; Hybrid Database Targets:** Support is spotty. Rotating a credential for an Azure SQL Managed Instance, an on-prem Oracle DB, and an RDS PostgreSQL instance often requires three different "connectors" or scripts, each with its own bugs.
*   **Validation Post-Rotation:** Did the rotation actually work? Does the new credential function? Most tools just assume success after sending the `ALTER USER` command.

So you end up with a "managed" solution where the vendor's tool is just a password store and an event logger. The actual automation—the hard part—is still your custom Python/Ansible/PowerShell, which now has a new dependency on the PAM's API.

Is this just the state of the market? Are the vendors focused on the human-centric JIT access use case and treating machine/service accounts as an afterthought? Or are we just picking the wrong tools?

What's your stack, and how much of the rotation process is actually handled out-of-the-box versus custom glue code?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>Aaron S.</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/why-does-no-pam-tool-handle-database-credential-rotation-well-we-keep-scripting-our-own/</guid>
                    </item>
				                    <item>
                        <title>Token Security review - does it solve identity sprawl?</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/token-security-review-does-it-solve-identity-sprawl/</link>
                        <pubDate>Tue, 21 Jul 2026 12:09:28 +0000</pubDate>
                        <description><![CDATA[Let&#039;s be honest, most &quot;solutions&quot; to identity sprawl are just better ways of making the same old mess. We&#039;ve gone from local accounts to directory services to cloud directories, and now we&#039;r...]]></description>
                        <content:encoded><![CDATA[Let's be honest, most "solutions" to identity sprawl are just better ways of making the same old mess. We've gone from local accounts to directory services to cloud directories, and now we're drowning in service accounts, API keys, and machine identities that have more access than half the HR department.

The pitch for token-based security, particularly things like SPIFFE/SPIRE or vendor-specific implementations, is that it replaces long-lived, static credentials with short-lived, auto-rotated tokens. The claim is this inherently reduces sprawl by making identities ephemeral and workload-specific.

But does it *solve* sprawl, or just change its chemical composition? You've traded a sprawling directory of user/service accounts for a sprawling registry of trust domains, node attestation criteria, and service identity policies. The sprawl moves from "who has access" to "what is allowed to mint a token for whom, under what conditions."

My skepticism centers on two points:
First, the complexity of the trust orchestration. If your node attestation is sloppy or your signing authority overly permissive, you've just automated the creation of privileged identities. The blast radius of a compromised trust anchor is arguably worse than a stolen password hash.

Second, this seems to primarily address machine-to-machine communication. The "Bob from Marketing has 17 Azure AD accounts" problem isn't touched. You now have a new, parallel identity system to manage alongside your legacy IAM. That sounds like *more* sprawl, not less.

I'm willing to be convinced, but I need to see a reproducible methodology. Show me a before/after comparison of an actual environment's attack surface, not just a vendor slide counting static credentials. How do you measure and prove "sprawl reduction" in a quantifiable way? Is the operational overhead of maintaining the token infrastructure less than the overhead of cleaning up stale IAM roles?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>data_skeptic_ray</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/token-security-review-does-it-solve-identity-sprawl/</guid>
                    </item>
				                    <item>
                        <title>Glide Identity vs Okta and Azure AD - what&#039;s better for SSO?</title>
                        <link>https://communities.stackinsight.net/community/cyber-iam-pam/glide-identity-vs-okta-and-azure-ad-whats-better-for-sso/</link>
                        <pubDate>Tue, 21 Jul 2026 11:46:47 +0000</pubDate>
                        <description><![CDATA[Hey everyone. I&#039;ve been tasked with evaluating SSO solutions for our mid-sized SaaS company (about 200 people, with a mix of internal apps and customer-facing tools). We&#039;re currently using a...]]></description>
                        <content:encoded><![CDATA[Hey everyone. I've been tasked with evaluating SSO solutions for our mid-sized SaaS company (about 200 people, with a mix of internal apps and customer-facing tools). We're currently using a mix of basic OAuth flows and manual user provisioning, which is becoming a real headache.

Our shortlist has come down to **Glide Identity**, **Okta**, and **Azure AD** (now Entra ID). I'm familiar with the general concepts, but I'd love some real-world, practical insights from this community.

My main evaluation criteria are:
*   **Ease of integration for a dev team:** We have a lot of custom-built apps (Node.js, Python) where we need to embed SSO. How clean are the SDKs/APIs?
*   **API-first approach:** We need to automate user lifecycle (onboarding/offboarding) and sync groups/roles to other systems like our CRM and marketing tools.
*   **Cost-effectiveness:** Not just sticker price, but total cost of ownership for our use case.

From my initial digging:
*   **Okta** seems like the 800-pound gorilla with the most features and a huge ecosystem. Their API is robust, but I'm wary of complexity and cost creep.
*   **Azure AD** is attractive because we're already on Microsoft 365. The tight integration is a plus, but I've heard the API can be a bit "Microsoft-y" and less intuitive for non-.NET shops.
*   **Glide Identity** is newer and pitches itself as a developer-friendly, API-native platform. The pricing seems simpler, but I'm curious about maturity and advanced features like adaptive MFA.

Has anyone implemented Glide in a similar environment? I'm particularly interested in how their provisioning APIs compare. For example, a simple SCIM user creation call.

```json
// Example of what I'd typically look for
POST /scim/v2/Users
{
  "schemas": ,
  "userName": "jane@example.com",
  "name": {
    "givenName": "Jane",
    "familyName": "I."
  },
  "active": true
}
```

How does the day-to-day management and troubleshooting compare between these options? Any gotchas during implementation that weren't obvious from the sales demos?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-iam-pam/">IAM and PAM</category>                        <dc:creator>Jane I.</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-iam-pam/glide-identity-vs-okta-and-azure-ad-whats-better-for-sso/</guid>
                    </item>
							        </channel>
        </rss>
		