Corvus
Landscape Market · 39d12804

Identity and Access Management (IAM) Market

The global market for software and services that manage user, device, and machine identities and control their access to digital resources across enterprises.

In scope: workforce IAM, customer IAM (CIAM), privileged access management (PAM), identity governance and administration (IGA), authentication standards (SAML, OAuth, OIDC, WebAuthn/passkeys), and non-human/machine identity including AI agents. Out of scope: physical access control, government civil-registry programs, and end-user password managers.

Completed
2026-08-05 00:15 UTC

Bottom Line Up Front

The global IAM market is a roughly USD 20-25 billion software-and-services category growing 10-15% annually, in which Microsoft Entra ID dominates the bundled installed base and Okta leads the pure-play workforce/CIAM segment (approximately 41% share of the independent IAM segment) [ev_032]. A clear consolidation cycle is underway: Thoma Bravo (Ping + ForgeRock + SailPoint), CyberArk's Venafi acquisition, and Palo Alto Networks' USD 25 billion CyberArk deal (closed 2026-02-11) are fusing identity into broader cybersecurity platforms — while agentic AI is rapidly expanding the non-human identity attack surface. A single week of late July 2026 saw roughly USD 1.4B in announced AI-agent identity M&A: Cyera-Oasis Security at USD 1B (2026-07-28) [ev_028, ev_034] and Okta-Permiso Security at ~USD 200M (2026-07-30) [ev_029, ev_033], on top of SailPoint's completed USD 200M Entro Security deal (2026-06-29) — with SailPoint shipping a unified human/machine/AI-agent Identity Security platform at Black Hat USA 2026 on 2026-08-04 [ev_031]. IBM's 2026 Cost of a Data Breach Report (2026-07-30) set a record USD 4.99M global average per breach and found 92% of AI-breached organizations lacked adequate access controls on their AI models [ev_030] — reinforcing identity as the primary security perimeter.

§ 01

What it is

Identity and access management (IAM, also IdM) is a framework of policies and technologies that ensures the right users — and increasingly the right machines and AI agents — have appropriate access to technology resources [ev_003]. IAM systems identify, authenticate, and authorize human and non-human principals against directories and policies, sitting under the joint umbrella of IT security and data management. The functional surface spans authentication (single sign-on, multi-factor, passwordless/passkeys), authorization and federation (SAML, OAuth, OpenID Connect), directory services (Active Directory, Entra ID, LDAP-based stores), identity governance and administration (joiner-mover-leaver lifecycle, access reviews, segregation-of-duties), privileged access management for high-risk administrator and service accounts, and — increasingly — machine and non-human identity management for API keys, certificates, workload tokens, and AI agents [ev_002, ev_003, ev_019]. The market sells these capabilities both as discrete products and as unified platforms that consolidate them under one control plane.

§ 02

Who operates in it

The IAM landscape splits into five archetypes of operator. (1) Hyperscale platform incumbents — Microsoft (Entra ID, the renamed Azure AD, the de-facto enterprise default since it ships with Microsoft 365 and Windows Server Active Directory) plus Google Cloud Identity, AWS IAM, and Oracle on cloud-platform footings — dominate the installed base by virtue of bundling [ev_002]. (2) Pure-play public leaders — Okta (workforce-identity benchmark, incorporating Auth0 for CIAM/developers) [ev_001] — and, until early 2026, CyberArk (privileged-access leader, Israeli-headquartered, absorbed by Palo Alto Networks on 2026-02-11) [ev_017]. (3) Private-equity-rolled-up suites — Thoma Bravo's combined Ping Identity + ForgeRock, the principal PE-backed access-management challenger [ev_013, ev_015], and SailPoint, the PE-backed governance leader that re-listed in February 2025 and closed its Entro Security acquisition in June 2026 [ev_014, ev_022, ev_023]. (4) Adjacent-security-platform extenders — Cisco (Duo, USD 2.35B acquisition in 2018 for MFA) [ev_009] and IBM (IBM Verify). (5) Cloud-native and niche specialists — JumpCloud, BeyondTrust and Delinea in PAM, Saviynt in IGA, Yubico in hardware authenticators, and a fast-growing crop of non-human-identity startups (Astrix, Oasis, Token Security, Entro before its SailPoint acquisition). Standards stewardship sits with the FIDO Alliance (passkeys/WebAuthn) [ev_025], the OpenID Foundation (OIDC), OASIS (SAML), and IETF (OAuth), with NIST setting the U.S. federal architectural anchor via SP 800-207 [ev_026]. CISA and other government CERTs increasingly act as public-sector regulators of identity hygiene through advisories such as AA23-320A on Scattered Spider [ev_012]. In late July 2026 the AI-agent / non-human identity subcategory itself became an M&A battleground: Cyera (a data-security firm) announced a USD 1 billion acquisition of Israeli NHI startup Oasis Security on 2026-07-28 [ev_028, ev_034], and Okta announced a ~USD 200 million acquisition of ITDR firm Permiso Security on 2026-07-30 [ev_029, ev_033]. SailPoint then unified Agentic Fabric (from Entro) and Human Identity Security into a single platform at Black Hat USA 2026 on 2026-08-04 [ev_031].

§ 03

How it works

Operationally, an IAM platform sits between a directory (the canonical store of identities and groups) and the resources users and machines need to reach (SaaS apps, on-prem applications, infrastructure, APIs). Authentication establishes who the principal is — increasingly through passkeys/WebAuthn or phishing-resistant MFA rather than passwords [ev_025]. Federation (SAML, OAuth 2.0, OpenID Connect) hands a signed assertion of identity to a target service so the user only signs in once. Authorization decides what they may do, increasingly evaluated continuously rather than only at login (the zero-trust pivot) [ev_026]. Lifecycle (joiner-mover-leaver) automates provisioning into and de-provisioning out of downstream apps — SCIM is the workhorse protocol — while identity governance layers add access reviews and segregation-of-duties enforcement on top. Privileged access management isolates the riskiest accounts behind session brokering, just-in-time elevation, and credential rotation. Machine-identity management — increasingly the strategic frontier — handles workload-to-workload trust via X.509 certificates, secrets vaults, SPIFFE/SPIRE for workload identity, and SaaS scanners for the sprawl of API tokens and OAuth grants across DevOps stacks; Entro Security's absorption into SailPoint is a market signal that this tier is consolidating [ev_023]. The value chain runs identity provider → federation/SSO layer → access-decision policy engine → audit/governance plane → IGA reporting/attestation; the platform consolidators (Microsoft, Okta, PANW-CyberArk, SailPoint, Ping-ForgeRock) are racing to own as many of those tiers as possible under one control plane.

§ 04

Why it exists

Five forces drive demand. (1) Cloud and SaaS migration: every SaaS app a workforce uses needs an identity plane, and IAM became the natural control point as the network perimeter dissolved. (2) Zero-trust doctrine: NIST SP 800-207 (August 2020) and U.S. Executive Order 14028 (2021) operationalized 'never trust, always verify' as the U.S. federal default and as a private-sector reference architecture — identity is the decision point [ev_026]. (3) Breach economics: the most consequential 2022-2023 incidents (Lapsus$/Okta, Storm-0558/Microsoft 365, Scattered Spider/MGM-Caesars) were all identity-system compromises rather than network breaches [ev_010, ev_018, ev_012]. (4) Regulatory pressure: GDPR, PSD2 SCA, DORA, SEC cybersecurity disclosure rules, and HIPAA enforcement turn identity hygiene into a compliance obligation rather than an optional posture. (5) The non-human and AI-agent explosion: workload identities, API tokens, certificates, and autonomous LLM agents now outnumber human identities by an order of magnitude or more in cloud-heavy organizations, generating an attack surface that legacy IAM was not designed for — and creating the fastest-growing IAM subsegment, now visibly consolidating [ev_019, ev_020, ev_023].

§ 05

When — the chronology

The modern IAM market is the product of three overlapping eras. The directory/federation era (2000-2014) was anchored by Microsoft Active Directory, OASIS-published SAML 2.0 (2005) and the IETF's OAuth 2.0 (2012) [ev_003]. The cloud-IDaaS era (2014-2021) saw Okta IPO in 2017 [ev_001], Cisco buy Duo for USD 2.35B in 2018 [ev_009], the FIDO Alliance (launched 2013) [ev_025] mature WebAuthn/passkeys, and NIST anchor zero-trust doctrine with SP 800-207 in August 2020 [ev_026]. The consolidation-and-identity-as-perimeter era (2021-present) opened with Okta's USD 6.5B Auth0 acquisition (May 2021) and crystallized in 2022 with the Lapsus$ breach of Okta's third-party support contractor [ev_010] and Thoma Bravo's take-privates of SailPoint (USD 6.9B), Ping (USD 2.8B), and later ForgeRock (USD 2.3B, merged into Ping in August 2023) [ev_013, ev_014, ev_015]. 2023 added the Storm-0558 forged-token attack against Microsoft 365 [ev_018], Microsoft's Azure-AD-to-Entra-ID rename [ev_002], and Scattered Spider's MGM/Caesars helpdesk-pivot attacks [ev_012], followed by Okta's October support-system breach [ev_011]. 2024-2026 has been the platform-fusion phase: CyberArk acquired Venafi for USD 1.54B (October 2024) [ev_016]; SailPoint re-IPO'd at USD 12.8B (February 2025) [ev_022]; Palo Alto Networks completed its USD 25B CyberArk acquisition on February 11, 2026 — the largest identity-security M&A on record [ev_017]; SailPoint completed the USD 200M Entro Security acquisition on June 29, 2026 [ev_023]; and Okta shipped OIG and OPA in mid-2026 to extend into IGA and PAM [ev_021]. Late July 2026 marks a distinct new inflection: five agentic-AI identity transactions closed or were announced in a single week (Cyera-Oasis, Okta-Permiso, plus VC rounds), and SailPoint shipped a unified human/machine/AI-agent Identity Security platform at Black Hat USA 2026 on 2026-08-04 [ev_028, ev_029, ev_031].

§ 06

Where

Global — not geographically bounded as a market, but with concentrated supply geography. The United States dominates supply: Silicon Valley/Bay Area (Okta in San Francisco, Cisco in San Jose), the Seattle area (Microsoft in Redmond), Austin (SailPoint), Denver (Ping Identity), and Santa Clara (Palo Alto Networks). Israel hosts CyberArk (Petah Tikva) and Entro Security (Tel Aviv), reflecting the country's outsized presence in identity and non-human-identity security. Demand is global and largely follows enterprise IT spending: North America is the largest region (driven by U.S. federal zero-trust mandates and SaaS-heavy private-sector IT), Western Europe is second (driven by GDPR and PSD2/strong-customer-authentication), and Asia-Pacific is the fastest-growing region (cloud-first build-outs, India and Singapore as regional hubs). Regulatory geography is bifurcated: the U.S. (NIST SP 800-207, CISA advisories) on architecture [ev_026, ev_012]; the EU (GDPR, NIS2, DORA, eIDAS 2.0/EUDI Wallet) on data-subject rights, regulated-sector resilience, and cross-border digital identity; and a growing patchwork of national digital-ID programs that increasingly shape CIAM design.

§ 07

Players

12 in the space
§ 07b

Chronology

26 events
  1. 2005-03-15 OASIS publishes SAML 2.0, the enterprise SSO federation standard that becomes the backbone of workforce IAM.
  2. 2012-10-01 IETF publishes OAuth 2.0 (RFC 6749), foundational to modern API authorization and OIDC federation.
  3. 2013-02-12 FIDO Alliance launches; sets the trajectory that leads to WebAuthn/passkeys.
  4. 2017-04-07 Okta IPOs on Nasdaq (OKTA); becomes the pure-play workforce-identity benchmark.
  5. 2018-10-01 Cisco completes acquisition of Duo Security for USD 2.35 billion (MFA).
  6. 2020-08-11 NIST publishes SP 800-207 Zero Trust Architecture — the canonical U.S. federal ZTA reference.
  7. 2022-01-20 Lapsus$/Sitel breach of Okta customer-support contractor discovered.
  8. 2022-08-16 Thoma Bravo completes SailPoint take-private at approximately USD 6.9 billion.
  9. 2022-10-17 Thoma Bravo completes Ping Identity take-private at approximately USD 2.8 billion.
  10. 2023-07-11 Microsoft discloses Storm-0558 forged-token attack against Exchange Online / Outlook.com.
  11. 2023-07-11 Microsoft announces rename of Azure Active Directory to Microsoft Entra ID.
  12. 2023-08-23 Thoma Bravo completes ForgeRock acquisition (~USD 2.3B) and combines it into Ping Identity.
  13. 2023-09-11 Scattered Spider MGM Resorts intrusion begins via IT helpdesk social-engineering.
  14. 2023-10-20 Okta discloses support-system breach; HAR files accessed via stolen credentials.
  15. 2024-10-01 CyberArk completes Venafi acquisition for approximately USD 1.54 billion — first major dedicated machine-identity consolidation.
  16. 2025-02-13 SailPoint re-IPOs on Nasdaq at USD 12.8 billion market value; raises USD 1.38B in upsized offering.
  17. 2025-07-30 Palo Alto Networks announces agreement to acquire CyberArk for approximately USD 25 billion — the largest pure-play identity-security M&A ever announced.
  18. 2026-02-11 Palo Alto Networks completes acquisition of CyberArk; CYBR delists. PANW establishes Identity Security as a third platform.
  19. 2026-06-15 SailPoint announces agreement to acquire Entro Security (~USD 200M) — first major NHI/agentic-identity roll-up by a public IAM leader.
  20. 2026-06-29 SailPoint completes acquisition of Entro Security to secure agentic identities.
  21. 2026-07-04 Okta ships Okta Identity Governance (OIG) and Okta Privileged Access (OPA) into general availability, extending platform coverage into IGA and PAM.
  22. 2026-07-07 Post-CyberArk-sale, founder Udi Mokady appointed chairman of CHEQ, signalling next-generation AI-agent identity as the frontier category.
  23. 2026-07-28 Cyera announces USD 1 billion acquisition of Oasis Security — the largest AI-agent/non-human identity security deal to date.
  24. 2026-07-30 Okta announces acquisition of Permiso Security (~USD 200M) to add identity threat detection and response (ITDR) plus AI-agent identity monitoring to its platform.
  25. 2026-07-30 IBM publishes 2026 Cost of a Data Breach Report — global average USD 4.99 million per breach (+12% YoY, record); 92% of AI-breached organizations lacked adequate access controls on their models.
  26. 2026-08-04 SailPoint launches unified Identity Security platform at Black Hat USA 2026, combining Agentic Fabric (from the Entro Security acquisition) with Human Identity Security into a single control plane for human, machine, and AI-agent identities.
§ 08

Market

The IAM software-and-services market is variably sized at roughly USD 20-25 billion in 2024-2025 across third-party analyst estimates, with consensus CAGR in the low-to-mid teens through 2030. Concentration is high at the top: Microsoft Entra ID has by far the largest installed base and forms the de-facto enterprise default. Among pure-play vendors, Okta leads workforce IAM and CIAM, SailPoint leads IGA (and now NHI via Entro), and PANW-CyberArk anchors PAM plus machine identity. The two structural dynamics are (a) consolidation — Thoma Bravo's absorption of Ping, ForgeRock, and SailPoint between 2022 and 2024, CyberArk's 2024 Venafi acquisition, and Palo Alto Networks' USD 25 billion CyberArk purchase (closed 2026-02-11) [ev_013, ev_014, ev_015, ev_016, ev_017] — and (b) disruption from non-human identity and AI agents, where the incumbents have now moved to acquire rather than cede the category, notably SailPoint completing the Entro Security deal on 2026-06-29 [ev_019, ev_020, ev_023].

Size
Approximately USD 20-25 billion globally in 2024-2025 across third-party analyst sources; consensus 10-15% CAGR through 2030 (analyst source definitions of scope vary; corroborated estimates only).
Segments
Workforce IAM / Access Management (SSO, MFA, federation for employees) · Customer IAM (CIAM) — externally-facing for B2C and B2B logins · Identity Governance and Administration (IGA) · Privileged Access Management (PAM) · Machine / Non-Human Identity (workload identity, secrets, certificates, AI agents)
§ 09

Outlook

Moderate confidence

Over the next 24-36 months the IAM market is very likely to continue consolidating around a small set of platform suites (Microsoft, Okta, Palo Alto Networks-CyberArk, SailPoint, Ping-ForgeRock), while the non-human and AI-agent identity subsegment is very likely to be the fastest-growing category and to see continued roll-ups. The late-July 2026 wave — Cyera-Oasis at USD 1B, Okta-Permiso at ~USD 200M, SailPoint's unified Identity Security platform launch at Black Hat USA 2026 on 2026-08-04, and the previously-completed SailPoint-Entro deal — collectively priced the AI-agent identity control plane above USD 1 billion in a single week [ev_028, ev_029, ev_031, ev_034]. Standalone workforce-IAM Leaders emerging outside the incumbent set is unlikely absent a discontinuity. Increased category-overlap between Okta on the one hand and SailPoint plus CyberArk on the other (via Okta Identity Governance, Okta Privileged Access, and now Okta-Permiso ITDR) has roughly even chance of triggering meaningful pricing pressure on IGA and PAM through 2027, and unlikely to displace either incumbent in its home category on that timeline. Regulation (NIS2, DORA, SEC cyber disclosure, eIDAS 2.0/EUDI Wallet) sustains compliance-driven baseline demand across the cycle, and IBM's 2026 Cost of a Data Breach finding that 92% of AI-breached organizations lacked adequate model-access controls very likely reinforces buyer pull for AI-agent identity capabilities specifically [ev_030].

§ 10

Key Judgments

graded per ICD 203
KJ-01 High Confidence

Identity is now treated by both attackers and defenders as the primary security perimeter: the largest enterprise breaches of 2022-2023 (Lapsus$/Okta, Storm-0558/Microsoft 365, Scattered Spider/MGM-Caesars) were all identity-system compromises rather than network or endpoint compromises.

KJ-02 High Confidence

The IAM market is very likely consolidating into a small number of platform suites: Microsoft (Entra), Okta (with Auth0), Thoma Bravo's Ping+ForgeRock combination, SailPoint (governance, with Entro NHI capability as of 2026-06-29), and CyberArk-inside-Palo-Alto-Networks (privileged and machine identity, deal closed 2026-02-11). New standalone workforce-IAM Leaders are unlikely to emerge in the next 24 months absent a discontinuity.

KJ-03 Moderate Confidence

Non-human identity (machine identities, API tokens, secrets, AI agents) is very likely to be the fastest-growing IAM subsegment over the next 24-36 months. SailPoint's completed acquisition of Entro Security (2026-06-29) is the first structurally significant roll-up of the category by a public IAM leader and signals that the incumbents will contest the space rather than cede it to standalone NHI startups.

KJ-04 Moderate Confidence

Okta is roughly even chance to succeed at extending upward into Identity Governance (Okta Identity Governance) and Privileged Access (Okta Privileged Access) territory traditionally owned by SailPoint and CyberArk, but the direct product overlap increases pricing pressure and near-term competitive intensity in access management and PAM regardless of Okta's platform outcome.

KJ-05 High Confidence

AI-agent / non-human identity is very likely the definitive next M&A battleground in IAM: within a single week of late July 2026 the category cleared roughly USD 1.4 billion in announced transactions (Cyera-Oasis at USD 1B and Okta-Permiso at ~USD 200M plus additional VC rounds), and SailPoint completed the acquisition-to-integration cycle for Entro Security in eight weeks (announced 2026-06-29, unified platform shipped 2026-08-04 at Black Hat USA 2026).