Skip to content
Team Acalvio
|
September 13, 2026

Identity Security Part 2: The Identity Security Ecosystem

In any enterprise, there is an existing ecosystem for identities and their management. Starting with the identity repositories, authentication, and access policies, and covering the trust relationship definitions at macro and micro levels. Organizations have multiple solutions in place for managing this ecosystem.

At a glance

  • Identity Governance and Administration (IGA) governs how you provision accounts, assign entitlements, and certify access.
  • Identity and Access Management (IAM) governs authentication and authorization, including privileged access and single sign-on.
  • Identity repositories store the identity data that IGA and IAM both rely on.
  • None of these three components has threat detection as its primary function.
  • Identity Threat Detection and Response (ITDR) is the layer built to add it.

What are the Components of an Identity Security Ecosystem?

The three major components of an identity security ecosystem are:

  • IGA – Identity Governance and Administration
  • IAM – Identity and Access Management
  • Identity Repositories – such as Active Directory and Azure AD

What is IGA (Identity Governance and Administration)?

Identity Governance and Administration (IGA) is the identity security component that manages the identity lifecycle, and it matters most for large organizations. Enterprises implement IGA to control access and mitigate risk by automating user account creation and the management of user accounts, roles, and entitlements.

Companies use IGA to streamline onboarding, offboarding, employee movement, policy management, access governance, and other identity security measures. IGA can be envisioned as a lifecycle management system for identity. It is used to manage access to resources across on-premises assets, SaaS, and cloud-based applications.

The use of automation and centralized policy management strengthens security and reduces identity risk. For example, the various roles can be defined and managed in IGA, and a password policy can also be defined and managed through IGA. Another important function of IGA is auditing governance and compliance reporting. For example, access requests to resources are handled by IGA to ensure governance and auditing.

What is IAM (Identity and Access Management)?

Identity and Access Management or IAM is the management of access to systems and resources. Its earliest days are best represented by Microsoft’s Active Directory or AD service. AD was one of the earliest tools to keep track of access to PCs, and applications, and eventually, it expanded into managing access to mail systems and other IT resources.

There has been a heavy push for IAM services to be delivered from the cloud. One of the limitations of AD was that it was only available within local or enterprise networks. That changed as IT resources moved out of the internal enterprise domains into the Internet and cloud services became the norm. To take advantage of this shift, new types of cloud-based IAM services were developed and became popular.

What does IAM include and what are the limitations?

IAM includes many capabilities, such as password authentication and a more secure form of authentication known as Multi-Factor Authentication (MFA). Authorization, also known as Access Control, is also a part of IAM.

Controlling what a user does inside an application sits outside what traditional IAM was built to govern. It is one thing to get access to the applications, but controlling what a user can do once they get access to the application is a challenge. Getting access to the database is governed by IGA and enforced by IAM, but what the user can do once inside it is not. But controlling what the user can do once they log in to the database, is outside the scope of traditional IAM offerings

Where does PAM (Privileged Access Management) fit in?

PAM is a specific type of access control meant for privileged users. Since attackers are interested in compromising privileged accounts like administrator accounts, a special type of identity offering was required. The goal is to secure access for privileged accounts by password vaulting, besides session recording for compliance reasons.

What about Single Sign-On?

Single sign-on (SSO) means users do not have to authenticate each time they want to access a resource, and it is part of IAM along with federation. IAM components ensure that identity is verified by authentication, access to resources is controlled, and consistent with the policies using RBAC (Role-Based Access Control).

MFA provides additional verification for an identity trying to access a resource.

What are identity stores?

Identity stores, or identity repositories, are the data stores that hold identities and related information such as groups and policies, and they are another component of the identity security ecosystem. Active Directory AD, Azure AD, JumpCloud, LDAP, and AWS Directory Services are all examples of an identity store.

How do IGA and IAM work together?

Identity Governance and Administration (IGA) and Identity and Access Management (IAM) work in concert to control access to resources, prevent data breaches, and comply with regulations. IGA can be thought of as a higher form of IAM because it provides more granular access to applications.

Once a user is in an application, IGA controls what the user can do within the application. As an example, a simple user role can only access basic functionality, but an administrator role can manage the application itself. What a user can do based on their role is called entitlements.

In highly regulated industries such as healthcare and financial services, it becomes even more important to track what users have been given access to within applications that might have personally identifiable information (PII). Governments mandate that firms protect this information and companies must keep records of which users have access to PII. Even more important is removing accesses for users who leave the firm. To manage and report these access details, firms use identity governance and administration capabilities.

Where deception fits in a Zero Trust model

Zero Trust architecture governs whether access is granted in the first place, verifying identity and context before every request, while deception addresses what happens after an attacker has already obtained valid credentials and passed that verification. Zero Trust reduces the odds that a stolen credential clears verification, but it cannot judge intent once that credential is active inside the environment, which is the post-authentication judgment gap deception is built to close. A decoy identity has no legitimate use, so engagement with it is a high-confidence signal regardless of whether the credential presenting it passed authentication. Deception is additive to IAM, PAM, and MFA, running alongside these controls rather than replacing them, and it extends Zero Trust security by adding a layer that judges behavior after access, not just credentials before it.

What are the identity threat detection capabilities of these components?

There is no component whose primary function is to detect threats against identities; threat detection sits outside what IGA, IAM, and identity repositories were built to govern. Gartner identified this gap and introduced the term ITDR, or Identity Threat Detection and Response, as the layer that adds it. Attack surface management is another capability that sits outside the scope of the current identity security ecosystem. While threat detection and response capabilities are useful and required, it is always better to prevent or reduce the attack surface. For a deeper look, see [[Comprehensive Identity Protection through ITDR]].

There are many ways to implement ITDR, including deception technology. Advanced solutions such as Acalvio ShadowPlex offer both ITDR and attack surface reduction capabilities for enhanced identity security.

See where post-authentication identity activity goes unjudged: get a 360 Deception Attack Path Assessment or schedule a ShadowPlex demo.

Frequently asked questions

IAM and IGA govern different layers of identity security. IAM handles authentication and authorization: verifying who a user is and controlling their access to systems and resources, including privileged access and single sign-on. IGA operates at a higher level, managing the identity lifecycle itself: provisioning accounts, defining roles and entitlements, and providing the auditing and compliance reporting that access governance requires across on-premises, SaaS, and cloud applications.

Neither IAM nor PAM has threat detection as its primary function. IAM verifies identity and enforces access policy, and PAM secures privileged accounts through password vaulting and session recording. Detecting threats against identities sits outside what either was built to govern, which is the gap that Identity Threat Detection and Response (ITDR) and deception technology are designed to close.

Zero Trust governs whether access is granted, and deception addresses what happens after access is granted with valid credentials. A decoy identity has no legitimate use, so engagement with it is a high-confidence signal regardless of whether the credential passed authentication. Deception is additive to IAM, PAM, and MFA, adding a post-authentication layer to a Zero Trust architecture rather than replacing any of its existing controls.

Content
Acalvio, the Ultimate Preemptive Cybersecurity Solution.