Identity and Access Management (IAM)
What is identity and access management (IAM)?
How does identity and access management work?
- Identity creation and provisioning. An account is created and connected to relevant attributes, roles, groups, and resources.
- Authentication. The user or system proves control of the claimed digital identity through a password, passkey, certificate, device, biometric factor, or multi-factor authentication (MFA).
- Authorization. Policy determines which resources and actions the authenticated identity may access.
- Access changes. Permissions are updated when a person changes role, a contract ends, a device is replaced, or a workload changes function.
- Review and deprovisioning. Managers or system owners review permissions and remove unneeded accounts or privileges.
- Logging and investigation. Access records support security monitoring, audits, and investigation of misuse.
How is IAM different from identity verification?
Where is IAM used?
- Workforce IAM manages employees, contractors, administrators, and their access to internal resources.
- Customer IAM (CIAM) manages registration, login, consent, and account access for consumers or external users.
- Partner or B2B IAM controls access for suppliers, distributors, and other organizations.
- Machine identity management covers applications, workloads, services, devices, certificates, and cryptographic keys.
How can Regula help with IAM?
FAQ
Is IAM the same as authentication?
No. Authentication is one IAM function: it confirms that a user or system controls the credentials associated with a digital identity. IAM also covers account provisioning, authorization, access reviews, role changes, deprovisioning, and audit records.
What is the difference between IAM and CIAM?
IAM is the broader discipline of managing digital identities and access. Customer identity and access management (CIAM) applies IAM functions to consumers or other external users, commonly adding customer registration, consent, preference management, privacy controls, and large-scale account recovery. Workforce IAM concentrates on employees, contractors, and administrative access.
What does least privilege mean in IAM?
Least privilege means giving an identity only the access needed for its current duties and removing that access when the need ends. Roles, approval rules, time-limited permissions, and periodic reviews can support this principle. It limits the damage caused by a compromised account, an error, or deliberate misuse.
What is the difference between IAM and identity governance?
IAM covers identity lifecycle and access control as a whole. Identity governance and administration (IGA) concentrates on who should receive access, how access is approved and reviewed, and whether permissions meet policy. IGA is commonly treated as part of, or closely connected to, the wider IAM program.
How do SSO and MFA fit into IAM?
Single sign-on (SSO) lets a user authenticate through one identity provider and access multiple connected services. Multi-factor authentication (MFA) requires independent authentication factors and reduces reliance on a password alone. Both support authentication within IAM, but neither decides what the user is authorized to do or manages the full identity lifecycle.