Identity and Access Management (IAM), Explained in Plain English
Every company has the same problem: the right people need the right access, at the right time, for the right reasons — and nobody else should have it. IAM is the discipline of making that happen.
The 4 pieces of IAM
- Identity — who (or what) is asking? Every employee, contractor, and service account gets a digital identity.
- Authentication (authN) — proving you are who you claim to be. Passwords, MFA, biometrics, smart cards.
- Authorization (authZ) — what are you allowed to do once inside? This is roles, permissions, and policies.
- Lifecycle — access isn't forever. Joiner-mover-leaver: provision on day one, adjust on role change, remove on exit. Orphaned accounts are how breaches happen.
Why it matters: most breaches aren't fancy zero-days — they're stolen credentials and over-privileged accounts. IAM is the unglamorous work that stops the boring attacks, which are the common ones.
Where the tools fit: Okta and Entra ID handle authentication and SSO. SailPoint governs who has access to what. CyberArk locks down privileged accounts. None of them works alone — that's why IAM is a program, not a product.
The strongest IAM programs connect identity, authentication, authorization, and lifecycle controls instead of treating each one as a separate tool.