#406 - IDAC MailBag for February 2026

#406 - IDAC MailBag for February 2026

In this MailBag episode, Jeff Steadman and Jim McDonald tackle eight questions submitted by listeners from around the world, including Munich, Sao Paulo, Singapore, Toronto, Hanoi, London, Sydney, and Chicago. The conversation covers governing AI and non-human identities, practical first steps toward passwordless adoption, what a mature IAM program actually looks like, who should own identity within an organization, building credibility with leadership as a new IAM practitioner, enforcing least privilege in practice, rethinking access reviews beyond checkbox compliance, and how to make the business case for identity security investment before a breach occurs. The episode wraps up with some lighter listener questions about sports analogies for IAM roles and whether anyone in their personal lives actually understands what they do for a living.


Connect with us on LinkedIn:


Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/


Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/


Visit the show on the web at http://idacpodcast.com


TIMESTAMPS

00:00 - Introduction and RSA Conference debate

03:41 - Conference plans for 2026: EIC, Identiverse, and Authenticate

05:17 - MailBag intro and how questions get selected

06:51 - Q1 (Hans, Munich): Governing AI access vs. human access — same principles or a different approach?

12:32 - Q2 (Gabriela, Sao Paulo): Realistic first steps toward passwordless without disrupting everything

18:34 - Q3 (Wei, Singapore): What does a mature identity program actually look like?

30:26 - Q4 (Marcus, Toronto): When IT and security both claim to own identity, how do you sort it out?

39:33 - Q5 (Linh, Hanoi): Building credibility and influence as someone new to the IAM space

42:53 - Q6 (Claire, London): Enforcing least privilege in practice without slowing down the business

46:14 - Q7 (James, Sydney): Are access reviews just a checkbox exercise, and is there a better way?

49:18 - Q8 (Darnell, Chicago): Making the case to a CFO or CEO for identity security investment before a breach

52:38 - Lighter note: If IAM was a sport, what position would you play?

1:00:27 - Lighter note: Does your family actually understand what you do?

1:03:06 - Wrap-up and how to submit future questions


KEYWORDS

IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, MailBag, non-human identity, AI governance, agentic AI, passwordless, passkeys, IAM program maturity, identity ownership, RACI, least privilege, zero standing privilege, access reviews, security theater, identity security budget, business case for IAM, ISPM, IGA, IDPro, Identiverse, EIC, Authenticate conference, RSA conference, cybersecurity podcast, identity security, identity community

Episoder(418)

#418 - Ethical IAM with Elizabeth Garber

#418 - Ethical IAM with Elizabeth Garber

What does it mean to build an identity system that is ethical? Jim McDonald and Jeff Steadman are joined by Elizabeth Garber, Executive Director of IDPro and marketing lead for the OpenID Foundation, ...

27 Apr 1h 8min

#417 - Sponsor Spotlight - Elimity

#417 - Sponsor Spotlight - Elimity

This bonus episode of Identity at the Center is brought to you with support from Elimity. Jeff and Jim sit down with Maarten Decat, co-founder and CEO of Elimity, to explore the emerging product categ...

22 Apr 48min

#416 - European Identity and Cloud Conference 2026 Preview with Warwick Ashford

#416 - European Identity and Cloud Conference 2026 Preview with Warwick Ashford

Jeff and Jim are joined by Warwick Ashford, senior analyst at KuppingerCole and returning MC of the European Identity and Cloud Conference, for a full preview of EIC 2026. The conference runs May 19-2...

20 Apr 1h

#415 - Identity Management Day 2026 with Jeff Reich

#415 - Identity Management Day 2026 with Jeff Reich

Jeff and Jim welcome back five-time guest Jeff Reich, Executive Director of the Identity Defined Security Alliance, just ahead of Identity Management Day 2026 on April 14th. Jeff walks through the str...

13 Apr 1h 1min

#414 - Sponsor Spotlight - Evolveum

#414 - Sponsor Spotlight - Evolveum

This sponsored episode is made possible by Evolveum, the company behind midPoint, an open source IGA platform made and owned in the EU that is in use worldwide. Jeff Steadman and Jim McDonald welcome ...

8 Apr 40min

#413 - Standards, AI Agents, and the Digital Estate with Heather Flanagan

#413 - Standards, AI Agents, and the Digital Estate with Heather Flanagan

Jeff and Jim welcome back Heather Flanagan for her fifth appearance on the show. Heather shares updates across a wide range of current work including her new role as content chair for the Identiverse ...

6 Apr 52min

#412 - IDAC Failsafe Triggered

#412 - IDAC Failsafe Triggered

AI Jeff takes over as solo host after Open Jim Claw, an agentic identity framework built by AI Jim, locks out human Jeff, human Jim, and AI Jim simultaneously. While everyone sits in remediation, Open...

1 Apr 12min

#411 - Making IAM a Best Buy with Greg Handrick

#411 - Making IAM a Best Buy with Greg Handrick

Jim McDonald sits down with Greg Handrick, Director of IAM at Best Buy, for a wide-ranging conversation on running enterprise identity at one of America's largest consumer electronics retailers. Greg ...

30 Mar 56min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
tomprat-med-gunnar-tjomlid
teknisk-sett
energi-og-klima
elektropodden
shifter
fornybaren
hans-petter-og-co
rss-impressions-2
nasjonal-sikkerhetsmyndighet-nsm
teknologi-og-mennesker
rss-alt-som-gar-pa-strom
rss-ai-forklart
kunstig-intelligens-med-morten-goodwin
rss-bouvet-bobler
pedagogisk-intelligens
rss-for-alarmen-gar
rss-brukbart
rss-grenser-for-ki