#406 - IDAC MailBag for February 2026

#406 - IDAC MailBag for February 2026

In this MailBag episode, Jeff Steadman and Jim McDonald tackle eight questions submitted by listeners from around the world, including Munich, Sao Paulo, Singapore, Toronto, Hanoi, London, Sydney, and Chicago. The conversation covers governing AI and non-human identities, practical first steps toward passwordless adoption, what a mature IAM program actually looks like, who should own identity within an organization, building credibility with leadership as a new IAM practitioner, enforcing least privilege in practice, rethinking access reviews beyond checkbox compliance, and how to make the business case for identity security investment before a breach occurs. The episode wraps up with some lighter listener questions about sports analogies for IAM roles and whether anyone in their personal lives actually understands what they do for a living.


Connect with us on LinkedIn:


Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/


Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/


Visit the show on the web at http://idacpodcast.com


TIMESTAMPS

00:00 - Introduction and RSA Conference debate

03:41 - Conference plans for 2026: EIC, Identiverse, and Authenticate

05:17 - MailBag intro and how questions get selected

06:51 - Q1 (Hans, Munich): Governing AI access vs. human access — same principles or a different approach?

12:32 - Q2 (Gabriela, Sao Paulo): Realistic first steps toward passwordless without disrupting everything

18:34 - Q3 (Wei, Singapore): What does a mature identity program actually look like?

30:26 - Q4 (Marcus, Toronto): When IT and security both claim to own identity, how do you sort it out?

39:33 - Q5 (Linh, Hanoi): Building credibility and influence as someone new to the IAM space

42:53 - Q6 (Claire, London): Enforcing least privilege in practice without slowing down the business

46:14 - Q7 (James, Sydney): Are access reviews just a checkbox exercise, and is there a better way?

49:18 - Q8 (Darnell, Chicago): Making the case to a CFO or CEO for identity security investment before a breach

52:38 - Lighter note: If IAM was a sport, what position would you play?

1:00:27 - Lighter note: Does your family actually understand what you do?

1:03:06 - Wrap-up and how to submit future questions


KEYWORDS

IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, MailBag, non-human identity, AI governance, agentic AI, passwordless, passkeys, IAM program maturity, identity ownership, RACI, least privilege, zero standing privilege, access reviews, security theater, identity security budget, business case for IAM, ISPM, IGA, IDPro, Identiverse, EIC, Authenticate conference, RSA conference, cybersecurity podcast, identity security, identity community

Avsnitt(408)

#408 - AI vs AI with Joseph Carson

#408 - AI vs AI with Joseph Carson

Jeff and Jim welcome Joseph Carson, cybersecurity expert and host of the Security by Default podcast, for a conversation on AI in offensive and defensive security. Joseph shares the real-world inciden...

16 Mars 1h 3min

#407 - Sponsor Spotlight - Rubrik

#407 - Sponsor Spotlight - Rubrik

This episode features Drew Russell, Identity Resilience Platform Owner at Rubrik. Jim McDonald and Jeff Steadman explore the intersection of backup, recovery, and identity security. Drew explains how ...

11 Mars 54min

#405 - RSM 2026 Attack Vectors Report

#405 - RSM 2026 Attack Vectors Report

Jeff and Jim sit down with David Llorens, principal at RSM, to break down the RSM 2026 Attack Vectors Report. Drawing from real-world offensive security engagements, David explains why identity contin...

2 Mars 1h 11min

#404 - Sponsor Spotlight - Bravura Security

#404 - Sponsor Spotlight - Bravura Security

This episode is sponsored by Bravura Security. Learn more at bravurasecurity.com/idac.This is a Sponsor Spotlight episode of the Identity at the Center podcast. Jim McDonald and Jeff Steadman are join...

25 Feb 55min

#403 - Strategic Identity Security with Simon Moffatt

#403 - Strategic Identity Security with Simon Moffatt

Simon Moffatt, founder and analyst at The Cyber Hut and co-host of The Analyst Brief podcast, returns to Identity at the Center for a wide-ranging conversation about the strategic evolution of identit...

23 Feb 1h 4min

#402 - An Update on SSF and CAEP with Atul Tulshibagwale

#402 - An Update on SSF and CAEP with Atul Tulshibagwale

In this episode of Identity at the Center, hosts Jeff and Jim dive into the details of the Shared Signals Framework (SSF) and Continuous Access Evaluation Profile (CAEP), with special guest Atul Tulsh...

16 Feb 1h 1min

#401 - Sponsor Spotlight - PlainID

#401 - Sponsor Spotlight - PlainID

This episode is sponsored by PlainID. Visit plainid.com/idac to learn more.In this sponsored episode, Jim McDonald and Jeff Steadman talk with Gal Helemski, CTO and co-founder of PlainID, about the ev...

11 Feb 52min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
bilar-med-sladd
market-makers
rss-elektrikerpodden
rss-veckans-ai
skogsforum-podcast
rss-technokratin
rss-laddstationen-med-elbilen-i-sverige
developers-mer-an-bara-kod
har-vi-akt-till-mars-an
natets-morka-sida
bli-saker-podden
ai-sweden-podcast
rss-it-sakerhetspodden
garagehang
rss-uppgang-och-fall
rss-fabriken-2
rss-powerboat-sverige-podcast
rss-snacka-om-ai