#406 - IDAC MailBag for February 2026

#406 - IDAC MailBag for February 2026

In this MailBag episode, Jeff Steadman and Jim McDonald tackle eight questions submitted by listeners from around the world, including Munich, Sao Paulo, Singapore, Toronto, Hanoi, London, Sydney, and Chicago. The conversation covers governing AI and non-human identities, practical first steps toward passwordless adoption, what a mature IAM program actually looks like, who should own identity within an organization, building credibility with leadership as a new IAM practitioner, enforcing least privilege in practice, rethinking access reviews beyond checkbox compliance, and how to make the business case for identity security investment before a breach occurs. The episode wraps up with some lighter listener questions about sports analogies for IAM roles and whether anyone in their personal lives actually understands what they do for a living.


Connect with us on LinkedIn:


Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/


Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/


Visit the show on the web at http://idacpodcast.com


TIMESTAMPS

00:00 - Introduction and RSA Conference debate

03:41 - Conference plans for 2026: EIC, Identiverse, and Authenticate

05:17 - MailBag intro and how questions get selected

06:51 - Q1 (Hans, Munich): Governing AI access vs. human access — same principles or a different approach?

12:32 - Q2 (Gabriela, Sao Paulo): Realistic first steps toward passwordless without disrupting everything

18:34 - Q3 (Wei, Singapore): What does a mature identity program actually look like?

30:26 - Q4 (Marcus, Toronto): When IT and security both claim to own identity, how do you sort it out?

39:33 - Q5 (Linh, Hanoi): Building credibility and influence as someone new to the IAM space

42:53 - Q6 (Claire, London): Enforcing least privilege in practice without slowing down the business

46:14 - Q7 (James, Sydney): Are access reviews just a checkbox exercise, and is there a better way?

49:18 - Q8 (Darnell, Chicago): Making the case to a CFO or CEO for identity security investment before a breach

52:38 - Lighter note: If IAM was a sport, what position would you play?

1:00:27 - Lighter note: Does your family actually understand what you do?

1:03:06 - Wrap-up and how to submit future questions


KEYWORDS

IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, MailBag, non-human identity, AI governance, agentic AI, passwordless, passkeys, IAM program maturity, identity ownership, RACI, least privilege, zero standing privilege, access reviews, security theater, identity security budget, business case for IAM, ISPM, IGA, IDPro, Identiverse, EIC, Authenticate conference, RSA conference, cybersecurity podcast, identity security, identity community

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(447)

#447 - Authenticate 2026 Preview with Andi Hindle

#447 - Authenticate 2026 Preview with Andi Hindle

Jeff Steadman sits down with Andi Hindle, conference chair for Authenticate 2026, for a preview of this year's event. Making his seventh appearance on the show, Andi walks through how Authenticate has...

14 Sep 1h 16min

#446 - Rethinking Identity for AI Agents with Rick Scot

#446 - Rethinking Identity for AI Agents with Rick Scot

Rick Scot, Global CIO and CISO at Elevate Textiles, joins Jim and Jeff to talk about how he went from leading a data team to holding both the CIO and CISO seats at a global manufacturing company. Rick...

7 Sep 1h 10min

#445 - Sponsor Spotlight - Twine Security

#445 - Sponsor Spotlight - Twine Security

Jim McDonald hosts this Sponsor Spotlight episode of Identity at the Center, made possible with support from Twine Security. Jim is joined by Benny Porat, co-founder and CEO of Twine Security and prev...

2 Sep 52min

#444 - August 2026 Mailbag

#444 - August 2026 Mailbag

Jeff and Jim open with the unavoidable topic of AI agents and the tension between enabling innovation and governing agent permissions, then run through a packed fall conference schedule. The August ma...

31 Aug 49min

#443 - Ghosts in the Machine with John Huyette and Omer Arshed

#443 - Ghosts in the Machine with John Huyette and Omer Arshed

Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growi...

24 Aug 1h 13min

#442 - Identiverse 2026 - Identity After Dark with Bravura Security

#442 - Identiverse 2026 - Identity After Dark with Bravura Security

Recorded live at Identiverse 2026 in Las Vegas on June 17, Jeff and Jim are joined by Bart Allan, General Manager at Bravura Security, for a live recording with a studio audience. In a late-night talk...

19 Aug 1h 29min

#441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer

#441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer

Live from Identiverse 2026 in Las Vegas, Jeff and Jim sit down with Sachini Siriwardene, winner of this year's Kim Cameron Award, along with Ian Glazer of the Digital Identity Advancement Foundation (...

17 Aug 37min

#440 - Identiverse 2026 - Mike Kiser

#440 - Identiverse 2026 - Mike Kiser

Recorded live at Identiverse 2026, Jeff and Jim sit down with returning guest Mike Kiser, Director of Strategy and Standards at SailPoint, for a wide-ranging conversation that spans two of the standar...

10 Aug 52min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
market-makers
rss-laddstationen-med-elbilen-i-sverige
rss-elektrikerpodden
rss-en-ai-till-kaffet
gubbar-som-tjotar-om-bilar
rss-veckans-ai
rss-technokratin
natets-morka-sida
bilar-med-sladd
skogsforum-podcast
bli-saker-podden
developers-mer-an-bara-kod
hej-bruksbil
rss-uppgang-och-fall
rss-sakerhetspodcasten
rss-digitala-influencer-podden
rss-it-sakerhetspodden
rss-nytankarna