Digital Trust · Complete deep dive

Identity & Access Management Platforms technology and investment research

IAM is the toll booth at the entrance to every enterprise digital transaction. Before any user accesses any application, their identity must be verified authentication and their permissions checked authorization . The core products:…

Universe
Digital Trust
Layer
Identity & Access
Mapped
1 stock
Editorial status
Complete deep dive

IAM is the toll booth at the entrance to every enterprise digital transaction. Before any user accesses any application, their identity must be verified authentication and their permissions checked authorization . The core products: Single Sign On SSO , Multi Factor Authentication MFA , Privileged Access Management PAM , Identity Governance IGA , and Customer Identity CIAM .

IAM switching cost at 2.80× annual spend is durable. Integration graph complexity grows with SaaS sprawl, increasing lock in over time.

Track protected identities and applications, module expansion, retention, privileged coverage and independently measured authentication outcomes.

Identity & Access Management Platforms: technology and investment research

1,013 words · Vault research updated Jul 29, 2026

Technology Overview

IAM is the toll booth at the entrance to every enterprise digital transaction. Before any user accesses any application, their identity must be verified (authentication) and their permissions checked (authorization). The core products: Single Sign-On (SSO), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), Identity Governance (IGA), and Customer Identity (CIAM).

Quantitative Bottleneck Analysis

The Per-User Economics of IAM Lock-In

The moat in IAM is NOT the software license — it is the identity integration graph. Every application, API, and directory a user authenticates against represents a connection that must be rebuilt during a migration. This creates a structural switching cost proportional to the number of integrated applications.

Worked Calculation — OKTA Identity Integration Switching Cost (5,000-Seat Enterprise):

Cost CategoryPer-App Migration CostApps per EnterpriseTotal Migration Cost
SAML/OIDC app reintegration$2,800 per app (dev + QA)85 apps (Okta average)$238,000
AD/LDAP directory sync rebuild$18,000 (one-time)2 directories$36,000
MFA policy migration (per user)$4.20 per user5,000 users$21,000
HRIS (Workday/SuccessFactors) integration$45,000 per connector1 connector$45,000
PAM vault migration (privileged accounts)$1,200 per account450 accounts$540,000
End-user retraining + helpdesk surge$38 per user (first month)5,000 users$190,000
Parallel run (3 months dual IAM)100% of IAM license cost$420K annual → $105K$105,000
Total Switching Cost$1,175,000
Annual IAM SpendSwitching CostSwitching Cost / Annual Spend
~$420K (Okta Workforce @ $7/user/mo + PAM + IGA)$1,175,0002.80×

Parameters (source confidence):

ParameterValueSourceConfidence
Avg Okta Workforce ARPU$7/user/monthOkta FY2026 Q1 earningsmeasured
Avg apps per Okta customer85Okta FY2025 10-K, Oktane 2025 presentationmeasured
SAML integration dev cost$2,800Gartner IAM TCO model 2025inferred
PAM account migration cost$1,200CyberArk customer case studiesinferred
Parallel run duration3 months (standard)Gartner IAM migration best practiceassumed

Key insight: At 2.80× annual spend, an IAM migration costs nearly 3 years of license fees. A competitor must offer >65% savings for 3 years just to break even. This is why OKTA's gross retention is >95%.

The MFA Adoption S-Curve

MFA Adoption Cohort% of Workforce (2026)Annual Spend Per UserGrowth Rate
FIDO2/Passkey (phishing-resistant)18%$22/user/yr+45% YoY
Push-based (Okta Verify, Duo)35%$10/user/yr+18% YoY
SMS/OTP (legacy)28%$4/user/yr-8% YoY
No MFA19%$0-22% YoY

The shift from SMS/OTP to phishing-resistant MFA (FIDO2, hardware tokens) is a structural upgrade cycle. FIDO2 adoption mandated for federal agencies per OMB M-22-09 by FY2025. Enterprise cyber insurance providers increasingly require phishing-resistant MFA as a condition of coverage.

Market Structure

VendorPrimary MoatIAM Revenue (est. CY2025)Key Metric
Microsoft (MSFT)Entra ID bundled with E3/E5 — default choice~$8B+ (IAM portion of Entra)600M+ monthly active users
Okta (OKTA)Best-of-breed neutral platform$2.6B19,000+ customers, $2.6B ARR
CyberArk (CYBR)PAM market leader (45% share)$1.1B8,400+ customers
SailPoint (SAIL)IGA pure play$0.7B (est.)IPO Aug 2025 at $23/share
Ping Identity (private)CIAM + workforce~$0.4B (est.)Acquired by Thoma Bravo 2022

Key dynamic: Microsoft Entra ID has ~80%+ market share by user count, but Okta/CyberArk own the high-value identity workflows — PAM, IGA, and CIAM for regulated verticals. The market is bifurcating: Microsoft owns "identity for Office 365," best-of-breed owns "identity for everything else."

Competitive Dynamics

Microsoft Entra threat: Bundled SSO/MFA in E5 ($57/user/month) makes standalone IAM hard for MS-centric shops. However, heterogeneous environments (AWS + GCP + on-prem + SaaS) require neutral platforms — Okta's core advantage.

AI identity threat: AI agents acting on behalf of humans create a new identity class — "non-human identities" (NHI). Machine identities now outnumber human identities 45:1 in the average enterprise (CyberArk 2025 survey). NHI governance is the next IAM battleground.

Passwordless acceleration: FIDO2/Passkey adoption grew 190% in 2025 (FIDO Alliance). This reduces one dimension of Okta's lock-in (password sync) but INCREASES the value of the identity orchestration layer that manages passkey lifecycles.

Validation Signals

  • Okta dollar-based net retention: 111% (Q1 FY2026) — existing customers expanding
  • CyberArk SaaS ARR grew >40% YoY driven by machine identity management
  • US federal zero-trust mandate requires phishing-resistant MFA by FY2025
  • Cyber insurance providers increasingly require IAM audits and MFA coverage

Invalidation Signals

  • Microsoft Entra achieves >90% enterprise SSO share, making Okta redundant
  • FIDO2/Passkey standardization eliminates IAM vendor lock-in
  • AI-native identity startups (e.g., Oso, Cerby) bypass traditional IAM entirely

Open Questions

  • Does NHI (non-human identity) management become a separate billion-dollar category, or does it fold into existing IAM/PAM platforms?
  • Will FIDO2 reduce switching costs enough to compress Okta's gross retention below 90%?
  • Can CyberArk expand beyond PAM into full IGA/SSO without losing PAM focus?

Research Update — 2026-07-26

_Source: SEC filings (OKTA 10-K FY2026, CYBR 10-K FY2025), Gartner IAM Magic Quadrant 2025, FIDO Alliance adoption data, OMB M-22-09, Okta Businesses at Work 2026_

Technical readiness: Mature. SSO/MFA deployed at >80% of Global 2000. Phishing-resistant MFA (FIDO2) still in early majority phase (18% penetration).

Bottleneck assessment: IAM switching cost at 2.80× annual spend is durable. Integration graph complexity grows with SaaS sprawl, increasing lock-in over time.

Alternative risk: Microsoft Entra bundling is real for MS-centric shops; FIDO2 standardization could compress switching costs long-term.

Adoption rate: MFA adoption growing at 18-22% YoY; FIDO2 at 45% YoY off small base. NHI identity is the next growth vector.

Thesis impact: IAM is the toll booth BEFORE the Zero Trust toll road — you must prove identity before any ZT policy can be applied. OKTA and CYBR own complementary moats: workforce SSO and privileged access, respectively.

Deep Research — 2026-07-29

Thesis-Relevant Finding

  • IDENTITY_ACCESS_MGMT requires verified SEC financials and competitor filing checks before conviction changes.

Financial Verification

  • Revenue, margin, and backlog figures: needs primary source validation.

Contradiction Check

  • Competitor filings should be checked for demand, pricing, and share-shift contradictions.

Sources

  • https://www.sec.gov/edgar/search/
  • https://www.sec.gov/ixviewer/

Sources

4 cited sources from the research vault and public framework used to define this capability.

  1. sec.govsec.govOpen source ↗
  2. sec.govsec.govOpen source ↗
  3. NISTNIST Digital Identity Guidelines, SP 800-63-4Open source ↗
  4. NISTNIST Zero Trust Architecture, SP 800-207Open source ↗
01

Stocks mapped to this technology

Compare the current investment signal, conviction, target and research freshness for each stock.

02

Technology questions

Direct answers about the technology, its infrastructure layer and mapped public stocks.

What is Identity & Access Management Platforms?

IAM is the toll booth at the entrance to every enterprise digital transaction. Before any user accesses any application, their identity must be verified authentication and their permissions checked authorization . The core products:…

Which universe and layer is Identity & Access Management Platforms mapped to?

Identity & Access Management Platforms is mapped to Digital Trust across Identity & Access.

Which stocks are mapped to Identity & Access Management Platforms?

PXS Research currently maps 1 public stock to Identity & Access Management Platforms, including OKTA.