IAM is the toll booth at the entrance to every enterprise digital transaction. Before any user accesses any application, their identity must be verified authentication and their permissions checked authorization . The core products: Single Sign On SSO , Multi Factor Authentication MFA , Privileged Access Management PAM , Identity Governance IGA , and Customer Identity CIAM .
Identity & Access Management Platforms technology and investment research
IAM is the toll booth at the entrance to every enterprise digital transaction. Before any user accesses any application, their identity must be verified authentication and their permissions checked authorization . The core products:…
IAM switching cost at 2.80× annual spend is durable. Integration graph complexity grows with SaaS sprawl, increasing lock in over time.
Track protected identities and applications, module expansion, retention, privileged coverage and independently measured authentication outcomes.
Identity & Access Management Platforms: technology and investment research
1,013 words · Vault research updated Jul 29, 2026
Technology Overview
IAM is the toll booth at the entrance to every enterprise digital transaction. Before any user accesses any application, their identity must be verified (authentication) and their permissions checked (authorization). The core products: Single Sign-On (SSO), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), Identity Governance (IGA), and Customer Identity (CIAM).
Quantitative Bottleneck Analysis
The Per-User Economics of IAM Lock-In
The moat in IAM is NOT the software license — it is the identity integration graph. Every application, API, and directory a user authenticates against represents a connection that must be rebuilt during a migration. This creates a structural switching cost proportional to the number of integrated applications.
Worked Calculation — OKTA Identity Integration Switching Cost (5,000-Seat Enterprise):
| Cost Category | Per-App Migration Cost | Apps per Enterprise | Total Migration Cost |
|---|---|---|---|
| SAML/OIDC app reintegration | $2,800 per app (dev + QA) | 85 apps (Okta average) | $238,000 |
| AD/LDAP directory sync rebuild | $18,000 (one-time) | 2 directories | $36,000 |
| MFA policy migration (per user) | $4.20 per user | 5,000 users | $21,000 |
| HRIS (Workday/SuccessFactors) integration | $45,000 per connector | 1 connector | $45,000 |
| PAM vault migration (privileged accounts) | $1,200 per account | 450 accounts | $540,000 |
| End-user retraining + helpdesk surge | $38 per user (first month) | 5,000 users | $190,000 |
| Parallel run (3 months dual IAM) | 100% of IAM license cost | $420K annual → $105K | $105,000 |
| Total Switching Cost | $1,175,000 |
| Annual IAM Spend | Switching Cost | Switching Cost / Annual Spend |
|---|---|---|
| ~$420K (Okta Workforce @ $7/user/mo + PAM + IGA) | $1,175,000 | 2.80× |
Parameters (source confidence):
| Parameter | Value | Source | Confidence |
|---|---|---|---|
| Avg Okta Workforce ARPU | $7/user/month | Okta FY2026 Q1 earnings | measured |
| Avg apps per Okta customer | 85 | Okta FY2025 10-K, Oktane 2025 presentation | measured |
| SAML integration dev cost | $2,800 | Gartner IAM TCO model 2025 | inferred |
| PAM account migration cost | $1,200 | CyberArk customer case studies | inferred |
| Parallel run duration | 3 months (standard) | Gartner IAM migration best practice | assumed |
Key insight: At 2.80× annual spend, an IAM migration costs nearly 3 years of license fees. A competitor must offer >65% savings for 3 years just to break even. This is why OKTA's gross retention is >95%.
The MFA Adoption S-Curve
| MFA Adoption Cohort | % of Workforce (2026) | Annual Spend Per User | Growth Rate |
|---|---|---|---|
| FIDO2/Passkey (phishing-resistant) | 18% | $22/user/yr | +45% YoY |
| Push-based (Okta Verify, Duo) | 35% | $10/user/yr | +18% YoY |
| SMS/OTP (legacy) | 28% | $4/user/yr | -8% YoY |
| No MFA | 19% | $0 | -22% YoY |
The shift from SMS/OTP to phishing-resistant MFA (FIDO2, hardware tokens) is a structural upgrade cycle. FIDO2 adoption mandated for federal agencies per OMB M-22-09 by FY2025. Enterprise cyber insurance providers increasingly require phishing-resistant MFA as a condition of coverage.
Market Structure
| Vendor | Primary Moat | IAM Revenue (est. CY2025) | Key Metric |
|---|---|---|---|
| Microsoft (MSFT) | Entra ID bundled with E3/E5 — default choice | ~$8B+ (IAM portion of Entra) | 600M+ monthly active users |
| Okta (OKTA) | Best-of-breed neutral platform | $2.6B | 19,000+ customers, $2.6B ARR |
| CyberArk (CYBR) | PAM market leader (45% share) | $1.1B | 8,400+ customers |
| SailPoint (SAIL) | IGA pure play | $0.7B (est.) | IPO Aug 2025 at $23/share |
| Ping Identity (private) | CIAM + workforce | ~$0.4B (est.) | Acquired by Thoma Bravo 2022 |
Key dynamic: Microsoft Entra ID has ~80%+ market share by user count, but Okta/CyberArk own the high-value identity workflows — PAM, IGA, and CIAM for regulated verticals. The market is bifurcating: Microsoft owns "identity for Office 365," best-of-breed owns "identity for everything else."
Competitive Dynamics
Microsoft Entra threat: Bundled SSO/MFA in E5 ($57/user/month) makes standalone IAM hard for MS-centric shops. However, heterogeneous environments (AWS + GCP + on-prem + SaaS) require neutral platforms — Okta's core advantage.
AI identity threat: AI agents acting on behalf of humans create a new identity class — "non-human identities" (NHI). Machine identities now outnumber human identities 45:1 in the average enterprise (CyberArk 2025 survey). NHI governance is the next IAM battleground.
Passwordless acceleration: FIDO2/Passkey adoption grew 190% in 2025 (FIDO Alliance). This reduces one dimension of Okta's lock-in (password sync) but INCREASES the value of the identity orchestration layer that manages passkey lifecycles.
Validation Signals
- Okta dollar-based net retention: 111% (Q1 FY2026) — existing customers expanding
- CyberArk SaaS ARR grew >40% YoY driven by machine identity management
- US federal zero-trust mandate requires phishing-resistant MFA by FY2025
- Cyber insurance providers increasingly require IAM audits and MFA coverage
Invalidation Signals
- Microsoft Entra achieves >90% enterprise SSO share, making Okta redundant
- FIDO2/Passkey standardization eliminates IAM vendor lock-in
- AI-native identity startups (e.g., Oso, Cerby) bypass traditional IAM entirely
Open Questions
- Does NHI (non-human identity) management become a separate billion-dollar category, or does it fold into existing IAM/PAM platforms?
- Will FIDO2 reduce switching costs enough to compress Okta's gross retention below 90%?
- Can CyberArk expand beyond PAM into full IGA/SSO without losing PAM focus?
Research Update — 2026-07-26
_Source: SEC filings (OKTA 10-K FY2026, CYBR 10-K FY2025), Gartner IAM Magic Quadrant 2025, FIDO Alliance adoption data, OMB M-22-09, Okta Businesses at Work 2026_
Technical readiness: Mature. SSO/MFA deployed at >80% of Global 2000. Phishing-resistant MFA (FIDO2) still in early majority phase (18% penetration).
Bottleneck assessment: IAM switching cost at 2.80× annual spend is durable. Integration graph complexity grows with SaaS sprawl, increasing lock-in over time.
Alternative risk: Microsoft Entra bundling is real for MS-centric shops; FIDO2 standardization could compress switching costs long-term.
Adoption rate: MFA adoption growing at 18-22% YoY; FIDO2 at 45% YoY off small base. NHI identity is the next growth vector.
Thesis impact: IAM is the toll booth BEFORE the Zero Trust toll road — you must prove identity before any ZT policy can be applied. OKTA and CYBR own complementary moats: workforce SSO and privileged access, respectively.
Deep Research — 2026-07-29
Thesis-Relevant Finding
- IDENTITY_ACCESS_MGMT requires verified SEC financials and competitor filing checks before conviction changes.
Financial Verification
- Revenue, margin, and backlog figures: needs primary source validation.
Contradiction Check
- Competitor filings should be checked for demand, pricing, and share-shift contradictions.
Sources
- https://www.sec.gov/edgar/search/
- https://www.sec.gov/ixviewer/
Sources
4 cited sources from the research vault and public framework used to define this capability.
Stocks mapped to this technology
Compare the current investment signal, conviction, target and research freshness for each stock.
Technology questions
Direct answers about the technology, its infrastructure layer and mapped public stocks.
What is Identity & Access Management Platforms?
IAM is the toll booth at the entrance to every enterprise digital transaction. Before any user accesses any application, their identity must be verified authentication and their permissions checked authorization . The core products:…
Which universe and layer is Identity & Access Management Platforms mapped to?
Identity & Access Management Platforms is mapped to Digital Trust across Identity & Access.
Which stocks are mapped to Identity & Access Management Platforms?
PXS Research currently maps 1 public stock to Identity & Access Management Platforms, including OKTA.