{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"iam","name":"Identity & access management","short":"IAM"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"workforce-idp","name":"Workforce identity providers","scope":"Comparable workforce identity-provider editions for employee, contractor, and partner sign-in. Exclude customer identity, identity-governance certification suites, and privileged-access vaults. Score only the licensed workforce IdP modules named in each assessment; adjacent SKUs are constraints, not extra points."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented operating safeguards for running a workforce identity provider: recovery, emergency access, policy simulation, session-revocation limits, health monitoring, and license gates. Does not score uptime, efficacy, staffing, or vendor size.","question":"How completely do public docs describe production operating safeguards for this workforce identity provider?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.","1: A concrete basic operating safeguard is documented for the evaluated edition.","2: Docs describe authenticator enrollment or recovery plus at least one emergency-access or admin-MFA safeguard.","3: Docs add policy testing or fail-closed options plus audit of authentication or admin events.","4: Docs describe hybrid/sync or session-revocation limits together with explicit license packaging for those safeguards.","5: Docs describe a closed operating loop: recovery bootstrap, residual-session limits, health/monitoring, and license gates for the evaluated edition."],"refinements":[{"base":3,"criteria":[{"id":"session-hybrid-limits","label":"Documented hybrid/sync or session-revocation limits","weight":6},{"id":"safeguard-packaging","label":"Explicit license packaging for those operating safeguards","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","description":"Ordinal evidence of shipped workflows against a contemporary shared cohort baseline. Stage 3 means supported baseline workflows, not novelty or superiority. Higher stages require concrete generally available differences supported by comparative primary evidence. Workforce SSO, MFA including phishing-resistant authentication, lifecycle provisioning, device or sign-in context, conditional access, and documented session/recovery workflows are contemporary baseline capabilities. Session revocation, passkeys and risk-adaptive access alone do not establish differentiation.","question":"Which current baseline workflows are supported, and is any concrete shipped difference from that shared baseline established?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a shipped workflow within the scoped cohort. Missing evidence is unknown, never zero.","1: One basic in-scope workflow is confirmed shipped; no broader stage is established.","2: Several baseline components are confirmed shipped, but an integrated contemporary baseline workflow is not established.","3: An integrated contemporary baseline workflow is supported by primary evidence; this stage makes no differentiation or novelty claim.","4: Stage 3 plus one concrete generally available operator workflow difference beyond the shared contemporary baseline, supported by comparative primary evidence.","5: Stage 4 plus multiple complementary generally available workflow differences beyond that baseline, with their boundaries and prerequisites established."]},{"id":"breadth","name":"Capability breadth","description":"How much of the workforce identity plane is documented in the evaluated edition: protocols, directory, provisioning, adaptive policy, hybrid or device overlays. Excludes IGA certification campaigns and PAM vaults.","question":"How much of the workforce identity plane is documented in the evaluated edition?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an in-scope assessment capability. Missing evidence is unknown, never zero.","1: A bounded in-scope capability is documented for one environment or workflow.","2: SSO plus MFA plus a workforce directory.","3: Adds SCIM or HR provisioning and per-app or conditional policy.","4: Adds hybrid protocols (LDAP, RADIUS, on-prem adapters or gateways) or partner/guest federation in the evaluated edition.","5: Documented workforce plane includes lifecycle, hybrid or on-prem, and device or session controls inside the evaluated edition (still not IGA or PAM)."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Published connector catalogs, provisioning, management APIs, hybrid directory or adapters, and telemetry export. Does not score market share or partner counts as quality.","question":"How documented is the connector, API, and partner surface for this workforce IdP?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an integration or supported data handoff. Missing evidence is unknown, never zero.","1: A concrete native connector or supported manual integration is documented.","2: A published SaaS SSO catalog.","3: Catalog plus SCIM or equivalent provisioning and a public management API.","4: Adds hybrid directory sync or federation, or on-prem application adapters.","5: Broad catalog plus device/MDM or SIEM/health export and published integration kits."]},{"id":"governance","name":"Governance & control","description":"Administrative RBAC and access-policy controls for the workforce IdP itself. Identity-governance certifications and PAM vaults are out of cohort unless they are in the evaluated workforce edition.","question":"How documented are administrative RBAC and access-policy controls for the workforce IdP itself?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an administrative or policy control. Missing evidence is unknown, never zero.","1: A specific administrative control is documented for the scoped workflow.","2: Named admin roles plus MFA for administrators.","3: Per-app or group policy plus least-privilege admin roles.","4: Custom admin roles or privileged-role eligibility in the evaluated edition.","5: Stage 4 plus documented policy-change approval or versioning, scoped delegated administration and exportable evidence of administrative decisions in the evaluated workforce IdP edition; separate IGA campaigns are outside scope."]},{"id":"operations","name":"Operator enablement","description":"Operator toolkit for configuring, testing, and troubleshooting: admin how-tos, audit logs, APIs, simulation, health dashboards, and recovery runbooks. Does not score staffing savings or untested efficacy.","question":"How documented is the operator toolkit for configuring, testing, and troubleshooting this workforce IdP?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a supported operator action or guidance path. Missing evidence is unknown, never zero.","1: A concrete operator action and its basic use are documented.","2: Audit or sign-in logs documented.","3: Public APIs plus troubleshooting or report-only simulation.","4: Health dashboards or log export plus documented recovery or revocation runbooks.","5: Full documented operator loop: API, simulation, health/export, and recovery playbooks with residual-session caveats."]}],"assessments":[{"vendor":"microsoft-entra-id","cohort":"workforce-idp","edition":"Microsoft Entra ID P1 workforce authentication and Conditional Access; P2 ID Protection, Privileged Identity Management, and Entra ID Governance are named extras","asOf":"2026-09-21","status":"research-preview","summary":"P1 documents Conditional Access, TAP recovery, emergency-access exclusions, hybrid Connect, and Graph logs; risk policies, PIM, and governance campaigns need higher SKUs and are not scored as present.","dimensions":{"maturity":{"score":5,"confidence":"medium","rationale":"Current primary documentation supports the complete anchor 5 operating loop for P1: Temporary Access Pass bootstraps recovery, its expiration does not retroactively end established sessions, Conditional Access session controls bound residual access, and Connect Health supplies monitoring under an explicit P1 license requirement. Emergency-access guidance preserves recovery access. P2 risk-based policy and Governance extras remain excluded. This is a documentation-stage correction, not measured reliability.","sourceIds":["entra-tap","entra-emergency","entra-ca","entra-connect","entra-idprotection"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support phishing-resistant authentication, recovery bootstrap and Conditional Access policy workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["entra-auth","entra-tap","entra-ca"]},"breadth":{"score":5,"confidence":"medium","rationale":"P1 includes app provisioning and group provisioning, while public procedures document identity creation, updates and deprovisioning. Together with the established SSO/MFA, Conditional Access session controls and hybrid synchronization, this completes stage 5. Lifecycle here means provisioning lifecycle; the separately licensed Lifecycle Workflows, access reviews, PIM and Governance products are not counted.","sourceIds":["entra-auth","entra-ca","entra-connect","entra-provisioning","entra-licensing"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"The application gallery and provisioning procedures now substantiate the earlier cumulative SaaS-catalog and SCIM stages. Microsoft Graph and Connect hybrid synchronization complete stage 4, with provisioning entitlements confirmed in the feature table. Stage 5 is not inferred from a catalog count or adjacent Intune/MDM products; a complete in-edition integration-kit boundary remains unverified.","sourceIds":["entra-gallery","entra-provisioning","entra-licensing","entra-graph","entra-connect"]},"governance":{"score":4,"confidence":"medium","rationale":"Conditional Access supports user/group/application targeting and named least-privilege roles. Microsoft Entra custom role definitions and object-scoped assignments are documented, with P1 required for each user assigned a custom role. This meets stage 4 without P2 PIM or separate Governance features. Policy-change approval/versioning required for stage 5 is not established within this edition.","sourceIds":["entra-ca","entra-tap","entra-custom-roles","entra-licensing"]},"operations":{"score":5,"confidence":"medium","rationale":"Graph activity-log access, Conditional Access report-only evaluation, Connect Health monitoring under P1, and TAP/emergency-access recovery procedures together establish the stage-5 operator loop. TAP guidance explicitly warns that expiry does not retroactively terminate established sessions and directs operators to session controls. The rubric requires these documented procedures, not a single bundled handbook; the previous stage-4 ceiling imposed that extra requirement. This is documentation coverage, not measured reliability.","sourceIds":["entra-graph","entra-report-only","entra-ca","entra-connect","entra-tap","entra-emergency"]}},"constraints":["Evaluated edition is Entra ID P1 workforce authentication and Conditional Access; Microsoft 365 E3/Business Premium include P1, E5 includes P2.","Risk-based Conditional Access and full ID Protection reports require Entra ID P2.","PIM, entitlement management, access reviews, and lifecycle workflows require Entra ID P2 and/or Entra ID Governance or Entra Suite; they are not scored as workforce-IdP capabilities.","Hardware OATH tokens and agent identities in Conditional Access are preview and are not treated as GA.","TAP does not retroactively invalidate established sessions; NPS extension and AD FS adapter cannot use TAP.","Connect Health requires P1; Azure AD Connect V1 is retired. Cloud Sync was not separately assessed.","Intune device compliance, Defender for Cloud Apps session control, and Azure Monitor log export are adjacent products.","Customer identity (Entra External ID) is out of cohort.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","The ecosystem gap concerns the evidence assembled for this rubric, not an assertion that Entra lacks a gallery or provisioning."],"sources":[{"id":"entra-auth","title":"Microsoft Entra authentication overview","url":"https://learn.microsoft.com/en-us/entra/identity/authentication/overview-authentication","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-tap","title":"Configure a Temporary Access Pass in Microsoft Entra ID","url":"https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-ca","title":"Microsoft Entra Conditional Access overview","url":"https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-emergency","title":"Manage emergency access admin accounts","url":"https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-connect","title":"What is Microsoft Entra Connect and Connect Health","url":"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/whatis-azure-ad-connect","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-idprotection","title":"What is Microsoft Entra ID Protection","url":"https://learn.microsoft.com/en-us/entra/id-protection/overview-identity-protection","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-graph","title":"Access activity logs in Microsoft Entra ID","url":"https://learn.microsoft.com/en-us/entra/identity/monitoring-health/howto-access-activity-logs","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-governance-license","title":"Microsoft Entra ID Governance licensing fundamentals","url":"https://learn.microsoft.com/en-us/entra/id-governance/licensing-fundamentals","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-gallery","title":"Microsoft Entra application gallery","url":"https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/overview-application-gallery","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-provisioning","title":"Microsoft Entra automated application provisioning","url":"https://learn.microsoft.com/en-us/entra/identity/app-provisioning/user-provisioning","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-licensing","title":"Microsoft Entra feature licensing","url":"https://learn.microsoft.com/en-us/entra/fundamentals/licensing","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-custom-roles","title":"Microsoft Entra built-in and custom roles","url":"https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/custom-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-report-only","title":"Conditional Access report-only evaluation","url":"https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-report-only","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Microsoft Entra ID","company":"Microsoft","profileUrl":"/landscape/vendors/microsoft-entra-id/"},{"vendor":"okta-workforce-identity","cohort":"workforce-idp","edition":"Okta Workforce Identity Cloud, Identity Engine, with Adaptive MFA; Lifecycle Management, Access Gateway, Identity Governance, and Identity Threat Protection are named extras","asOf":"2026-09-21","status":"research-preview","summary":"Identity Engine documents FastPass, app sign-in policies, custom admin roles, and Universal Logout; automatic logout and SCIM lifecycle depend on extra SKUs and are constrained, not assumed.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: Universal Logout and device-suspend session termination are documented operating safeguards, with explicit packaging (manual, rate-limited Universal Logout when only Adaptive MFA is enabled; Identity Threat Protection for policy-driven logout). Device lifecycle states (active, suspended, deactivated) and app sign-in policies are GA operator controls. Hybrid Access Gateway health was not verified in this edition.","sourceIds":["okta-ul","okta-device","okta-fastpass","okta-policy"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support device-aware authentication and scoped session-termination workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["okta-fastpass","okta-ul","okta-device"]},"breadth":{"score":2,"confidence":"medium","rationale":"The selected SSO/Adaptive MFA edition documents SSO, MFA and Universal Directory, satisfying stage 2. Stage 3 additionally requires SCIM or HR provisioning; the assessment explicitly treats Lifecycle Management as a separate excluded module, so the prior stage-3 award borrowed an out-of-scope prerequisite. Per-app policy alone does not complete that cumulative anchor. This corrects the research scope and does not indicate a product regression.","sourceIds":["okta-policy","okta-fastpass","okta-scim"]},"ecosystem":{"score":null,"confidence":"low","rationale":"The cited integration material spans SCIM and Lifecycle Management capabilities outside the explicitly scoped Adaptive MFA/SSO edition. It does not establish all cumulative integration requirements within this edition; the ecosystem score remains unknown until licensing and in-scope connectors are verified.","sourceIds":["okta-scim","okta-superadmin"]},"governance":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: standard roles (super, org, app, help desk, report, and others) plus custom admin roles (maximum 100) with resource sets are documented for Identity Engine. Access Certifications Administrator is an IGA role and is not treated as workforce-IdP governance. Super admin remains required to manage other admins.","sourceIds":["okta-custom-admin","okta-standard-admin","okta-policy"]},"operations":{"score":4,"confidence":"medium","rationale":"Existing operator procedures cover authentication, device lifecycle and manual Universal Logout within Adaptive MFA. Identity Engine log streaming exports System Log events to EventBridge or Splunk Cloud with explicit delivery/deactivation limits, completing stage 4 alongside the documented revocation runbook. Policy-driven logout remains an Identity Threat Protection extra. A full in-edition simulation/recovery loop for stage 5 is unverified.","sourceIds":["okta-ul","okta-device","okta-fastpass","okta-log-streams"]}},"constraints":["Evaluated edition is Workforce Identity Cloud Identity Engine with Adaptive MFA, not Auth0 customer identity.","Okta Lifecycle Management is required for SCIM provisioning features cited in help; it is not assumed in the breadth score.","Identity Threat Protection with Okta AI is required for automatic Universal Logout from entity-risk policy and for several System Log session-protection events.","In Adaptive MFA-only orgs, Universal Logout is manual, Admin Console-triggered, and rate-limited.","Access Gateway, Okta Privileged Access, and Identity Governance are distinct SKUs and are not scored.","FastPass requires current Okta Verify enrollment; FastPass cannot sign in to the computer itself.","Universal logout still depends on each application honoring logout; residual app sessions are unverified here.","Classic Engine versus Identity Engine differences can change policy semantics; this assessment uses Identity Engine docs.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"okta-fastpass","title":"Okta FastPass","url":"https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/fp/fp-main.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-ul","title":"Configure Universal Logout","url":"https://help.okta.com/en-us/content/topics/apps/universal-logout-amfa.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-device","title":"Device lifecycle","url":"https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/devices-lifecycle.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-policy","title":"App sign-in policies","url":"https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/about-app-sign-on-policies.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-scim","title":"SCIM app integrations","url":"https://help.okta.com/en-us/Content/Topics/Apps/apps-about-scim.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-custom-admin","title":"Custom admin roles","url":"https://help.okta.com/en-us/Content/Topics/security/custom-admin-role/custom-admin-roles.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-standard-admin","title":"Standard administrator roles and permissions","url":"https://help.okta.com/oie/en-us/content/topics/security/administrators-admin-comparison.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-superadmin","title":"Super administrators","url":"https://help.okta.com/en-us/Content/Topics/Security/administrators-super-admin.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-syslog","title":"View System Log events for Identity Threat Protection","url":"https://help.okta.com/oie/en-us/content/topics/itp/system-log-events.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-log-streams","title":"Okta Identity Engine log streaming and delivery limits","url":"https://help.okta.com/oie/en-us/content/topics/reports/log-streaming/about-log-streams.htm","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Okta Workforce Identity","company":"Okta","profileUrl":"/landscape/vendors/okta-workforce-identity/"},{"vendor":"ping-identity","cohort":"workforce-idp","edition":"PingFederate 13.x federation server with PingOne MFA for Workforce; DaVinci, PingOne Protect, and PingOne Verify are named extras","asOf":"2026-09-21","status":"research-preview","summary":"PingFederate documents a branched authentication policy engine and hybrid adapters; PingOne MFA for Workforce is a separate license, and DaVinci orchestration is not assumed in the scored edition.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Anchor 3 remains supported by fail-closed authentication policies and logged MFA integration outcomes. The 13.1 Session Revocation API documents client authentication and token-validation limits, adding 0.6 under the shared refinement rubric. The license packaging of those safeguards has not been established, so the remaining 0.4 is uncredited.","sourceIds":["ping-policies","ping-mfa-kit","ping-session-revocation"],"refinement":{"base":3,"evidence":[{"criterion":"session-hybrid-limits","rationale":"The 13.1 endpoint supports client-secret or client-certificate authentication, excludes Private Key JWT, and requires explicit token-validation revocation checks. Status queries can extend a session unless updateActivityTime is false.","sourceIds":["ping-session-revocation"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support federation policies, passkeys and passwordless authentication workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["ping-mfa-kit","ping-passwordless","ping-policies"]},"breadth":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: PingFederate browser SSO covers SAML, OIDC, and adapter-based legacy paths; bundled adapters include Kerberos, X.509, HTML form, Identifier First, and PingOne MFA. PingOne documents a workforce RADIUS gateway. Full joiner-mover-leaver IGA and device management are outside this federation-plus-MFA edition.","sourceIds":["ping-adapters","ping-saml","ping-mfa-integrations"]},"ecosystem":{"score":null,"confidence":"low","rationale":"The cited integration material includes a DaVinci kit and tenant outside the evaluated federation/MFA scope. The evidence does not establish the cumulative ecosystem stage within this edition, so it remains unknown rather than borrowing an adjacent SKU.","sourceIds":["ping-adapters","ping-mfa-kit","ping-davinci"]},"governance":{"score":3,"confidence":"low","rationale":"Maps to anchor 3 with low confidence: PingOne documents Environment Admin and PingFederate-related roles for admin SSO into PingFederate, and PingFederate policies can branch by group membership rules. A custom-admin-role or PIM-style eligibility model for the federation server was not verified, so anchor 4 is not awarded.","sourceIds":["ping-admin-sso","ping-policies"]},"operations":{"score":3,"confidence":"medium","rationale":"Maps to anchor 3: administrators get a detailed policy editor (copy/paste paths, fragments, tracked HTTP parameters) and adapter configuration references. Self-hosted operations, log export, and a cloud health dashboard for PingFederate nodes were not documented in the pages reviewed, so anchor 4 is not awarded.","sourceIds":["ping-policies","ping-adapters","ping-mfa-kit"]}},"constraints":["Evaluated edition is PingFederate plus PingOne MFA for Workforce, not PingOne for Customers and not a ForgeRock-branded SKU.","PingOne MFA Integration Kit 4.x requires PingFederate 11.3 or later; passwordless kit guidance requires PingFederate 13.x and kit 4.1+ plus Java 17 for kit 4.1.","PingOne MFA for Customer or Workforce license is required; workforce versus customer MFA integration paths differ, including legacy PingID notes and Singapore-geography limits.","DaVinci, PingOne Protect, PingOne Verify, and Advanced Identity Cloud connectors are separate modules and are not in the innovation score.","PingFederate is self-hosted; operating-system, clustering, and certificate-renewal operations were not assessed.","Government-cloud authorization packages were not checked.","IdP versus application logout and residual token lifetime must be tested per relying party; universal revocation is unverified.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"ping-policies","title":"Defining authentication policies (PingFederate 13.1)","url":"https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/pf_defining_auth_policies.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-adapters","title":"Bundled adapters (PingFederate 13.1)","url":"https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/pf_bundled_adapt.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-mfa-kit","title":"PingOne MFA Integration Kit 4.x","url":"https://docs.pingidentity.com/integrations/pingone/pingone_mfa_integration_kit/pf_p1_mfa_ik_4.0.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-passwordless","title":"Configuring a PingFederate policy for passwordless authentication","url":"https://docs.pingidentity.com/integrations/pingone/pingone_mfa_integration_kit/pid_configuring_pf_policy_for_passwordless_authentication.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-saml","title":"Configuring a SAML application (workforce use cases)","url":"https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_config_saml_app.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-mfa-integrations","title":"Strong authentication (MFA) integrations","url":"https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_strong_authentication_integrations.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-admin-sso","title":"Setting up SSO to PingFederate","url":"https://docs.pingidentity.com/pingone/getting_started_with_pingone/p1_setup_sso_pf.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-davinci","title":"PingOne DaVinci Integration Kit","url":"https://docs.pingidentity.com/integrations/pingone/pingone_davinci_integration_kit/pf_p1_davinci_ik.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-session-revocation","title":"Session Revocation API endpoint (PingFederate 13.1)","url":"https://docs.pingidentity.com/pingfederate/13.1/developers_reference_guide/pf_session_revocation_api_endpoint.html","accessedAt":"2026-09-21","kind":"documentation"}],"name":"PingFederate / PingOne","company":"Ping Identity","profileUrl":"/landscape/vendors/ping-identity/"},{"vendor":"jumpcloud","cohort":"workforce-idp","edition":"JumpCloud Open Directory with SSO and MFA; Directory Insights, device management, and some SSO packages are named extras","asOf":"2026-09-21","status":"research-preview","summary":"Open Directory documents SSO, SCIM, LDAP, RADIUS, conditional access, and admin RBAC in one cloud directory; Directory Insights and device modules are package-gated, and no FastPass-class session-revocation workflow was evidenced.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"Maps to anchor 3: Conditional Access and Default Access Policies are documented for User Portal, SSO, and LDAP, Directory Insights records auth and admin events, and MFA is required for Admin Portal sign-in. Directory Insights is package-gated with 90-day retention, and no TAP-class recovery or Universal Logout-class revocation runbook was found, so anchor 4 is not awarded.","sourceIds":["jc-cap","jc-di","jc-admin-mfa"]},"innovation":{"score":null,"confidence":"low","rationale":"Public documentation describes both conventional MFA and JumpCloud Go device-bound passwordless authentication. Go requires a supported managed device, agent, browser extension and hardware-backed authenticator. This research has not established the complete entitlement boundary for those prerequisites in the selected SSO/MFA edition. The innovation stage remains unknown pending that scope check; this is not evidence that passwordless workflows are absent.","sourceIds":["jumpcloud-go"]},"breadth":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: Open Directory documents SAML and OIDC SSO, JIT on SAML, SCIM create/update/deprovision, cloud LDAP, RADIUS, and conditional policy. Device management and MDM enrollment SSO exist in the family but are in-scope only when that module is licensed; they are not required for this score. IGA certifications and PAM vaults are out of cohort.","sourceIds":["jc-sso","jc-scim","jc-ldap","jc-cap"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Maps to anchor 3: a published SSO catalog with prebuilt and custom SAML/OIDC connectors, SCIM connectors (and custom SCIM), plus REST and PowerShell for Directory Insights. LDAP/RADIUS are counted in breadth rather than as a third-party adapter kit. SIEM/S3 export beyond the optional AWS serverless Directory Insights app was not independently verified, so anchor 4/5 are not awarded.","sourceIds":["jc-sso","jc-scim","jc-di"]},"governance":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: named Admin Portal roles (Administrator with Billing through Help Desk and Read Only) plus custom admin roles (documentation states a maximum of 20) with permission categories for access and application management. Admin Portal Conditional Access cannot be password-only. Access-package certification campaigns are not documented in this workforce directory edition.","sourceIds":["jc-roles","jc-custom-roles","jc-cap"]},"operations":{"score":3,"confidence":"medium","rationale":"Maps to anchor 3: Admin Portal how-tos cover SSO/SCIM setup, Conditional Access troubleshooting with Directory Insights policy-evaluation logs, and API/PowerShell queries. Directory Insights enablement may require an account manager, retention is 90 days, and no report-only policy mode equivalent was evidenced, so anchor 4 is not awarded.","sourceIds":["jc-di","jc-cap-ts","jc-sso"]}},"constraints":["Evaluated edition is JumpCloud Open Directory with SSO and MFA, not customer identity and not a full IGA or PAM suite.","Directory Insights is included only in some package plans and may need account-manager enablement; retention is 90 days unless exported.","SSO Package or higher (or SSO add-on) is cited as a prerequisite on some SCIM/SSO integrations (example: SuccessFactors).","Device management, Remote Assist, Password Manager, and AI Gateway are separate modules and are not scored as IdP capabilities.","Conditional Access Chrome Device Trust Connector depends on Google Admin Chrome connectors and supported browsers.","LDAP/RADIUS FQDNs are region-specific; plaintext LDAP is not allowed.","Not all catalog apps support create, update, and deprovision SCIM actions.","Offline or cached device login after user suspend was not verified from public docs.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Confirm the JumpCloud Go and device-management entitlements and enrollment prerequisites for the selected SSO/MFA package; documented availability does not establish inclusion in this narrower edition."],"sources":[{"id":"jc-di","title":"Get Started: Directory Insights","url":"https://jumpcloud.com/support/directory-insights","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-cap","title":"Set a Default Access Policy","url":"https://jumpcloud.com/support/set-a-global-policy","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-sso","title":"Get Started: SSO Applications","url":"https://jumpcloud.com/support/get-started-applications","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-scim","title":"Get Started: SCIM Connectors","url":"https://jumpcloud.com/support/get-started-identity-management-connectors","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-mfa","title":"Configure TOTP MFA for Your Org","url":"https://support.jumpcloud.com/support/s/article/set-up-multi-factor-authentication-for-your-org----jumpcloud-admins-2019-08-21-10-36-47","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-admin-mfa","title":"Enable MFA for the Admin Portal","url":"https://support.jumpcloud.com/support/s/article/how-to-enable-multi-factor-authentication-for-the-jumpcloud-admin1-2019-08-21-10-36-47","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-roles","title":"Admin Portal Roles","url":"https://jumpcloud.com/support/admin-portal-roles","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-custom-roles","title":"Custom Admin Roles","url":"https://jumpcloud.com/support/custom-admin-roles","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-ldap","title":"Get Started: Cloud LDAP","url":"https://jumpcloud.com/support/use-cloud-ldap","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-cap-ts","title":"Troubleshoot JumpCloud Conditional Access Policy Issues (Chrome DTC)","url":"https://jumpcloud.com/support/troubleshooting-jumpcloud-conditional-access-policy-issues-chrome-dtc","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jumpcloud-go","title":"Get Started: JumpCloud Go","url":"https://jumpcloud.com/support/get-started-jumpcloud-go","accessedAt":"2026-09-21","kind":"documentation"}],"name":"JumpCloud Open Directory","company":"JumpCloud","profileUrl":"/landscape/vendors/jumpcloud/"}],"scenarios":[{"id":"lean-team","name":"Small IT team consolidating directory and SSO","description":"A small workforce wants one administrative plane for identities, SaaS SSO, and optional device or LDAP/RADIUS leftovers, without buying a separate IGA or PAM product in the first phase.","priorities":["operations","breadth","ecosystem"],"questions":["Which SSO, SCIM, Directory Insights, and device modules are actually on the quote versus directory-only?","Which lab applications honor logout after the IdP session is cleared?","Can LDAP or RADIUS in the lab replace the bind and network-login paths you still run?"]},{"id":"hybrid-federation","name":"Hybrid and partner federation estate","description":"A regulated workforce still federates partner identity providers and on-premises apps while moving selected SaaS apps to a cloud IdP.","priorities":["ecosystem","maturity","governance"],"questions":["Which policies and adapters live on the federation server versus the cloud MFA or orchestration tenant?","If on-premises directory disablement happens on Friday, which system is authoritative and how is cloud access revoked?","Are emergency-access accounts excluded from blocking policies and independent of federation?"]},{"id":"recovery-revocation","name":"Authenticator recovery and leaver revocation","description":"Operators must bootstrap a replacement phishing-resistant authenticator after identity verification, then disable a contractor and record residual application sessions.","priorities":["maturity","operations","governance"],"questions":["What licensed recovery method exists, and is it identity proofing or only a bootstrap pass?","Does IdP logout end the application session, or only the next authentication?","Which admin role can issue recovery credentials without standing Global/Super Admin?"]}],"researchNotes":["First edition dated 2026-09-21; no historical assessments are available.","The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.","Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.","Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.","Contemporary cohort baseline: Workforce SSO, MFA including phishing-resistant authentication, lifecycle provisioning, device or sign-in context, conditional access, and documented session/recovery workflows are contemporary baseline capabilities. Session revocation, passkeys and risk-adaptive access alone do not establish differentiation.","Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.","Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.","Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.","Final editorial check added the current JumpCloud Go setup procedure. Because its managed-device entitlement scope was not resolved for this edition, innovation remains unknown rather than assigning a lower stage from an incomplete source read.","Rubric 1.1 audits maturity and innovation without adding cosmetic offsets. Between maturity anchors 3 and 4, documented hybrid/session limits carry six tenths and safeguard license packaging four tenths: the operational limit is the larger new requirement, while entitlement remains necessary to complete the anchor. The same criteria apply to every workforce offering. No credit repeats requirements already satisfied by the base anchor. Entra now meets the whole anchor 5; no fractional 4-to-5 rubric is needed. Innovation baseline ties and JumpCloud’s unknown entitlement remain unchanged.","All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged."],"history":{"segment":"iam","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"iam","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"workforce-idp","name":"Workforce identity providers","scope":"Comparable workforce identity-provider editions for employee, contractor, and partner sign-in. Exclude customer identity, identity-governance certification suites, and privileged-access vaults. Score only the licensed workforce IdP modules named in each assessment; adjacent SKUs are constraints, not extra points."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented operating safeguards for running a workforce identity provider: recovery, emergency access, policy simulation, session-revocation limits, health monitoring, and license gates. Does not score uptime, efficacy, staffing, or vendor size.","question":"How completely do public docs describe production operating safeguards for this workforce identity provider?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.","1: A concrete basic operating safeguard is documented for the evaluated edition.","2: Docs describe authenticator enrollment or recovery plus at least one emergency-access or admin-MFA safeguard.","3: Docs add policy testing or fail-closed options plus audit of authentication or admin events.","4: Docs describe hybrid/sync or session-revocation limits together with explicit license packaging for those safeguards.","5: Docs describe a closed operating loop: recovery bootstrap, residual-session limits, health/monitoring, and license gates for the evaluated edition."],"refinements":[{"base":3,"criteria":[{"id":"session-hybrid-limits","label":"Documented hybrid/sync or session-revocation limits","weight":6},{"id":"safeguard-packaging","label":"Explicit license packaging for those operating safeguards","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","description":"Ordinal evidence of shipped workflows against a contemporary shared cohort baseline. Stage 3 means supported baseline workflows, not novelty or superiority. Higher stages require concrete generally available differences supported by comparative primary evidence. Workforce SSO, MFA including phishing-resistant authentication, lifecycle provisioning, device or sign-in context, conditional access, and documented session/recovery workflows are contemporary baseline capabilities. Session revocation, passkeys and risk-adaptive access alone do not establish differentiation.","question":"Which current baseline workflows are supported, and is any concrete shipped difference from that shared baseline established?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a shipped workflow within the scoped cohort. Missing evidence is unknown, never zero.","1: One basic in-scope workflow is confirmed shipped; no broader stage is established.","2: Several baseline components are confirmed shipped, but an integrated contemporary baseline workflow is not established.","3: An integrated contemporary baseline workflow is supported by primary evidence; this stage makes no differentiation or novelty claim.","4: Stage 3 plus one concrete generally available operator workflow difference beyond the shared contemporary baseline, supported by comparative primary evidence.","5: Stage 4 plus multiple complementary generally available workflow differences beyond that baseline, with their boundaries and prerequisites established."]},{"id":"breadth","name":"Capability breadth","description":"How much of the workforce identity plane is documented in the evaluated edition: protocols, directory, provisioning, adaptive policy, hybrid or device overlays. Excludes IGA certification campaigns and PAM vaults.","question":"How much of the workforce identity plane is documented in the evaluated edition?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an in-scope assessment capability. Missing evidence is unknown, never zero.","1: A bounded in-scope capability is documented for one environment or workflow.","2: SSO plus MFA plus a workforce directory.","3: Adds SCIM or HR provisioning and per-app or conditional policy.","4: Adds hybrid protocols (LDAP, RADIUS, on-prem adapters or gateways) or partner/guest federation in the evaluated edition.","5: Documented workforce plane includes lifecycle, hybrid or on-prem, and device or session controls inside the evaluated edition (still not IGA or PAM)."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Published connector catalogs, provisioning, management APIs, hybrid directory or adapters, and telemetry export. Does not score market share or partner counts as quality.","question":"How documented is the connector, API, and partner surface for this workforce IdP?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an integration or supported data handoff. Missing evidence is unknown, never zero.","1: A concrete native connector or supported manual integration is documented.","2: A published SaaS SSO catalog.","3: Catalog plus SCIM or equivalent provisioning and a public management API.","4: Adds hybrid directory sync or federation, or on-prem application adapters.","5: Broad catalog plus device/MDM or SIEM/health export and published integration kits."]},{"id":"governance","name":"Governance & control","description":"Administrative RBAC and access-policy controls for the workforce IdP itself. Identity-governance certifications and PAM vaults are out of cohort unless they are in the evaluated workforce edition.","question":"How documented are administrative RBAC and access-policy controls for the workforce IdP itself?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an administrative or policy control. Missing evidence is unknown, never zero.","1: A specific administrative control is documented for the scoped workflow.","2: Named admin roles plus MFA for administrators.","3: Per-app or group policy plus least-privilege admin roles.","4: Custom admin roles or privileged-role eligibility in the evaluated edition.","5: Stage 4 plus documented policy-change approval or versioning, scoped delegated administration and exportable evidence of administrative decisions in the evaluated workforce IdP edition; separate IGA campaigns are outside scope."]},{"id":"operations","name":"Operator enablement","description":"Operator toolkit for configuring, testing, and troubleshooting: admin how-tos, audit logs, APIs, simulation, health dashboards, and recovery runbooks. Does not score staffing savings or untested efficacy.","question":"How documented is the operator toolkit for configuring, testing, and troubleshooting this workforce IdP?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a supported operator action or guidance path. Missing evidence is unknown, never zero.","1: A concrete operator action and its basic use are documented.","2: Audit or sign-in logs documented.","3: Public APIs plus troubleshooting or report-only simulation.","4: Health dashboards or log export plus documented recovery or revocation runbooks.","5: Full documented operator loop: API, simulation, health/export, and recovery playbooks with residual-session caveats."]}],"assessments":[{"vendor":"microsoft-entra-id","cohort":"workforce-idp","edition":"Microsoft Entra ID P1 workforce authentication and Conditional Access; P2 ID Protection, Privileged Identity Management, and Entra ID Governance are named extras","asOf":"2026-09-21","status":"research-preview","summary":"P1 documents Conditional Access, TAP recovery, emergency-access exclusions, hybrid Connect, and Graph logs; risk policies, PIM, and governance campaigns need higher SKUs and are not scored as present.","dimensions":{"maturity":{"score":5,"confidence":"medium","rationale":"Current primary documentation supports the complete anchor 5 operating loop for P1: Temporary Access Pass bootstraps recovery, its expiration does not retroactively end established sessions, Conditional Access session controls bound residual access, and Connect Health supplies monitoring under an explicit P1 license requirement. Emergency-access guidance preserves recovery access. P2 risk-based policy and Governance extras remain excluded. This is a documentation-stage correction, not measured reliability.","sourceIds":["entra-tap","entra-emergency","entra-ca","entra-connect","entra-idprotection"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support phishing-resistant authentication, recovery bootstrap and Conditional Access policy workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["entra-auth","entra-tap","entra-ca"]},"breadth":{"score":5,"confidence":"medium","rationale":"P1 includes app provisioning and group provisioning, while public procedures document identity creation, updates and deprovisioning. Together with the established SSO/MFA, Conditional Access session controls and hybrid synchronization, this completes stage 5. Lifecycle here means provisioning lifecycle; the separately licensed Lifecycle Workflows, access reviews, PIM and Governance products are not counted.","sourceIds":["entra-auth","entra-ca","entra-connect","entra-provisioning","entra-licensing"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"The application gallery and provisioning procedures now substantiate the earlier cumulative SaaS-catalog and SCIM stages. Microsoft Graph and Connect hybrid synchronization complete stage 4, with provisioning entitlements confirmed in the feature table. Stage 5 is not inferred from a catalog count or adjacent Intune/MDM products; a complete in-edition integration-kit boundary remains unverified.","sourceIds":["entra-gallery","entra-provisioning","entra-licensing","entra-graph","entra-connect"]},"governance":{"score":4,"confidence":"medium","rationale":"Conditional Access supports user/group/application targeting and named least-privilege roles. Microsoft Entra custom role definitions and object-scoped assignments are documented, with P1 required for each user assigned a custom role. This meets stage 4 without P2 PIM or separate Governance features. Policy-change approval/versioning required for stage 5 is not established within this edition.","sourceIds":["entra-ca","entra-tap","entra-custom-roles","entra-licensing"]},"operations":{"score":5,"confidence":"medium","rationale":"Graph activity-log access, Conditional Access report-only evaluation, Connect Health monitoring under P1, and TAP/emergency-access recovery procedures together establish the stage-5 operator loop. TAP guidance explicitly warns that expiry does not retroactively terminate established sessions and directs operators to session controls. The rubric requires these documented procedures, not a single bundled handbook; the previous stage-4 ceiling imposed that extra requirement. This is documentation coverage, not measured reliability.","sourceIds":["entra-graph","entra-report-only","entra-ca","entra-connect","entra-tap","entra-emergency"]}},"constraints":["Evaluated edition is Entra ID P1 workforce authentication and Conditional Access; Microsoft 365 E3/Business Premium include P1, E5 includes P2.","Risk-based Conditional Access and full ID Protection reports require Entra ID P2.","PIM, entitlement management, access reviews, and lifecycle workflows require Entra ID P2 and/or Entra ID Governance or Entra Suite; they are not scored as workforce-IdP capabilities.","Hardware OATH tokens and agent identities in Conditional Access are preview and are not treated as GA.","TAP does not retroactively invalidate established sessions; NPS extension and AD FS adapter cannot use TAP.","Connect Health requires P1; Azure AD Connect V1 is retired. Cloud Sync was not separately assessed.","Intune device compliance, Defender for Cloud Apps session control, and Azure Monitor log export are adjacent products.","Customer identity (Entra External ID) is out of cohort.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","The ecosystem gap concerns the evidence assembled for this rubric, not an assertion that Entra lacks a gallery or provisioning."],"sources":[{"id":"entra-auth","title":"Microsoft Entra authentication overview","url":"https://learn.microsoft.com/en-us/entra/identity/authentication/overview-authentication","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-tap","title":"Configure a Temporary Access Pass in Microsoft Entra ID","url":"https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-ca","title":"Microsoft Entra Conditional Access overview","url":"https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-emergency","title":"Manage emergency access admin accounts","url":"https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-connect","title":"What is Microsoft Entra Connect and Connect Health","url":"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/whatis-azure-ad-connect","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-idprotection","title":"What is Microsoft Entra ID Protection","url":"https://learn.microsoft.com/en-us/entra/id-protection/overview-identity-protection","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-graph","title":"Access activity logs in Microsoft Entra ID","url":"https://learn.microsoft.com/en-us/entra/identity/monitoring-health/howto-access-activity-logs","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-governance-license","title":"Microsoft Entra ID Governance licensing fundamentals","url":"https://learn.microsoft.com/en-us/entra/id-governance/licensing-fundamentals","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-gallery","title":"Microsoft Entra application gallery","url":"https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/overview-application-gallery","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-provisioning","title":"Microsoft Entra automated application provisioning","url":"https://learn.microsoft.com/en-us/entra/identity/app-provisioning/user-provisioning","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-licensing","title":"Microsoft Entra feature licensing","url":"https://learn.microsoft.com/en-us/entra/fundamentals/licensing","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-custom-roles","title":"Microsoft Entra built-in and custom roles","url":"https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/custom-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"entra-report-only","title":"Conditional Access report-only evaluation","url":"https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-report-only","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"okta-workforce-identity","cohort":"workforce-idp","edition":"Okta Workforce Identity Cloud, Identity Engine, with Adaptive MFA; Lifecycle Management, Access Gateway, Identity Governance, and Identity Threat Protection are named extras","asOf":"2026-09-21","status":"research-preview","summary":"Identity Engine documents FastPass, app sign-in policies, custom admin roles, and Universal Logout; automatic logout and SCIM lifecycle depend on extra SKUs and are constrained, not assumed.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: Universal Logout and device-suspend session termination are documented operating safeguards, with explicit packaging (manual, rate-limited Universal Logout when only Adaptive MFA is enabled; Identity Threat Protection for policy-driven logout). Device lifecycle states (active, suspended, deactivated) and app sign-in policies are GA operator controls. Hybrid Access Gateway health was not verified in this edition.","sourceIds":["okta-ul","okta-device","okta-fastpass","okta-policy"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support device-aware authentication and scoped session-termination workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["okta-fastpass","okta-ul","okta-device"]},"breadth":{"score":2,"confidence":"medium","rationale":"The selected SSO/Adaptive MFA edition documents SSO, MFA and Universal Directory, satisfying stage 2. Stage 3 additionally requires SCIM or HR provisioning; the assessment explicitly treats Lifecycle Management as a separate excluded module, so the prior stage-3 award borrowed an out-of-scope prerequisite. Per-app policy alone does not complete that cumulative anchor. This corrects the research scope and does not indicate a product regression.","sourceIds":["okta-policy","okta-fastpass","okta-scim"]},"ecosystem":{"score":null,"confidence":"low","rationale":"The cited integration material spans SCIM and Lifecycle Management capabilities outside the explicitly scoped Adaptive MFA/SSO edition. It does not establish all cumulative integration requirements within this edition; the ecosystem score remains unknown until licensing and in-scope connectors are verified.","sourceIds":["okta-scim","okta-superadmin"]},"governance":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: standard roles (super, org, app, help desk, report, and others) plus custom admin roles (maximum 100) with resource sets are documented for Identity Engine. Access Certifications Administrator is an IGA role and is not treated as workforce-IdP governance. Super admin remains required to manage other admins.","sourceIds":["okta-custom-admin","okta-standard-admin","okta-policy"]},"operations":{"score":4,"confidence":"medium","rationale":"Existing operator procedures cover authentication, device lifecycle and manual Universal Logout within Adaptive MFA. Identity Engine log streaming exports System Log events to EventBridge or Splunk Cloud with explicit delivery/deactivation limits, completing stage 4 alongside the documented revocation runbook. Policy-driven logout remains an Identity Threat Protection extra. A full in-edition simulation/recovery loop for stage 5 is unverified.","sourceIds":["okta-ul","okta-device","okta-fastpass","okta-log-streams"]}},"constraints":["Evaluated edition is Workforce Identity Cloud Identity Engine with Adaptive MFA, not Auth0 customer identity.","Okta Lifecycle Management is required for SCIM provisioning features cited in help; it is not assumed in the breadth score.","Identity Threat Protection with Okta AI is required for automatic Universal Logout from entity-risk policy and for several System Log session-protection events.","In Adaptive MFA-only orgs, Universal Logout is manual, Admin Console-triggered, and rate-limited.","Access Gateway, Okta Privileged Access, and Identity Governance are distinct SKUs and are not scored.","FastPass requires current Okta Verify enrollment; FastPass cannot sign in to the computer itself.","Universal logout still depends on each application honoring logout; residual app sessions are unverified here.","Classic Engine versus Identity Engine differences can change policy semantics; this assessment uses Identity Engine docs.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"okta-fastpass","title":"Okta FastPass","url":"https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/fp/fp-main.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-ul","title":"Configure Universal Logout","url":"https://help.okta.com/en-us/content/topics/apps/universal-logout-amfa.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-device","title":"Device lifecycle","url":"https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/devices-lifecycle.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-policy","title":"App sign-in policies","url":"https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/about-app-sign-on-policies.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-scim","title":"SCIM app integrations","url":"https://help.okta.com/en-us/Content/Topics/Apps/apps-about-scim.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-custom-admin","title":"Custom admin roles","url":"https://help.okta.com/en-us/Content/Topics/security/custom-admin-role/custom-admin-roles.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-standard-admin","title":"Standard administrator roles and permissions","url":"https://help.okta.com/oie/en-us/content/topics/security/administrators-admin-comparison.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-superadmin","title":"Super administrators","url":"https://help.okta.com/en-us/Content/Topics/Security/administrators-super-admin.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-syslog","title":"View System Log events for Identity Threat Protection","url":"https://help.okta.com/oie/en-us/content/topics/itp/system-log-events.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"okta-log-streams","title":"Okta Identity Engine log streaming and delivery limits","url":"https://help.okta.com/oie/en-us/content/topics/reports/log-streaming/about-log-streams.htm","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"ping-identity","cohort":"workforce-idp","edition":"PingFederate 13.x federation server with PingOne MFA for Workforce; DaVinci, PingOne Protect, and PingOne Verify are named extras","asOf":"2026-09-21","status":"research-preview","summary":"PingFederate documents a branched authentication policy engine and hybrid adapters; PingOne MFA for Workforce is a separate license, and DaVinci orchestration is not assumed in the scored edition.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Anchor 3 remains supported by fail-closed authentication policies and logged MFA integration outcomes. The 13.1 Session Revocation API documents client authentication and token-validation limits, adding 0.6 under the shared refinement rubric. The license packaging of those safeguards has not been established, so the remaining 0.4 is uncredited.","sourceIds":["ping-policies","ping-mfa-kit","ping-session-revocation"],"refinement":{"base":3,"evidence":[{"criterion":"session-hybrid-limits","rationale":"The 13.1 endpoint supports client-secret or client-certificate authentication, excludes Private Key JWT, and requires explicit token-validation revocation checks. Status queries can extend a session unless updateActivityTime is false.","sourceIds":["ping-session-revocation"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support federation policies, passkeys and passwordless authentication workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["ping-mfa-kit","ping-passwordless","ping-policies"]},"breadth":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: PingFederate browser SSO covers SAML, OIDC, and adapter-based legacy paths; bundled adapters include Kerberos, X.509, HTML form, Identifier First, and PingOne MFA. PingOne documents a workforce RADIUS gateway. Full joiner-mover-leaver IGA and device management are outside this federation-plus-MFA edition.","sourceIds":["ping-adapters","ping-saml","ping-mfa-integrations"]},"ecosystem":{"score":null,"confidence":"low","rationale":"The cited integration material includes a DaVinci kit and tenant outside the evaluated federation/MFA scope. The evidence does not establish the cumulative ecosystem stage within this edition, so it remains unknown rather than borrowing an adjacent SKU.","sourceIds":["ping-adapters","ping-mfa-kit","ping-davinci"]},"governance":{"score":3,"confidence":"low","rationale":"Maps to anchor 3 with low confidence: PingOne documents Environment Admin and PingFederate-related roles for admin SSO into PingFederate, and PingFederate policies can branch by group membership rules. A custom-admin-role or PIM-style eligibility model for the federation server was not verified, so anchor 4 is not awarded.","sourceIds":["ping-admin-sso","ping-policies"]},"operations":{"score":3,"confidence":"medium","rationale":"Maps to anchor 3: administrators get a detailed policy editor (copy/paste paths, fragments, tracked HTTP parameters) and adapter configuration references. Self-hosted operations, log export, and a cloud health dashboard for PingFederate nodes were not documented in the pages reviewed, so anchor 4 is not awarded.","sourceIds":["ping-policies","ping-adapters","ping-mfa-kit"]}},"constraints":["Evaluated edition is PingFederate plus PingOne MFA for Workforce, not PingOne for Customers and not a ForgeRock-branded SKU.","PingOne MFA Integration Kit 4.x requires PingFederate 11.3 or later; passwordless kit guidance requires PingFederate 13.x and kit 4.1+ plus Java 17 for kit 4.1.","PingOne MFA for Customer or Workforce license is required; workforce versus customer MFA integration paths differ, including legacy PingID notes and Singapore-geography limits.","DaVinci, PingOne Protect, PingOne Verify, and Advanced Identity Cloud connectors are separate modules and are not in the innovation score.","PingFederate is self-hosted; operating-system, clustering, and certificate-renewal operations were not assessed.","Government-cloud authorization packages were not checked.","IdP versus application logout and residual token lifetime must be tested per relying party; universal revocation is unverified.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"ping-policies","title":"Defining authentication policies (PingFederate 13.1)","url":"https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/pf_defining_auth_policies.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-adapters","title":"Bundled adapters (PingFederate 13.1)","url":"https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/pf_bundled_adapt.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-mfa-kit","title":"PingOne MFA Integration Kit 4.x","url":"https://docs.pingidentity.com/integrations/pingone/pingone_mfa_integration_kit/pf_p1_mfa_ik_4.0.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-passwordless","title":"Configuring a PingFederate policy for passwordless authentication","url":"https://docs.pingidentity.com/integrations/pingone/pingone_mfa_integration_kit/pid_configuring_pf_policy_for_passwordless_authentication.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-saml","title":"Configuring a SAML application (workforce use cases)","url":"https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_config_saml_app.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-mfa-integrations","title":"Strong authentication (MFA) integrations","url":"https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_strong_authentication_integrations.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-admin-sso","title":"Setting up SSO to PingFederate","url":"https://docs.pingidentity.com/pingone/getting_started_with_pingone/p1_setup_sso_pf.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-davinci","title":"PingOne DaVinci Integration Kit","url":"https://docs.pingidentity.com/integrations/pingone/pingone_davinci_integration_kit/pf_p1_davinci_ik.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ping-session-revocation","title":"Session Revocation API endpoint (PingFederate 13.1)","url":"https://docs.pingidentity.com/pingfederate/13.1/developers_reference_guide/pf_session_revocation_api_endpoint.html","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"jumpcloud","cohort":"workforce-idp","edition":"JumpCloud Open Directory with SSO and MFA; Directory Insights, device management, and some SSO packages are named extras","asOf":"2026-09-21","status":"research-preview","summary":"Open Directory documents SSO, SCIM, LDAP, RADIUS, conditional access, and admin RBAC in one cloud directory; Directory Insights and device modules are package-gated, and no FastPass-class session-revocation workflow was evidenced.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"Maps to anchor 3: Conditional Access and Default Access Policies are documented for User Portal, SSO, and LDAP, Directory Insights records auth and admin events, and MFA is required for Admin Portal sign-in. Directory Insights is package-gated with 90-day retention, and no TAP-class recovery or Universal Logout-class revocation runbook was found, so anchor 4 is not awarded.","sourceIds":["jc-cap","jc-di","jc-admin-mfa"]},"innovation":{"score":null,"confidence":"low","rationale":"Public documentation describes both conventional MFA and JumpCloud Go device-bound passwordless authentication. Go requires a supported managed device, agent, browser extension and hardware-backed authenticator. This research has not established the complete entitlement boundary for those prerequisites in the selected SSO/MFA edition. The innovation stage remains unknown pending that scope check; this is not evidence that passwordless workflows are absent.","sourceIds":["jumpcloud-go"]},"breadth":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: Open Directory documents SAML and OIDC SSO, JIT on SAML, SCIM create/update/deprovision, cloud LDAP, RADIUS, and conditional policy. Device management and MDM enrollment SSO exist in the family but are in-scope only when that module is licensed; they are not required for this score. IGA certifications and PAM vaults are out of cohort.","sourceIds":["jc-sso","jc-scim","jc-ldap","jc-cap"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Maps to anchor 3: a published SSO catalog with prebuilt and custom SAML/OIDC connectors, SCIM connectors (and custom SCIM), plus REST and PowerShell for Directory Insights. LDAP/RADIUS are counted in breadth rather than as a third-party adapter kit. SIEM/S3 export beyond the optional AWS serverless Directory Insights app was not independently verified, so anchor 4/5 are not awarded.","sourceIds":["jc-sso","jc-scim","jc-di"]},"governance":{"score":4,"confidence":"medium","rationale":"Maps to anchor 4: named Admin Portal roles (Administrator with Billing through Help Desk and Read Only) plus custom admin roles (documentation states a maximum of 20) with permission categories for access and application management. Admin Portal Conditional Access cannot be password-only. Access-package certification campaigns are not documented in this workforce directory edition.","sourceIds":["jc-roles","jc-custom-roles","jc-cap"]},"operations":{"score":3,"confidence":"medium","rationale":"Maps to anchor 3: Admin Portal how-tos cover SSO/SCIM setup, Conditional Access troubleshooting with Directory Insights policy-evaluation logs, and API/PowerShell queries. Directory Insights enablement may require an account manager, retention is 90 days, and no report-only policy mode equivalent was evidenced, so anchor 4 is not awarded.","sourceIds":["jc-di","jc-cap-ts","jc-sso"]}},"constraints":["Evaluated edition is JumpCloud Open Directory with SSO and MFA, not customer identity and not a full IGA or PAM suite.","Directory Insights is included only in some package plans and may need account-manager enablement; retention is 90 days unless exported.","SSO Package or higher (or SSO add-on) is cited as a prerequisite on some SCIM/SSO integrations (example: SuccessFactors).","Device management, Remote Assist, Password Manager, and AI Gateway are separate modules and are not scored as IdP capabilities.","Conditional Access Chrome Device Trust Connector depends on Google Admin Chrome connectors and supported browsers.","LDAP/RADIUS FQDNs are region-specific; plaintext LDAP is not allowed.","Not all catalog apps support create, update, and deprovision SCIM actions.","Offline or cached device login after user suspend was not verified from public docs.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Confirm the JumpCloud Go and device-management entitlements and enrollment prerequisites for the selected SSO/MFA package; documented availability does not establish inclusion in this narrower edition."],"sources":[{"id":"jc-di","title":"Get Started: Directory Insights","url":"https://jumpcloud.com/support/directory-insights","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-cap","title":"Set a Default Access Policy","url":"https://jumpcloud.com/support/set-a-global-policy","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-sso","title":"Get Started: SSO Applications","url":"https://jumpcloud.com/support/get-started-applications","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-scim","title":"Get Started: SCIM Connectors","url":"https://jumpcloud.com/support/get-started-identity-management-connectors","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-mfa","title":"Configure TOTP MFA for Your Org","url":"https://support.jumpcloud.com/support/s/article/set-up-multi-factor-authentication-for-your-org----jumpcloud-admins-2019-08-21-10-36-47","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-admin-mfa","title":"Enable MFA for the Admin Portal","url":"https://support.jumpcloud.com/support/s/article/how-to-enable-multi-factor-authentication-for-the-jumpcloud-admin1-2019-08-21-10-36-47","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-roles","title":"Admin Portal Roles","url":"https://jumpcloud.com/support/admin-portal-roles","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-custom-roles","title":"Custom Admin Roles","url":"https://jumpcloud.com/support/custom-admin-roles","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-ldap","title":"Get Started: Cloud LDAP","url":"https://jumpcloud.com/support/use-cloud-ldap","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jc-cap-ts","title":"Troubleshoot JumpCloud Conditional Access Policy Issues (Chrome DTC)","url":"https://jumpcloud.com/support/troubleshooting-jumpcloud-conditional-access-policy-issues-chrome-dtc","accessedAt":"2026-09-21","kind":"documentation"},{"id":"jumpcloud-go","title":"Get Started: JumpCloud Go","url":"https://jumpcloud.com/support/get-started-jumpcloud-go","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"lean-team","name":"Small IT team consolidating directory and SSO","description":"A small workforce wants one administrative plane for identities, SaaS SSO, and optional device or LDAP/RADIUS leftovers, without buying a separate IGA or PAM product in the first phase.","priorities":["operations","breadth","ecosystem"],"questions":["Which SSO, SCIM, Directory Insights, and device modules are actually on the quote versus directory-only?","Which lab applications honor logout after the IdP session is cleared?","Can LDAP or RADIUS in the lab replace the bind and network-login paths you still run?"]},{"id":"hybrid-federation","name":"Hybrid and partner federation estate","description":"A regulated workforce still federates partner identity providers and on-premises apps while moving selected SaaS apps to a cloud IdP.","priorities":["ecosystem","maturity","governance"],"questions":["Which policies and adapters live on the federation server versus the cloud MFA or orchestration tenant?","If on-premises directory disablement happens on Friday, which system is authoritative and how is cloud access revoked?","Are emergency-access accounts excluded from blocking policies and independent of federation?"]},{"id":"recovery-revocation","name":"Authenticator recovery and leaver revocation","description":"Operators must bootstrap a replacement phishing-resistant authenticator after identity verification, then disable a contractor and record residual application sessions.","priorities":["maturity","operations","governance"],"questions":["What licensed recovery method exists, and is it identity proofing or only a bootstrap pass?","Does IdP logout end the application session, or only the next authentication?","Which admin role can issue recovery credentials without standing Global/Super Admin?"]}],"researchNotes":["First edition dated 2026-09-21; no historical assessments are available.","The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.","Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.","Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.","Contemporary cohort baseline: Workforce SSO, MFA including phishing-resistant authentication, lifecycle provisioning, device or sign-in context, conditional access, and documented session/recovery workflows are contemporary baseline capabilities. Session revocation, passkeys and risk-adaptive access alone do not establish differentiation.","Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.","Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.","Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.","Final editorial check added the current JumpCloud Go setup procedure. Because its managed-device entitlement scope was not resolved for this edition, innovation remains unknown rather than assigning a lower stage from an incomplete source read.","Rubric 1.1 audits maturity and innovation without adding cosmetic offsets. Between maturity anchors 3 and 4, documented hybrid/session limits carry six tenths and safeguard license packaging four tenths: the operational limit is the larger new requirement, while entitlement remains necessary to complete the anchor. The same criteria apply to every workforce offering. No credit repeats requirements already satisfied by the base anchor. Entra now meets the whole anchor 5; no fractional 4-to-5 rubric is needed. Innovation baseline ties and JumpCloud’s unknown entitlement remain unchanged.","All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged."]},"changes":[]}]},"unassessed":[{"slug":"auth0","name":"Auth0","company":"Auth0","profileUrl":"/landscape/vendors/auth0/"},{"slug":"sailpoint-identity-security","name":"SailPoint Human Fabric / Identity Security Cloud","company":"SailPoint","profileUrl":"/landscape/vendors/sailpoint-identity-security/"},{"slug":"saviynt-identity-cloud","name":"Saviynt Identity Cloud","company":"Saviynt","profileUrl":"/landscape/vendors/saviynt-identity-cloud/"},{"slug":"cyberark-idira","name":"Idira Privileged Access Management","company":"CyberArk","profileUrl":"/landscape/vendors/cyberark-idira/"},{"slug":"beyondtrust-pam","name":"BeyondTrust PAM Portfolio","company":"BeyondTrust","profileUrl":"/landscape/vendors/beyondtrust-pam/"},{"slug":"delinea-secret-server","name":"Delinea Secret Server","company":"Delinea","profileUrl":"/landscape/vendors/delinea-secret-server/"},{"slug":"ibm-verify","name":"IBM Verify","company":"IBM","profileUrl":"/landscape/vendors/ibm-verify/"},{"slug":"oracle-identity","name":"Oracle OCI IAM / Identity Governance","company":"Oracle","profileUrl":"/landscape/vendors/oracle-identity/"},{"slug":"cisco-duo","name":"Cisco Duo","company":"Cisco Duo","profileUrl":"/landscape/vendors/cisco-duo/"},{"slug":"aws-iam-identity-center","name":"AWS IAM Identity Center","company":"Amazon Web Services","profileUrl":"/landscape/vendors/aws-iam-identity-center/"},{"slug":"google-cloud-identity","name":"Google Cloud Identity / Workforce Federation / Identity Platform","company":"Google Cloud","profileUrl":"/landscape/vendors/google-cloud-identity/"}]}