Atlas Fold / IAM

IAM, unfolded.

Identity & access management

Atlas Fold / IAM / First edition

Identity & access management

Provisional editorial research based on public documentation, not tested effectiveness.

First edition · Reviewed · Rubric 1.1

Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.

Comparable workforce identity-provider editions for employee, contractor, and partner sign-in. Exclude customer identity, identity-governance certification suites, and privileged-access vaults. Score only the licensed workforce IdP modules named in each assessment; adjacent SKUs are constraints, not extra points.

Download JSON

Six dimensions, with gaps listed

Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.

Separated marks connect to their exact positions. Separation does not change scores.

Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.

A position is only half the story

Momentum

Building history

Baseline recorded 2026-09-21. A second comparable review is needed to show movement.

Download dated history

Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.

History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.

Review history & what changed

The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.

  • 2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
How momentum is calculated →

Documented scores

Microsoft Entra ID (medium confidence) has the highest documented score (5.0) for Operational maturity among assessed offerings in this comparison group.

Microsoft Entra ID (low confidence) and Okta Workforce Identity (low confidence) and PingFederate / PingOne (low confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings. 1 offering remains unknown for this dimension.

Unknowns and gaps

Unknown is not low quality. Marks are omitted where a required score is unknown.

  • Microsoft Entra ID: no unknown dimensions.
  • Okta Workforce Identity: Ecosystem & integration
  • PingFederate / PingOne: Ecosystem & integration
  • JumpCloud Open Directory: Shipped innovation

Scenario lens

A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.

Selected evidence

Microsoft Entra ID · Microsoft

Microsoft Entra ID P1 workforce authentication and Conditional Access; P2 ID Protection, Privileged Identity Management, and Entra ID Governance are named extras · Assessed 2026-09-21 · Research preview

Operational maturity

How completely do public docs describe production operating safeguards for this workforce identity provider?

Documented operating safeguards for running a workforce identity provider: recovery, emergency access, policy simulation, session-revocation limits, health monitoring, and license gates. Does not score uptime, efficacy, staffing, or vendor size.

P1 documents Conditional Access, TAP recovery, emergency-access exclusions, hybrid Connect, and Graph logs; risk policies, PIM, and governance campaigns need higher SKUs and are not scored as present.

Score5.0 / 5.0medium confidence

Rationale and sources

Current primary documentation supports the complete anchor 5 operating loop for P1: Temporary Access Pass bootstraps recovery, its expiration does not retroactively end established sessions, Conditional Access session controls bound residual access, and Connect Health supplies monitoring under an explicit P1 license requirement. Emergency-access guidance preserves recovery access. P2 risk-based policy and Governance extras remain excluded. This is a documentation-stage correction, not measured reliability.

Constraints

  • Evaluated edition is Entra ID P1 workforce authentication and Conditional Access; Microsoft 365 E3/Business Premium include P1, E5 includes P2.
  • Risk-based Conditional Access and full ID Protection reports require Entra ID P2.
  • PIM, entitlement management, access reviews, and lifecycle workflows require Entra ID P2 and/or Entra ID Governance or Entra Suite; they are not scored as workforce-IdP capabilities.
  • Hardware OATH tokens and agent identities in Conditional Access are preview and are not treated as GA.
  • TAP does not retroactively invalidate established sessions; NPS extension and AD FS adapter cannot use TAP.
  • Connect Health requires P1; Azure AD Connect V1 is retired. Cloud Sync was not separately assessed.
  • Intune device compliance, Defender for Cloud Apps session control, and Azure Monitor log export are adjacent products.
  • Customer identity (Entra External ID) is out of cohort.
  • Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.
  • The ecosystem gap concerns the evidence assembled for this rubric, not an assertion that Entra lacks a gallery or provisioning.

Sources

0–5 rubric anchors

  • 0 — Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.
  • 1 — A concrete basic operating safeguard is documented for the evaluated edition.
  • 2 — Docs describe authenticator enrollment or recovery plus at least one emergency-access or admin-MFA safeguard.
  • 3 — Docs add policy testing or fail-closed options plus audit of authentication or admin events.
  • 4 — Docs describe hybrid/sync or session-revocation limits together with explicit license packaging for those safeguards.
  • 5 — Docs describe a closed operating loop: recovery bootstrap, residual-session limits, health/monitoring, and license gates for the evaluated edition.
Assessed offerings inWorkforce identity providers. Unknown means not scored, not low quality.
OfferingOperational maturityShipped innovationCapability breadthEcosystem & integrationGovernance & controlOperator enablement
Microsoft Entra ID5.0 (medium)3.0 (low)5.0 (medium)4.0 (medium)4.0 (medium)5.0 (medium)
Okta Workforce Identity4.0 (medium)3.0 (low)2.0 (medium)Unknown4.0 (medium)4.0 (medium)
PingFederate / PingOne3.6 (medium)3.0 (low)4.0 (medium)Unknown3.0 (low)3.0 (medium)
JumpCloud Open Directory3.0 (medium)Unknown4.0 (medium)3.0 (medium)4.0 (medium)3.0 (medium)

Not yet assessed

Unknown is explicitly not low quality. These catalog offerings have no Atlas Fold scores.

Research notes

First edition dated 2026-09-21; no historical assessments are available.

The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.

Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.

Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.

Contemporary cohort baseline: Workforce SSO, MFA including phishing-resistant authentication, lifecycle provisioning, device or sign-in context, conditional access, and documented session/recovery workflows are contemporary baseline capabilities. Session revocation, passkeys and risk-adaptive access alone do not establish differentiation.

Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.

Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.

Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.

Final editorial check added the current JumpCloud Go setup procedure. Because its managed-device entitlement scope was not resolved for this edition, innovation remains unknown rather than assigning a lower stage from an incomplete source read.

Rubric 1.1 audits maturity and innovation without adding cosmetic offsets. Between maturity anchors 3 and 4, documented hybrid/session limits carry six tenths and safeguard license packaging four tenths: the operational limit is the larger new requirement, while entitlement remains necessary to complete the anchor. The same criteria apply to every workforce offering. No credit repeats requirements already satisfied by the base anchor. Entra now meets the whole anchor 5; no fractional 4-to-5 rubric is needed. Innovation baseline ties and JumpCloud’s unknown entitlement remain unchanged.

All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged.

How to read these scores

Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.

What this edition covers.

First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.

  • First edition dated 2026-09-21; no historical assessments are available.
  • The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.
  • Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.
  • Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.
  • Contemporary cohort baseline: Workforce SSO, MFA including phishing-resistant authentication, lifecycle provisioning, device or sign-in context, conditional access, and documented session/recovery workflows are contemporary baseline capabilities. Session revocation, passkeys and risk-adaptive access alone do not establish differentiation.
  • Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.
  • Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.
  • Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.
  • Final editorial check added the current JumpCloud Go setup procedure. Because its managed-device entitlement scope was not resolved for this edition, innovation remains unknown rather than assigning a lower stage from an incomplete source read.
  • Rubric 1.1 audits maturity and innovation without adding cosmetic offsets. Between maturity anchors 3 and 4, documented hybrid/session limits carry six tenths and safeguard license packaging four tenths: the operational limit is the larger new requirement, while entitlement remains necessary to complete the anchor. The same criteria apply to every workforce offering. No credit repeats requirements already satisfied by the base anchor. Entra now meets the whole anchor 5; no fractional 4-to-5 rubric is needed. Innovation baseline ties and JumpCloud’s unknown entitlement remain unchanged.
  • All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged.

Workforce identity providers

Comparable workforce identity-provider editions for employee, contractor, and partner sign-in. Exclude customer identity, identity-governance certification suites, and privileged-access vaults. Score only the licensed workforce IdP modules named in each assessment; adjacent SKUs are constraints, not extra points.

Find your next idea.

Tip: press / to open search. Escape closes this window.