Our State of Authorization: AI Edition is now available Get it now »

Gartner IAM Texas 2024 recap with David Brossard and Matt Luckett

Our CTO and VP of Customer Relations share highlights from the summit and what the future looks like for authorization.

Last week our team hopped on a plane and went down to Grapevine, Texas for the Gartner Identity and Access Management Summit. This event is Gartner’s biggest conference focused on identity across workforce and customer.

We had a great time chatting with everyone about authorization, reducing standing access, Zero Trust, and many other topics that came up at the summit. We spoke with our Chief Technology Officer, David Brossard, and VP of Customer Relations, Matt Luckett, about their time at the conference.

What were the major authorization trends or issues highlighted at the event?

David: I was glad to see several sessions focused on authorization. One key topic that made its way to Gartner IAM was API Authorization. OWASP has repeatedly defined broken access control as the number one concern for APIs and Gartner’s Erik Wahlström took notice. His session on API authorization was phenomenal.

I was also able to attend Espen Bago’s expert session on ABAC and PBAC. Attribute management is still a concern for practitioners.

AI is up and coming in the authorization realm. Everyday, I’m amazed by Microsoft Copilot’s ability to write AFLA policies. Not only that, but it’s now possible to implement authorization in RAG-based AI systems. As time progresses, we see the rise of AI in the cybersecurity industry maturing and that was present at Gartner.

Matt: I noticed a couple of trends kept showing up at Gartner this year. The Joiner, Mover, Leaver problem is something that customers are still dealing with decades after the problem presented itself. This tells me companies are spending money trying to solve the problem, but not making any headway.

The other trend is for companies to focus more on resilience. A big threat to businesses is disruptions caused not by hackers, but by systems going down. Building a resilient system to support the business should be top of mind for most companies.

What was the most surprising or insightful session?

David: I was delighted to see how well-attended the last session dedicated to authorization was. My peer, Omri Gazitt of Aserto and fellow co-chair of the OpenID AuthZEN Working Group, Homan Farahmand of Gartner, and I delivered a 30-minute presentation on the latest advancements in the authorization space. Because it was so late on Wednesday, I expected a relatively empty room. Instead, it was packed. It is a sure sign customers and IAM teams are paying attention to their next challenge: fine-grained access.

Source: Omri Gazitt

Matt: The opening keynote left the biggest impression on me. The topic in particular was around resilience and keeping the business moving forward. A question was asked for people to raise their hand if their business had been affected by hackers like what happened at MGM Grand in Las Vegas. Quite a few hands went up. Then the question was asked on how many businesses had been affected by systems crashing — servers, networks, end points, etc. Every hand across the room went up. This highlighted to me the importance of making sure that the policies governing access were robust and externalized from the application so user access was easy to manage and scale with the business.

From the floor of the Gartner presentation

Are there any authorization trends you believe will emerge based on what you heard at the conference?

David: I am curious to see how authorization will evolve and possibly provide a natural extension to authentication and especially token-based authentication (think SSO or OAuth-based experiences). My peer, Atul, is leading the OpenID Shared Signals Working Group which aims to enable more dynamic sessions. The OAuth WG is talking about transaction tokens and dynamic claims. Authorization has a part to play there. I am starting to think about “pragmatic authorization”– a means to deliver the right level of protection in a way a broad spectrum of applications can use.

Matt: Based on the topics covered in different sessions I believe there are a few trends that will emerge in the next 24 months.

  1. Focus on getting identities correct: Identities are the core to understanding who your users are and the first step to aligning to most compliance standards.  This builds the definition for all access policies to ensure the right users have the right level of access at the right time.  Organizations are going to spend time and resources to make sure these definitions are correct.
  2. Building Resilient Policies: Once the user identities are defined, organizations will shift to creating policies to pull user attributes rather than assign roles to users.  This effort will drastically reduce the burden of maintaining policies and user roles. It will also be core to addressing the Joiner, Mover, Leaver problem.
  3. More AI with more control: AI is being used across every business for better or for worse.  AI will become a fundamental aspect of both organizations and vendor tools.  This will end up forcing more controls to be implemented to limit the improper use and training of AI.

Are the trends we’re seeing in Europe further ahead or behind with what’s happening in North America?

David: Both regions have somewhat overlapping concerns and drivers. North America may be leading the charge in AI all the while, European regulators are providing businesses with more reasons to implement fine-grained access. I wouldn’t say either region is ahead: they have a common set of challenges and regional specificities.

Matt: Europe has some new compliance standards taking effect this year such as DORA that is causing businesses in Europe to take more steps to ensure safe handling of information. North America has other regulations like CCPA and the executive order to improve national cybersecurity, but seem to be lagging slightly behind Europe.

What would you like to see covered at the conference in 2025?

David: I was delighted with the focus Gartner gave standards and especially shared signals. I am looking forward to replicating that success for AuthZEN.

Matt: Overall, the conference and conversations were great, but a common concern coming from participants was the lack of direction. Individuals kept making the same comment:

“The information is great, but where do I go from here? Where should I be investing my software security dollars?”

Ideally, it would be great to have a guide that shows the steps each company should take that will address the security challenges, enable their users and handle their compliance regulations.  This would give organizations the insight to know where they fit on their security journey and where they should look to tackle the upcoming challenges.

Thank you to those who visited us at Gartner IAM!

It was a pleasure getting to meet new and familiar faces at our booth and sessions. Want to read more about what we talked about at the conference?

Here are three great resources for you to look into:

Didn’t get the chance to talk with us at Gartner IAM? Request a demo and join the movement towards modernized, scalable runtime authorization and access control.

P.S. We’re going to be at the event again next year in 2025. Looking forward to seeing everyone there!

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About Axiomatics

The world’s largest enterprises and government agencies continually depend on Axiomatics’ award-winning authorization platform to share sensitive, valuable and regulated digital assets – but only to authorized users and in the right context.