News

AI is the New Thing, But Identity Management Still Demands a Focus on Fundamentals

February 17, 2026

Does the AI hype live up to the promise in IDM? 

 

There is an unprecedented amount of buzz and even more investment in AI that echoes historical tech bubbles (Dot-Com, Telecom, Crypto) in a way that should have us all reaching for a pinch of salt. Some researchers and industry experts are doing exactly that. It would be a mistake to replicate the deployment rush of previous tech booms where the excitement sometimes outpaced the practical security considerations, or take our collective eyes off the real prize of solid, mature security practices where the bouncy AI ball diverges from it. Otherwise, we can get ourselves into trouble. 

This is not to say that AI isn't and won’t continue to be transformative, but that there is an over-emphasis on it, as there is a tendency to be when there's any shiny, new object. This inadvertently leads to a sort of relegating to second tier status the unglamorous basics of IT security, particularly in the realm of identity. Too many identity and other security professionals spend their time evangelizing about AI and what it might hold for the future when there is still an exigent need in many organizations for foundational IAM security practices. Many organizations, even large ones, are still struggling to plan and execute on IAM or IGA 101 and having a rough go of it. Is that much of the rest of the world truly living in a world of “automagical” workflows manned by AI agents?

Identity needs to continually and increasingly to be treated as foundational to security, with identity systems treated as critical infrastructure, as opposed to more things that security needs to manage. The pace of change has already outstripped many companies' capabilities because they are in their respective businesses first, and security second (as an enabler of the first, we hope). As useful a tool as AI is, it cannot relieve organizations of what can be the monumental job of building a solid identity security base upon which more sophisticated controls can be implemented. The work of foundational identity remains essential and should be treated with the requisite seriousness and care. The reason that many organizations are still having a rough go of it is that the same challenges remain, and while the basics are well-understood, that does not make them trivial or easy. 

Prioritizing these six essentials elements form the resilient base needed before AI tools can add value:

  • assessing your identity landscape, 
  • classifying high-value assets, 
  • strengthening authentication,
  • managing identity lifecycles, 
  • enforcing least privilege, and 
  • adopting Zero Trust 

Assess and document your current landscape

In my experience, even more mature companies are at the very least still in the process of doing this, and most have never started because of how daunting it is. It’s a well-worn maxim that you can’t secure what you don’t know about. This isn’t just about application inventory and network mapping – it’s about uncovering the hidden attack surfaces that can catch a security team completely off-guard. 

 

Secure high-value assets and implement data classification

Once you know about it, then you can prioritize it. All assets are important, but not all equally so. What systems are operationally the most critical? Which contain highly sensitive or regulated data? This is a serious undertaking that often involves multiple parties across the enterprise; legal, finance, operations, and others. The challenge is in accurately identifying what data is where across which assets, performing which functions, and how it is used. The better you do this, the more effectively you can protect what's truly critical..

 

Strengthen authentication fundamentals

Perhaps, in some ways, the most basic is the most non-trivial. Multi-factor authentication (MFA) is just the starting point. Adoption is around 70% in enterprises but lower in SMBs at 27-34% according to Jumpcloud. Even in 2026, full coverage eludes most companies, especially across legacy systems, hybrid environments, third-party integrations and remote workforces. Doing this in a phased, risk-aware manner requires planning and prioritization. Choose reliable methods (avoid SMS), train users, and enforce it for privileged accounts and systems first. From there, moving toward phishing-resistant options like passkeys and hardware tokens dramatically reduces breach risks but must be approached carefully; users have low thresholds for operational disruptions.

 

Establish identity lifecycle management processes

It’s important to cover the automation of governance of the entire user lifecycle from onboarding and provisioning to offboarding and deprovisioning (and everything in between). This foundational management and governance is often incomplete due to lack of proper source data, manual processes, or lack of visibility. This leads to incomplete access that requires manual intervention, or worse, inappropriate access that nobody ever notices. Getting this right eliminates one of the largest sources of identity risks before they become headlines.

 

Implement Least Privilege access controls

Begin, methodically and deliberately, to enforce granting only the necessary permissions to applications and assets. Use role-based access (RBAC) or attribute-based access control wherever possible. This is extraordinarily complex. Permission sets are highly specific to users and their respective systems, which require dealing with legacy constraints and engaging in fine-tuning on an ongoing basis, but the payoff is worth it. It mitigates privilege sprawl, shrinks the attack surface, and goes straight to the bottom-line when it comes to reducing breaches. 

 

Adopt Zero Trust

Of all the things on this list, this is probably the most “it’s a journey, not a destination” one of the bunch. You could think of it as an overarching philosophy to tie all this together. Zero Trust is expressly iterative; an ongoing, maturity-based program that requires re-architecting around identity, context, and risk. It means shifting to a model of default denial and verifying access on an ongoing basis.This is another undertaking that will require sustained effort and cross-functional collaboration, but if an enterprise can gain momentum it can start to create a resilient posture that will scale as new threats emerge. 

 

Even in the most promising possible future of AI-agent fleets writing code and running enterprises, they will increasingly multiply the force capability of humans (albeit fewer of them), but never obsolesce them. You also cannot rely on new AI tech to relieve teams of the necessity for strong foundations on which to build this better, more autonomous future. Anything else is the age-old mistake of automating a bad process. 

 

Speaking of automated processes, have you taken a hard look at your own security in the adoption of AI? It may seem trivial now, but having the right controls set in place first can save heartache and potential data disaster down the line. Need some help working on that AI security? Idenhaus can help - just call to see what our experts can bring to your cybersecurity, from AI to z. 

 

Richard Hawes is a CISSP‑certified Cybersecurity Consultant at Idenhaus Consulting, specializing in Identity and Access Management (IAM) and Identity Governance and Administration (IGA). With seven years of experience in cybersecurity, he helps organizations design and implement scalable identity solutions that strengthen security and support business objectives. Richard focuses on practical, governance‑driven approaches to access management, delivering value through sound IAM strategy, modern access control practices, and identity program development.

More News

Subscribe To Our Newsletter

Please send me the following content from Idenhaus:*
Select as many boxes as you'd like!
Idenhaus needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.