
I’ve been on a number of Identity Governance Administration (IGA) engagements and at each one I have witnessed an ongoing tension between IGA and IT Service Management (ITSM). To ground this discussion, let’s clarify the key terms. Identity Governance Administration, a critical subset of Identity and Access Management (IAM), is a suite of tools and methodologies that manage and control access rights across the different systems and applications within an organization. Its focus is security by way of ensuring appropriate user access at all levels on an ongoing basis and compliance. IT Service Management (ITSM), on the other hand, is a set of processes and tools that manage and deliver IT services to users, streamlines workflows, and administers service requests across an organization. It prioritizes user experience and centralizing operations to create a unified interface for IT services. Right away one can imagine the ways in which these two things can overlap.
The Lure
ITSM (especially ServiceNow) is a near-universal presence in enterprises, often representing a prior investment so massive that it shapes IT strategy. I’ve seen IAM directors get frustrated as the Identity Governance program they’ve been tasked with developing at their organization is slowly supplanted by ITSM functionality. This is usually for understandable reasons. ITSM practices are often quite mature by the time an enterprise embarks on a full scale IAM/IGA program. It provides a centralized user experience (“a single pane of glass”) that leaders are leery of disrupting, and there are usually already identity request-related workflows in place because of the flexibility ITSM offers. It is a tough ask for leaders and ITSM teams to replace something that, in their eyes, works. When compared with the costs of a new implementation, all this makes ITSM a time and cost-saving shortcut in some cases. Despite all this, over-relying on ITSM for identity tasks erodes IGA’s long-term value, reduces ROI, and introduces security risks.
The Consequences of Undermining IGA
Expensive, built-for-purpose IGA suites are underutilized when features like automated provisioning, role management or compliance workflows are sidelined. Despite their flexibility, these are costly, support-intensive, and sometimes incomplete features when built in ITSM, even if some already exist. ITSM lacks IGA’s robust controls for audits such as segregation of duties and access certifications, increasing regulatory exposure when the enterprise has decided to make the investment in IGA to reduce it. While tempting from a front-end cost perspective, keeping and extending identity-workflows in ITSM will slowly result in fragmented identity processes that can create blind spots like missed or delayed deprovisioning, defeating one of the most critical purposes of IGA. Furthermore, not consolidating identity governance processes into IGA foregoes data for advanced capabilities like role mining, analytics, and event/condition-based alerting. When these are left untapped, none of their benefits for identity security can be fully realized.
I want to reiterate that the lure of ITSM is well-founded, and given its purpose and position in the enterprise, fronting IGA with ITSM is often the right decision. It will ease the transition to a functional and scalable IGA program while keeping a streamlined and familiar user experience, reducing training and keeping valuable integrations with broader IT processes. It is important to ensure that these benefits do not come at the cost of security and governance depth, as ITSM can’t match IGA’s core features.
Find the Balance Between IGA and ITSM
There are things that IGA program owners and IT leadership can do to ensure that encroachment of ITSM into identity security and governance territory doesn’t go too far.
IAM teams often lack the clout to resist the institutional push for ITSM dominance, but over-relying on it undermines IGA’s ROI and security benefits. Seemingly small, incremental, cost-benefit decisions to route identity tasks through ITSM will accumulate, eroding IGA over time. Enterprises must strategically integrate IGA and ITSM, using identity best-practices and remembering why they decided to do IGA in the first place to protect their investment and realize its goals. With clear boundaries and advocacy, organizations can maximize both platforms’ strengths without sacrificing security or compliance.
Still looking for more guidance on cybersecurity issues? Talk to the experts at Idenhaus today to get those questions, and more, answered asap.