Artificial intelligence (AI) driven enhancements, increased vendor scrutiny and a slowdown in biometric adoption are among the top 10 trends Forrester has identified for the identity access management (IAM) market this year.

“Our report highlights deepening alignment of identity and cybersecurity as organizations wrestle with identity-centric threats in more complex and dynamic IT environments, seeking commercial IAM solutions that can keep pace,” Geoff Cairns, report co-author and Forrester Principal Analyst, said in a statement.

“Not surprisingly, AI is a significant factor, impacting the 2024 trends we see for shoring up the underlying security of IAM platforms, allowing deeper insights to identities and entitlements, and advancing detection of identity-based threats, even as the proliferation of genAI [generative AI]-aided deepfakes disrupt biometric adoption.”

AI enhances identity-based threat detection and remediation

The report emphasizes that IAM staff shortages have hampered organizations' abilities to respond to identity threats and implement zero-trust architectures based on least privilege. GenAI is set to address this challenge.

The technology, building on proven machine learning models, can help organizations identify threats in on-premises applications, software-as-a-service (SaaS) applications and cloud infrastructure platforms. Then, not only can it automatically generate identity and access policies to mitigate these threats; but then gain easy and natural language-based access to IAM systems for queries and reporting, Forrester noted.

“Identifying new threats and generating policies are already on many IAM vendor roadmaps; we expect these to be available from mid to late 2024,” analysts wrote.

They recommend security teams ask their IAM vendors for detailed information regarding the genAI technologies they employ, the accuracy of their algorithms, and easy to obtain or interpret reason codes that sit behind genAI’s responses.

Increased scrutiny of IAM vendors

Another trend Forrester identified is the heightened scrutiny of IAM platforms' underlying security.

The firm pointed out that several high-visibility breaches last year involved targeted IAM vendor platforms like Okta. This has driven organizations to demand more assurances from vendors about their internal operational processes and security practices.

Now, IAM vendors are expected to comply with regulations and frameworks such as Service Organization Control Type 2 (Soc 2 Security Standard), the Federal Risk and Authorization Management Program (FedRAMP) and ISO 27002.

“As IAM vendors’ servicing and operations are linked to their platform security posture and, ultimately, customer trust, we expect them to strengthen their contact center/help desk authentication measures in 2024,” the report wrote.

Forrester recommends security and risk professionals demand multifactor authentication (MFA) for all workforce business and admin users, while prioritizing IAM vendors that adhere to secure-by-design and secure-by-default principles and value two-way customer engagement to improve their overall cybersecurity posture.

Biometric adoption slows down due to deepfake concerns

Despite the widespread adoption, users started to be increasingly concerned about the use of biometric authentication due to AI-aided deepfake attacks.

While advanced features like liveness detection in facial and fingerprint recognition systems have maintained a fairly high standard against spoofing, voice biometrics have proven to be more vulnerable.

To address these concerns, “vendors will add additional deepfake detection to their solutions in 2024, resulting in a rebound in biometrics adoption in 2025,” Forrester analysts expect.

They suggest organizations that rely on voice biometrics for authentication to augment extra technical and/or procedural steps that provide defense in depth, particularly focusing on fraud prevention during enrollment.

Other noteworthy trends

Other IAM trends made to Forrester’s top 10 list for this year include the following:

  • IAM and non-IAM vendors respond to identity-centric threats.
  • FIDO passkey authentication goes mainstream for the workforce and business-to-consumer uses.
  • Identity management and governance (IMG) and product information management (PIM) vendors expand coverage of cloud administrator identities.
  • Government-issued digital identities continue to spread.
  • Business-to-business IAM becomes a differentiating feature.
  • Commercial and homegrown IAM solutions face a growing demand for upgrades.
  • The fine-grained authorization market is heating up.