Glossary · simply explained

IAM (Identity and Access Management)

Identity and access management (IAM) comprises the processes and systems organisations use to manage digital identities and their access rights: creating and deactivating accounts, authentication, granting permissions, roles and regular review.

IAM is the foundation of Zero Trust: when access no longer depends on the network perimeter but on identity and context, the quality of identity management becomes the security boundary. Most successful attacks today start with a compromised identity, not a technical gap.

The building blocks of IAM

It starts with the lifecycle: on joining, accounts and basic rights are created (joiner), on changes they are adjusted (mover), on leaving they are reliably revoked (leaver) — automated from the HR process, not on request. On top sit authentication (ideally via SSO and MFA through a central identity provider) and authorisation: roles and policies decide who may do what.

Evidence and hygiene complete the picture: recertifications regularly check whether granted rights are still needed; orphaned accounts and privilege creep are the typical findings — and popular entry points for attackers.

Where IAM fails in practice

  • Offboarding gaps: accounts of departed employees stay active.
  • Privilege creep: role changes add rights, old ones are never revoked.
  • Shadow identities in SaaS services outside the central directory.
  • Technical accounts without owner, expiry date or monitoring.

Frequently asked questions about IAM (Identity and Access Management)

What is the difference between authentication and authorisation?

Authentication answers who someone is — via password, passkey or MFA. Authorisation answers what that identity may do — via roles, groups and policies. IAM connects both into a controlled, verifiable process.

Why is IAM the basis for Zero Trust?

Zero Trust checks every access based on identity and context instead of network location. That only works if identities are well maintained, strongly authenticated and rights are current — poor IAM turns any Zero Trust architecture into a facade.

What does joiner-mover-leaver mean?

The three lifecycle events of an identity: joining (accounts and basic rights are created), moving (rights are adjusted), leaving (everything is revoked). Automation from the HR process prevents the classic gap: active accounts of people who left.

What is a recertification?

The regular, documented review of granted rights by the responsible business owners: does this person still need this access? Recertifications reduce privilege creep and provide the evidence audits and regulations such as NIS2 or ISO 27001 expect.

How do IAM and PAM relate?

PAM (privileged access management) is the specialist discipline for highly privileged access — admin accounts, root, service accounts. IAM governs the breadth of all identities, PAM secures the critical tip with vaulting, session recording and just-in-time rights.

Open questions about this in your environment? KAEMI advises you in line with your requirements and can also take over ongoing management.