Vendor category

Identity and Access Management vendors

Identity vendors control authentication and authorization for your systems and potentially your customers' systems. A compromise of an identity vendor is a compromise of everything that vendor protects.

Risk profile for this category

Extremely high security criticality. Identity providers are the keys to everything. A compromised IdP gives attackers access to every system that trusts it. Require SOC 2 Type II, ISO 27001, and rigorous review of their own security posture.

Sample vendors in this category

Okta

okta.com

SOC 2 Type II, ISO 27001, FedRAMP High.

View profile →

Auth0

auth0.com

SOC 2 Type II, ISO 27001, HIPAA BAA.

View profile →

Microsoft Entra ID

microsoft.com

SOC 2 Type II, ISO 27001, FedRAMP High.

View profile →

This is a sample of vendors in this category. Search the full TrustVendor graph for comprehensive coverage including posture scores, certifications, and subprocessor counts.

Search all Identity and Access Management vendors →

Common questions

The Okta 2022 breach — what happened and what lessons apply?
In 2022, a threat actor gained access to Okta's support case management system via a subcontractor. This exposed some customer data. The key lessons: vendor breach notification timeliness matters (Okta was criticized for delays), subcontractor access controls are part of your vendor's attack surface, and identity providers require the same scrutiny as any critical system.

Monitor your Identity and Access Management vendors.

Get continuous posture scores, subprocessor monitoring, and certification tracking for every Identity and Access Management vendor in your portfolio.

Book a demo