u/Putrd-Cohemistry-512

▲ 9 r/ciso

Are identity security posture management tools actually useful beyond finding misconfigurations?

finding problems was never the hard part for us. deciding what to fix first with a small team is.

what's changed things for us is having full discovery and mapping feed directly into prioritization, so the tool tells you which of the hundred findings actually raises your risk instead of handing you a flat list. has anyone gotten real prioritization value out of a platform like that, or are you still triaging manually after the scan runs?

reddit.com
u/Putrd-Cohemistry-512 — 2 days ago

How are teams approaching identity attack surface management across disconnected systems?

our identity footprint spans an hr system, three cloud providers, a legacy on-prem directory, and a pile of saas apps that were never centrally provisioned, and none of it talks to any of the others.

mapping the full attack surface across all of that used to be manual, which meant it was already out of date by the time we finished. what's changed is treating discovery as continuous and automatic instead of a quarterly project, so every identity system gets found and folded into one record without someone chasing it down by hand.

what's your process for keeping a current picture of exposure when the systems themselves aren't connected?

reddit.com
u/Putrd-Cohemistry-512 — 2 days ago

IGA tools reviews, anyone happy with their setup for mid size org?

Been tasked with cleaning up our identity governance and access stuff and I feel kind of stuck between vendors rn.

We are a mid size org, mostly Microsoft stack (Entra, M365, a couple on prem AD domains still lingering, plus a bunch of SaaS that all have their own permission models. Current IGA is a mix of manual access reviews in Excel, some homegrown scripts, and ticket based approvals that nobody is really happy with.

Boss wants a real IGA tool so we get proper joiner mover leaver flows, certification campaigns, SoD checks, and cleaner audit trails for the next compliance visit.

So far I’ve looked at SailPoint, Saviynt, OneIdentity, and a couple of smaller cloud first options. Demos always look great, but I’m lowkey worried about:

- how painful the initial role modeling and connector setup is in real life
- whether the access reviews are usable for non technical managers or just another thing they ignore
- how well these tools actually integrate with Entra plus random SaaS apps and not just the big 5 connectors they show in slides

If anyone here has an IGA tool in production that they dont hate, would really appreciate hearing what you picked and how rough the rollout and day 2 has been, especially around access reviews and audit requests.

Appreciate any thoughts.

reddit.com
u/Putrd-Cohemistry-512 — 16 days ago