Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

A Simpler Way We Release and Support Every Product

A plain-language look at our new release and support policy — and what it means for you, no matter which product you run. For customers and partners, release and support practices have not always been easy to interpret. Different products used different terms for similar things — major and minor releases, patch releases, hotfixes — which made it hard to know which release to adopt, how long it would be supported, or whether a given update added functionality or only fixed something.

Rethinking identity security in the agentic AI age

Identity security conversations often arrive at the same unfortunate scenario: a stolen token and breach only discovered once major damage is done. Experts Rob Kraczek, global strategist at One Identity, and Chris Ray, field CTO of security and risk at GigaOm, recently unpacked why 3 a.m. token theft has become less exception, more routine — among other things.

How Active Roles by One Identity supports IAM in a university environment

Managing user accounts, permissions and security access across a university environment involves significant administrative work. For institutions that rely on Microsoft Active Directory, keeping that infrastructure organized, secure and current can quickly become resource-intensive as student and staff populations shift each semester. This type of challenge grows when IT teams must handle onboarding, access changes and offboarding manually for each individual.

Best practices: How to implement Kerberos authentication correctly in your AD environment

Authentication configuration issues, especially those tying into Kerberos, are a big call driver for the Active Roles by One Identity Support team. When Kerberos requirements are met, Integrated Windows Authentication typically attempts Kerberos before falling back to NTLM. Due to expected IIS functionality, we will see multiple HTTP requests which trigger authentication repeatedly.

PAM ROI: Modern privileged access management pays for itself

Privileged access management (PAM) is one of the clearest ways to reduce identity-based risk and demonstrate security value. But ROI depends on more than simply deploying a PAM tool. Organizations need a solution that can be implemented efficiently, managed without unnecessary operational burden and scaled in a way that supports long-term cost control. For organizations evaluating PAM investments, these factors matter.

EMEA compliance just made sovereign cloud mandatory

For years, sovereign cloud was basically a data center pin on a map. A vendor would point at Frankfurt or Paris and call it a day. That pitch doesn’t work anymore, and it stopped working fast. Between late 2024 and late 2025, the EU passed three separate rules that turned sovereignty from a talking point into something organizations now have to prove, on a schedule, with documentation, to a specific regulator.

How identity sprawl is quietly expanding your attack surface

No city is designed to become complex. It starts with a simple plan with a handful of streets and a few neighborhoods. Then it grows. New districts appear, roads extend, bridges get built and temporary solutions slowly become permanent. As cities grow, complexity compounds, perhaps because that growth was never planned for. Identity environments follow the same pattern.

Your AD is a stomping ground for lateral movement

Active Directory (AD) is the backbone many enterprises lean on for their IT environments. Yet, most organizations rarely govern the directory with the scrutiny necessary. This was the throughline of a recent webinar with Nitish Deshpande, senior analyst at KuppingerCole, and Robert Kraczek, global strategist at One Identity. The pair made a strong case for mediating admin access to AD, emphasizing just how easily compromised credentials can beget full-blown incidents.

KuppingerCole names One Identity a leader in non-human identity management (NHIM)

Non-human identity management (NHIM) is the governance and security of machine, application, and service identities through standardized authentication, authorization and lifecycle controls. These identities often have elevated privileges, making them prime targets for exploitation, especially when left unmanaged. Effective NHIM reduces risk, strengthens compliance and ensures operational resilience. KuppingerCole notes:“One Identity solutions address all major NHIs.

How to prevent chaos in the Microsoft AD estate: A quick-start guide to reduce risk and administrative burden in medium-sized regulated businesses

If you work in IT for a medium-sized regulated business, you already know the truth: Your Microsoft environment didn’t become sprawling overnight. It grew through mergers, acquisitions, divestitures, reorganizations and the natural evolution of a business that’s constantly adapting. Every new business unit brought its own domain. Every acquisition added another tenant. Every project introduced new accounts, groups and privileges.