Identity Briefing.
Identity AttacksAI & Agent IdentityAuthenticationStandards & RegulationVendor MovesCommunity & Events
community & events · ai & agent identity

Four takeaways from the New York Identity Summit

Thirty per cent of enterprise applications never reach the IDP, only half the room could prove who has access to what, and session timeouts are quietly doing more damage than step-up prompts.

Over 200 identity leaders joined us in New York for the Identity Summit this fortnight. Thanks again to the Identity at the Center team and the Identibeers crew, who both did a great deal to make the day work.

The event is run by Clutch, the publisher of Identity Briefing, so apply the appropriate scepticism to our view of how it went. The four findings below are worth your time regardless of who hosted the room, because most of them came from surveying the practitioners in it rather than from the stage.

1. Roughly 30% of enterprise applications are disconnected from the IDP

Our session found that around 30% of enterprise applications sit outside the identity provider entirely, averaging about 80 disconnected applications per organisation.

It gets worse. Most organisations in the room still manage at least 20% of their applications manually, through the help desk and over email. That is not an integration backlog, it is a parallel access management system with no logging, no lifecycle and no owner.

The blind spot has always been there. What has changed is who is looking into it. As AI agents proliferate and prompt injection becomes a practical technique, every disconnected application becomes a route into the estate that your joiner-mover-leaver process has never touched.

An application the IDP has never heard of cannot be reviewed, cannot be de-provisioned, and will not appear in the evidence you hand the auditor.

The direction of travel for most teams is extending the identity stack out to those disconnected applications rather than waiting for each one to grow a SCIM endpoint. The alternative is accepting that a fifth of your access decisions live in a ticket queue.

2. NYDFS is now asking about NHI inventory and ownership lineage

Our panellists' lived experience is that NYDFS regulators have moved past asking whether you have a policy for non-human identities and are now asking for the inventory and the ownership lineage behind it.

When we surveyed the room, only 50% felt even somewhat confident they could prove who had access to what if asked tomorrow. That is the number worth sitting with. Half the identity leaders in a room of large enterprises were not confident they could evidence their own access model on demand.

Two things follow. The first is the obvious one: get audit ready, and build the security programme to the strictest requirement across all the regions you operate in rather than maintaining a different posture per jurisdiction.

The second is less obvious and more useful. Look at where those regulations are likely to be in three to five years and build towards that instead. NHI inventory was not a supervisory priority two years ago. Assume the same trajectory applies to agent identity.

3. Capital One's NHI remediation framework

Nader Nassar of Capital One gave a keynote walking through his NHI remediation framework. Three components stood out.

  • An enterprise-wide registry of identities. One list, covering everything, rather than a per-platform view that nobody can aggregate.

  • A trust tier per identity. Low risk, elevated risk or high risk, with guardrails attached to each tier rather than negotiated case by case.

  • Clear ownership with a chain of custody. This was the part Nassar pressed hardest on, and it is the part most frameworks skip.

The chain of custody matters because it assumes failure. If one person misses something, the next responsible layer catches it. A framework that only works when every owner does their job is not a framework, it is an aspiration with a diagram.

We are running our Identity Leaders Network virtual roundtable on this exact topic this month, in two timezones.

4. Step-up prompts cause the complaints. Session timeouts cause the abandonment.

We surveyed the audience on user friction. Step-up and re-authentication prompts were the top source, with legacy technology named as the biggest barrier to fixing it.

The panellists' experience was more specific, and more interesting. The thing actually driving abandonment right now is session timeouts, not step-up prompts. Users complain about the prompt they can see. They quietly give up on the session that expired while they were in a meeting.

The recommendation from the panel was to stop setting these arbitrarily. A 15-minute timeout because an auditor once said 15 minutes is not a control, it is a number in a policy document. Build the timeout dynamically from context, device trust and the user's risk profile, and you can usually lengthen it for most of the population while tightening it for the cases that warrant it.

What to take back to your own programme

  1. Count your disconnected applications. Not estimate. Count. If the number is near 80 you are normal, which is the problem.

  2. Try to prove who has access to what, today. Give yourself the exercise before a regulator does. Half the room could not.

  3. Check whether your NHI framework survives one person missing something. If it does not, you have owners but no chain of custody.

  4. Find out where your session timeout number came from. If nobody can tell you, it is a candidate for being rebuilt on context rather than folklore.

Session slides

The full set of slides from the New York Identity Summit sessions, including the disconnected applications research and the NHI remediation framework keynote, is available to download.

Get Identity Briefing

Independent analysis for identity practitioners. Fortnightly and free.

Join identity architects, IAM leads and security leaders worldwide.