Identity security answers one question, continuously and at enormous volume: should this actor be allowed to do this thing, right now. For thirty years the actor was a person. That assumption is being dismantled, and the industry is repricing itself around the consequences.
This report covers what identity security is, what the money looks like, what the threat data actually says as opposed to what vendors say it says, what has genuinely shipped in agent identity, where the standards sit, and the four structural debates that will decide which vendors matter in five years. Where a number is a vendor survey rather than an independent estimate, it is labelled as such. There is a good deal of that in this sector.
What it is
Identity and access management is the digital equivalent of a security guard on a building. It establishes who someone is, confirms they are allowed in, constrains what they can do once inside, and keeps a record of their movements. Four functions, in sequence: identification, authentication, authorisation, and audit.
Around that core sit the disciplines the industry sells as separate products. Single sign-on lets a user authenticate once and reach many systems. Multi-factor authentication adds a second proof. Directory services hold the authoritative record of who exists. Federation extends trust across organisational boundaries. Identity governance and administration manages the lifecycle at scale and proves least privilege to an auditor. Privileged access management protects the small number of accounts that can do catastrophic damage. Identity threat detection and response watches for the abuse of credentials that were legitimately issued.
A worked example makes the layering concrete. An analyst at a bank opens a research portal from a hotel in Germany. The directory holds his role and division. Single sign-on authenticates him once and carries him into the portal, the terminal and the collaboration suite. Because the location and network are unfamiliar, conditional access forces a step-up challenge. Device posture is checked, and because he is on untrusted wifi he is granted read access to research but blocked from the trading databases. When he needs a sensitive model held in a restricted repository he requests it through privileged access management and receives it for one hour, recorded and logged. Quarterly, his manager certifies that he still needs everything he holds. Every step generates telemetry that lands in the security operations platform.
Six vendors touch that single session. That fragmentation is the commercial reality of the sector and the reason consolidation is the defining theme.
How the money works, and what nobody can tell you
industry research most recent forecast puts worldwide end-user spending on information security at two hundred and forty-eight point nine billion dollars in 2026, growing twelve point seven per cent in constant currency, reaching three hundred and seventy-two point six billion by 2030. industry research number for 2026 exceeds three hundred billion, because industry research uses a broader taxonomy. The two should never be blended.
What is not available is a credible public figure for identity’s share of that. industry research releases its forecast to the press at a three-way split of security software, security services and network security. Identity is not broken out, and no sub-segment has a publicly attributable industry research dollar figure: not access management, not governance, not privileged access, not customer identity, not threat detection, not entitlement management, not machine identity. The granular numbers circulating in trade coverage come from commissioned research houses whose methodologies are undisclosed and whose estimates routinely differ by a factor of two or three.
The one identity-specific figure in general circulation puts spending above twenty-four billion dollars in 2025, growing around thirteen per cent, which would make identity roughly eleven per cent of information security spend and growing marginally faster than the market. It carries no named analyst attribution and should be treated as unverified. If it is broadly right, it is worth noting what it implies: identity is taking share slowly, not explosively. The claim that identity is eating security is not supported by segment data. It is supported by where acquisition money and product launches are going, which is a different claim and should not be conflated with the first.
The machine-to-human identity ratio, quoted everywhere, is entirely vendor marketing. CyberArk’s 2025 survey of two thousand six hundred decision-makers produced eighty-two to one. Palo Alto used one hundred and nine to one at the Idira launch in May 2026. Analysis of the Cyera acquisition of Oasis cited one hundred and forty-four to one. The figure inflated by seventy-five per cent in about fifteen months with no methodological continuity disclosed. The direction is real. The precision is theatre.
Agent-count forecasts deserve the same scepticism. industry research projects more than a billion agents deployed by 2028; Microsoft’s own research predicts one point three billion. Against which industry research predicts that over forty per cent of agentic AI projects will be cancelled by the end of 2027. Both belong in any honest model.
What the threat data actually says
The 2026 Verizon Data Breach Investigations Report, published in May 2026 and covering November 2024 to October 2025, analysed more than twenty-two thousand confirmed breaches, roughly double the prior corpus. It contains a finding that cuts against the standard identity pitch, and the sector has been quiet about it.
Credential abuse is no longer the leading initial access vector. Vulnerability exploitation is, at thirty-one per cent, up from twenty per cent. Phishing is sixteen per cent. Credential abuse has fallen to thirteen per cent from twenty-two. Handle that delta carefully: Verizon changed its taxonomy, splitting out pretexting as a separate six per cent category and reclassifying some credential-driven social engineering, so the true decline is smaller than the headline suggests.
The number that rescues the identity thesis is different and more interesting. Credentials appear as the initial access vector in only thirteen per cent of breaches, but appear somewhere in the chain in thirty-nine per cent. Identity has become a lateral movement and persistence problem rather than a front-door problem. That matters commercially, because it moves budget away from authentication and towards threat detection, posture management and session integrity.
The rest of the report reinforces the point. Ransomware featured in forty-eight per cent of breaches. Seventy-three per cent of ransomware victims had an associated infostealer or credential-leak event beforehand, and half had one within ninety-five days. Third-party involvement reached forty-eight per cent, up from thirty per cent, a sixty per cent year-on-year jump. Only twenty-three per cent of third parties had fully remediated missing or improperly configured multi-factor authentication, and thirty-seven per cent of infrastructure administrator accounts had it disabled entirely. Forty-one per cent of social engineering now arrives through channels other than email, with voice phishing showing roughly forty per cent higher success than email.
One statistic deserves separate mention because it quantifies a problem the industry has been describing anecdotally: forty-five per cent of employees are now regular AI users on corporate devices, up from fifteen per cent, and sixty-seven per cent of them use non-corporate accounts to do it.
The attack that defines the period
Scattered Spider, tracked variously as UNC3944, Octo Tempest and Roasted 0ktapus, is the reference case. The joint advisory from CISA, the FBI and five international partners, substantially updated in July 2025, reads as a catalogue of every failure mode in the sector: help-desk social engineering to obtain credentials and reset multi-factor enrolment; push-notification fatigue; SIM swapping to intercept one-time codes; lookalike single sign-on domains; attacker enrolment of their own authenticators for persistence.
The most instructive technique is federation abuse. The attacker adds an identity provider they control to the victim’s single sign-on tenant with automatic account linking, and becomes a trusted issuer of identity. No amount of phishing-resistant authentication addresses this, because the authentication is genuine. It is a configuration governance failure, which is precisely why identity security posture management has become a category.
The larger pattern of 2025 and 2026, though, is not attacks on humans at all. Microsoft’s mapping of the ShinyHunters campaign documents three attack paths into Salesforce environments, and the defining one is theft of OAuth tokens belonging to third-party integrations. The compromise of the Salesloft Drift chat integration in August 2025 exposed more than seven hundred organisations. Gainsight followed in November 2025 with over two hundred instances, and Klue in June 2026. Named victims across the campaign include Google, Chanel, Pandora, Adidas, Qantas and Allianz Life.
Nobody phished those companies. Attackers stole the credentials of a machine identity that a vendor had been granted, and walked in through an integration nobody was governing. That is the empirical foundation for everything in the next section, and it explains why seven of the ten identity acquisitions of the past year targeted non-human identity vendors.
The agentic shift: what has actually shipped
industry research devoted two of its six top cybersecurity trends for 2026 to this, naming registration and governance of agent identities, credential automation and policy-driven authorisation for machine actors as the specific gaps. On its 2026 Hype Cycle for Digital Identity, AI agent identity and workload identity management both sit at Innovation Trigger. Identity threat detection and response is the only mature profile on the cycle, at above fifty per cent market penetration.
Separating announcements from products is the useful exercise.
| Vendor | Product | Status as of September 2026 | Commercial terms |
|---|---|---|---|
| Microsoft | Entra Agent ID, inside Agent 365 | GA April 2026; non-Microsoft agent integration still preview | $15 per human user per month; bundled in E7 at $99 |
| Okta | Okta for AI Agents | GA 30 April 2026 | Priced separately, undisclosed |
| Okta | Agent SSO | GA 24 August 2026 | Free, inside core single sign-on |
| Palo Alto | Idira | GA 12 May 2026 | Undisclosed |
| SailPoint | Agentic Fabric | GA 4 August 2026 | Two tiers, undisclosed; free discovery tool |
| CrowdStrike | Agentic Identity Provider | Announced 2 September 2026; unreleased | None |
| Aembit | IAM for Agentic AI | GA 9 April 2026 | $20 per agent per month, 10 to 500 agents |
Three observations follow from that table. Microsoft and Okta are the only vendors with both a shipping product and disclosed commercial terms. CrowdStrike’s release explicitly describes an unreleased service subject to change, with no availability date, no pricing and no named standards, which is an announcement rather than a product. And Aembit, a startup, is the only participant publishing a per-agent price.
The capability set is converging fast. Every serious vendor now offers discovery of agents including unsanctioned ones, an inventory that maps each agent to a human owner, policy governing what it can connect to, short-lived credentials in place of static keys, and a kill switch. The differentiation is not features. It is distribution and price.
Standards, and how provisional they are
The most consequential development of 2026 received almost no coverage. Cross App Access, Okta’s mechanism for brokering agent access through the corporate identity provider, was adopted in June 2026 as the Model Context Protocol’s Enterprise-Managed Authorization extension and shipped as stable. The client obtains an assertion from the enterprise identity provider during sign-on and exchanges it for an access token at the tool’s authorisation server, replacing per-user consent prompts with central governance. Adopters include Anthropic, Microsoft and Okta, with server support from Asana, Figma, Linear and Slack.
The commercial implication is substantial: the enterprise authorisation model for agent-to-tool access now routes through the corporate identity provider by protocol design. That is a structural advantage for whoever owns the directory, and it explains why Okta could afford to give agent single sign-on away with core single sign-on. The protocol wins the seat, and the seat was already sold.
It is worth being precise about maturity, because the sector is not. The underlying mechanism, the Identity Assertion JWT Authorization Grant, is an IETF working group draft at revision four, authored by engineers from Okta and Ping. It is not a published standard. OAuth 2.1, which the Model Context Protocol’s authorisation model specifies, is itself still a draft at revision sixteen, not expected to reach the standards body until December 2026. A considerable amount of shipping agentic infrastructure is built on documents that are not yet standards.
The mature options are older and less fashionable. SPIFFE and SPIRE, which issue cryptographic identity to workloads, graduated from the Cloud Native Computing Foundation in 2022 and run in production at Netflix, Uber, GitHub and Pinterest. They were not designed for delegation chains in which a human principal stands behind an autonomous actor, which is the gap the newer drafts are trying to close. The W3C verifiable credentials family reached full Recommendation status in May 2025, the highest formal standing of anything in this space, and has almost no enterprise deployment for agent identity.
On workforce authentication, the FIDO Alliance’s 2026 survey of eleven thousand consumers and fourteen hundred enterprise decision-makers reports roughly five billion passkeys in use, sixty-eight per cent of organisations deploying them, and the number that matters: eighty-two per cent call passwordless a workforce goal while twenty-eight per cent have achieved it. That gap is the remaining addressable market in authentication, and it explains why phishing-resistant multi-factor authentication is still an active sales motion in year eight of the campaign.
Debate one: does identity consolidate, or does neutrality win
Ten identity acquisitions closed or were announced in roughly seven months: CrowdStrike bought SGNL for around seven hundred and forty million dollars in January 2026; Palo Alto completed CyberArk at twenty-five billion in February; ServiceNow agreed to buy Veza for over a billion; Silverfort took Fabrix; Cisco bought Astrix for a reported four hundred million; Snowflake took Natoma; 1Password bought Apono; SailPoint bought Entro; Cyera paid a reported billion for Oasis; and Okta bought Permiso.
Two patterns in that list are the actual argument. Seven of the ten targets sell non-human, machine or agent identity. And half the acquirers are not identity vendors at all: endpoint, network, workflow, data security and password management. Identity is being bought into other platforms rather than consolidating within itself.
The case for neutrality is not weak, but it is narrowing. Enterprises running one directory for productivity and another for everything else have a genuine requirement no platform vendor can serve, and analysts have begun publishing formal market-concentration concerns about the largest of these deals. The observation that consolidation trades flexibility for convenience is sound. The problem is ownership rather than merit: the neutral players are the ones being acquired. Okta and SailPoint are now the only independents of scale, and one of them has a thin float and a controlling sponsor.
One detail sharpens the picture. In industry research 2025 access management quadrant the leaders are Microsoft, Okta, Ping, IBM and Transmit Security, with CyberArk sitting as a challenger. Palo Alto paid twenty-five billion dollars for depth in privileged access, not breadth in access management. Platform buyers are acquiring point strength, and the integration remains unproven.
Debate two: is governance a category or a feature
The strongest evidence is a fact almost nobody has written about. industry research retired the Magic Quadrant for identity governance and administration and replaced it with a Market Guide, published in 2024 and again in 2025. Analyst firms do that when they judge a market insufficiently differentiated, or maturing out of standalone evaluation. The guide’s own headline finding is that approximately half of governance deployments are in distress: manual process load, poor data quality, disconnected systems.
Alongside it: ServiceNow, a workflow company, bought a governance vendor on the logic that governance is a workflow. Microsoft ships governance as an add-on to a directory customers already own. KuppingerCole has begun running a separate evaluation for lean governance aimed at organisations under a thousand employees, which implies the full product serves only the enterprise tail.
The counter-evidence is financial and hard to dismiss. SailPoint is a business with recurring revenue above one point one six billion dollars growing twenty-six per cent, with cloud recurring revenue growing thirty-six. Features do not compound at that rate at that scale. Saviynt raised seven hundred million dollars at a three billion valuation in December 2025 in a round led by KKR. Institutional capital is pricing governance as a standalone franchise.
The reconciliation is that governance is becoming a feature of platforms while remaining a category of budgets. Identity teams still hold their own line item; the buying centre is migrating toward whoever owns the workflow or the directory. The test is observable: if governance growth at the independents decelerates toward the mid-teens while directory-attached governance adoption climbs, the feature thesis is winning.
Debate three: can agent identities be priced like human seats
This is the best-evidenced debate in the sector, because three vendors have now published three incompatible answers.
Microsoft prices agents per human user, at fifteen dollars a month, with one licence covering every agent a person owns, sponsors, manages or interacts with. Agents are explicitly not a billable unit. Okta gives agent single sign-on away inside core single sign-on and monetises governance separately at undisclosed prices. Aembit charges twenty dollars per agent per month, above a typical single sign-on seat, with the published tier capping at five hundred agents before pricing goes custom.
Per-seat pricing for agents is not at risk of collapsing in future. It has already collapsed, and the evidence is what the two largest vendors put on their own price lists. If ratios are anywhere near even the conservative eighty-two to one, and agents spawn sub-agents as Okta’s own product leadership describes, per-agent pricing at human rates produces invoices no finance director signs.
The open question is whether the replacement model is additive or dilutive. Okta management has floated two candidates, a multiplier tied to human usage and a connection-based model scaling with system integrations, and has said pricing remains experimental. Its guidance assumes agentic products are not meaningful near-term revenue contributors, which is the company telling investors it has not solved this. The bull case is that authorisation events are a far larger pool than seats ever were, which is the metered-infrastructure path rather than the software-seat path. Nobody has yet demonstrated it at scale.
Debate four: endpoint or identity as the control plane
The rhetorical arguments are evenly matched. Identity’s case is that governance must begin with discovery and accountability, that the breach data shows credentials in thirty-nine per cent of chains and third parties in forty-eight, and that the emerging protocols route agent authorisation through the identity provider by design. The endpoint case is that a meaningful proportion of agent activity happens outside any protocol the identity provider can see, and only runtime instrumentation observes it.
The behavioural evidence settles it more usefully than the rhetoric. SailPoint, an identity governance company, shipped endpoint and browser sensors with its agentic product in August 2026. CrowdStrike, an endpoint company, is building an identity provider and paid around seven hundred and forty million dollars for runtime authorisation technology to do it. Two vendors from opposite ends have concluded they need the other end.
So identity is winning the authorisation control plane because the protocols put the directory in the token path, and endpoint is winning the discovery and observability control plane because agents do work the directory never sees. The investable question is not which layer wins. It is which layer’s incumbents can credibly buy the other, and on that test the endpoint and network platforms have moved faster and with far more capital than the identity independents can match.
Who the players are
Access management is led by Microsoft, Okta, Ping, IBM and Transmit Security, with CyberArk a challenger. ForgeRock has disappeared, absorbed into Ping under common private-equity ownership. Governance has no current quadrant; the scale players are SailPoint, Saviynt, Omada, One Identity and Microsoft’s directory-attached product, with Veza now inside ServiceNow. Privileged access is the most stable segment in the sector, led for years by CyberArk, BeyondTrust and Delinea, which is the segment Palo Alto paid twenty-five billion dollars to enter. Customer identity runs through Okta’s Auth0, Ping, Transmit and Microsoft’s external directory. Threat detection is the one mature agentic-adjacent category, with Silverfort, Semperis, CrowdStrike, Microsoft and now Okta’s acquired capability. Cloud entitlement management is dissolving into cloud-native application protection and should not be modelled as a standalone segment.
On disclosed scale: Okta reported revenue of two point nine two billion dollars for the year to January 2026, growing twelve per cent, and eight hundred and five million in its July quarter, growing eleven. SailPoint reported recurring revenue of one point one six billion, growing twenty-six. CyberArk’s final standalone year showed revenue of one point three six billion growing thirty-six per cent against recurring revenue growing twenty-three, a gap that reflects perpetual-to-subscription conversion rather than underlying demand. Microsoft does not disclose directory revenue separately; any figure attributed to it is an estimate.
Most of the interesting vendors are private and disclose nothing. Ping’s last self-reported figure, approaching eight hundred million dollars of recurring revenue, is nearly two years stale. Saviynt discloses a valuation and no revenue. Semperis has announced passing a hundred million. For Delinea, BeyondTrust, JumpCloud, 1Password and Omada there is no publishable figure at all, and the third-party estimator sites that appear to have one do not disclose their method.
On valuation, twenty-five billion dollars for CyberArk against one point four four billion of recurring revenue is roughly seventeen times. Below that, the machine identity acquisitions cluster between one hundred and four hundred million, with two outliers around seven hundred and forty million and a billion. Buyers are paying a very large premium for the category-defining asset and modest prices for everything else, which is the classic shape of a land grab and historically precedes a markdown in the tail.
What to watch
Whether agent pricing settles on metering. Microsoft has priced per human and Okta has priced authentication at zero. If the industry converges on charging for authorisation events or connections rather than identities, the revenue pool is larger than seats; if it converges on bundling, identity vendors have expanded their responsibility without expanding their invoice.
Whether governance growth at the independents holds. Deceleration toward the mid-teens while directory-attached governance climbs would confirm that the analyst community was right to retire the category.
Whether the remaining independents stay independent. The machine identity cohort has been more than halved by acquisition in seven months. Okta and SailPoint are the only scaled neutral players left, and the neutrality argument is worth considerably less if the neutral vendor is owned by a platform.
Whether the protocols hold. A great deal of shipping infrastructure depends on an authorisation grant that is a working-group draft and an OAuth revision that is not expected to be finalised until the end of 2026. Standards processes usually converge. They do not always converge on the version the early implementers shipped.
And whether the agent deployment actually happens. industry research prediction that more than forty per cent of agentic AI projects will be cancelled by the end of 2027 is the single most important counterweight to every forecast in this report. Identity vendors are building for a world of billions of agents. If that world arrives late, the products are early and the revenue is later still.
Bottom line
Identity security is not growing its share of security budgets particularly fast, and the most recent breach data has demoted credential abuse as an initial access vector. Those two facts should temper the more excitable claims made about this sector.
What has changed is the composition of the problem. The dominant identity attack of the past two years was not credential theft from humans but the abuse of tokens issued to machines, and the population of machines is about to increase by orders of magnitude. That is a real structural shift, and it is why every adjacent platform has bought its way into identity in the past twelve months.
The unresolved question is commercial rather than technical. The sector has largely worked out how to discover, govern and constrain autonomous agents; the products shipped this year and they broadly work. Nobody has worked out how to charge for it at a scale that reflects the responsibility. Until someone does, identity will keep becoming more strategically important and not proportionately more valuable, which is a distinction investors in this sector should hold onto.