Executive Summary
Identity & Access Management (IAM) secures who can sign in, how strongly they prove it, and what they access, acting as the enterprise’s primary control plane. Choosing an IAM platform involves balancing breadth versus depth of fit, considering factors like authentication, single sign-on, the joiner-mover-leaver lifecycle, and identity threat detection, across platforms such as Okta, Microsoft Entra ID, and SailPoint.
Identity is the new perimeter — which means your IAM platform is no longer a convenience layer over the network, it is the control plane an attacker has to beat first.
Workforce IAM secures the people and machines you run your business with — employees, contractors, service accounts, and now the AI agents acting on their behalf. It decides who can sign in, how strongly they prove it, what they get access to the moment HR hires them, and how fast that access disappears the day they leave. When the corporate network stopped being a meaningful boundary, identity became the boundary, and the login became the single most attacked surface in the enterprise. The hard part is no longer issuing credentials; it is making authentication phishing-resistant for tens of thousands of users without turning every morning sign-in into a fight.
This guide provides a vendor-neutral framework for evaluating 8 leading workforce IAM platforms — Okta Workforce Identity Cloud, Microsoft Entra ID, Ping Identity, CyberArk, SailPoint, IBM Verify, Oracle Access Management, and JumpCloud — across the forces that actually decide a deployment: authentication and single sign-on, the joiner-mover-leaver lifecycle, identity threat detection, and the move to passkeys and phishing-resistant multi-factor authentication. It is written for CIOs, CISOs, and the identity architects who have to make those choices stick across a real application estate.
The single hardest trade-off in this category is breadth versus depth of fit: the neutral best-of-breed platform that integrates with everything rarely also owns your directory, your endpoints, and your network the way an ecosystem incumbent does — and the incumbent that is already in your tenant rarely matches the specialist on connector coverage or non-native apps. This guide deliberately keeps to workforce identity; consumer login, deep governance, and privileged access are adjacent disciplines with their own guides, cross-linked throughout, because pretending one platform is equally excellent at all four is how IAM programs overspend and underdeliver.
Why Workforce IAM Is a Board-Level Priority
Workforce Identity & Access Management (IAM) is a board-level priority because it directly impacts breach risk and operational efficiency. Most intrusions begin with valid credentials, making strong authentication critical. Simultaneously, IAM systems gate onboarding, contractor access, and mergers, meaning slow or brittle platforms cause significant delays. The strategic impact is visible at the top of the house.
Workforce IAM is consequential because it sits on the critical path of two things a board cares about at once: breach risk and the ability to get work done. The overwhelming majority of intrusions now begin with a valid credential rather than an exploit — phished, stolen, replayed, or socially engineered from a help desk — which makes the strength and resilience of your authentication the difference between a blocked attempt and an incident. At the same time, the same system gates onboarding, contractor access, mergers, and divestitures; a slow or brittle IAM platform shows up as new hires idle for a week and as access that lingers months after someone leaves. Get it wrong in either direction and the cost is visible at the top of the house.
The 2026 reality is that the identity estate spans far beyond a directory of employees. Workforce platforms are being asked to issue scoped, short-lived credentials to first-party APIs and to the agentic systems now acting inside business workflows, and to govern those machine identities with the same rigor as human ones — lifecycle, least privilege, and revocation. Treat machine and agent identity as a first-class evaluation axis, because it is where the next wave of access risk is concentrating and where most incumbent tooling is thinnest.
The other defining shift is consolidation of the control plane. Buyers are tired of stitching together a separate SSO tool, MFA tool, lifecycle engine, and threat-detection product, and vendors are responding by folding authentication, governance signals, and ITDR into a single identity-security fabric. That convergence is real, but it sharpens the central decision rather than dissolving it: the more the platform becomes the perimeter, the more its own resilience, blast radius, and breach history matter — because when identity is the security architecture, an outage or compromise of the IAM platform is no longer an inconvenience, it is the incident.
Should you build or buy Identity & Access Management (IAM)?
For workforce Identity & Access Management, you should buy, not build, due to the complexity of protocols like SAML, OIDC, SCIM, and FIDO2/WebAuthn, and the constant attacker attention. The real decision is whether to modernize a legacy on-prem directory, extend an existing ecosystem like Microsoft 365’s Entra ID, or consolidate a sprawl of overlapping identity tools into one control plane. Each strategy carries distinct risks and costs.
Building your own workforce IAM is, for almost everyone, a settled question — you buy. The protocols (SAML, OIDC, SCIM, FIDO2/WebAuthn), the connector maintenance, the passkey edge cases, and the attacker attention make a home-grown identity platform a permanent security liability rather than a project. The live decision is not build-versus-buy; it is which posture to take among three: modernize off a legacy on-prem directory, extend the ecosystem suite you already own, or consolidate a sprawl of overlapping identity tools into one control plane. Each is a real strategy with a different risk profile, and the wrong choice is expensive precisely because IAM touches every application and every user.
The honest tension is gravity versus neutrality. If you live in Microsoft 365, Entra ID is already in your tenant and the marginal cost and friction of using it are low — but you inherit Microsoft’s pace and priorities for non-Microsoft apps. If your estate is genuinely heterogeneous, a neutral best-of-breed platform earns its premium in connector coverage and policy depth — but you are now running a strategic system that is not your cloud provider’s. There is no badge that resolves this for you; the table below frames the scenarios where each posture is defensible, and the most common failure is choosing on license economics alone and discovering the integration and governance gaps a year into rollout.
| Scenario | Recommendation | Rationale |
|---|---|---|
| Legacy on-prem directory (Active Directory / LDAP) with no cloud identity layer | Buy & modernize | Move to cloud-delivered IAM with a hybrid agent bridging to AD during coexistence. The goal is a single authoritative identity and phishing-resistant MFA across cloud and on-prem apps, not a lift-and-shift of the old directory. |
| Fragmented identity stack with four or more overlapping tools (SSO here, MFA there, lifecycle scripts elsewhere) | Consolidate | Collapse the sprawl onto one control plane to close the seams attackers exploit and to make lifecycle and certification consistent. Sequence the retirement carefully — consolidation fails when the old tools are switched off before the new policies are proven. |
| Deep Microsoft 365 estate, mostly Microsoft-native apps and Windows endpoints | Extend the incumbent suite | Entra ID P1/P2 plus the Entra Suite may already cover SSO, conditional access, and lifecycle. Pressure-test non-Microsoft app coverage and governance depth against a specialist before assuming the native tooling is enough. |
| Heterogeneous, multi-cloud estate with many SaaS and custom apps and no single dominant vendor | Buy neutral best-of-breed | A vendor-neutral platform with the broadest connector catalog and strongest policy engine pays for itself in integration breadth and avoids tying your security perimeter to one cloud provider’s roadmap. |
| Privileged access is the headline risk — admins, infrastructure, secrets, and standing entitlements | Pair IAM with PAM | Workforce IAM handles broad authentication; it is not a substitute for vaulting, session isolation, and just-in-time elevation. Treat privileged access as a distinct program and integrate, rather than stretching SSO to cover it. |
| SME or lean mid-market with mixed Windows/Mac/Linux devices and no AD legacy worth keeping | Buy a unified directory + device platform | An open directory that bundles IAM and device management replaces the AD-plus-SSO-plus-MDM stack at a scale where a full enterprise suite is overkill. Verify governance and connector depth match your compliance obligations. |
How do you evaluate Identity & Access Management (IAM)?
To evaluate an Identity & Access Management (IAM) solution, prioritize capability domains based on your organization’s specific needs, rather than a feature checklist. Key areas include Authentication & SSO (30%), Lifecycle & Provisioning (20%), Directory & Hybrid Architecture (15%), Identity Threat Detection & Response (15%), Machine & Agent Identity (10%), and Deployment, Integration & Commercial Fit (10%). Focus proof-of-concepts on your most challenging applications and populations, like legacy systems or contractors, to assess real-world effectiveness.
Weight these domains against your own estate before you score a single vendor, because a Microsoft-centric enterprise, a heterogeneous multi-cloud shop, and a regulated bank with a mainframe will rank them very differently. The framework below forces an explicit trade rather than a feature checklist — the platform that wins is the one strongest in the domains that carry the most weight for you, not the one with the longest aggregate feature list. Note that deep identity governance and privileged access appear here as integration points rather than primary weights; they are adjacent disciplines with their own guides, and a workforce IAM platform should connect to them cleanly rather than pretend to replace them.
| Capability Domain | Weight | What to Evaluate |
|---|---|---|
| Authentication & SSO | 30% | Phishing-resistant MFA and passkeys/FIDO2 as first-class methods, device-bound credentials, SAML/OIDC/WS-Fed breadth, adaptive and risk-based step-up, device trust, session management and continuous evaluation, and graceful fallback and recovery that does not become the help-desk attack vector |
| Lifecycle & Provisioning | 20% | HR-driven joiner-mover-leaver automation, SCIM and LDAP provisioning, depth and maintenance of the application connector catalog, self-service access requests, fast and reliable deprovisioning, and handling of contractors, partners, and seasonal populations |
| Directory & Hybrid Architecture | 15% | Universal/cloud directory, coexistence with on-prem Active Directory and LDAP, hybrid agents and write-back, multi-domain and multi-forest support, data residency options, and the resilience and blast radius of the directory as a revenue-critical dependency |
| Identity Threat Detection & Response (ITDR) | 15% | Post-authentication risk evaluation, session and token-theft detection, anomaly and impossible-travel signals, identity security posture (dormant accounts, over-privilege, MFA gaps), and how cleanly signals flow to and from the SIEM/XDR and trigger automated response |
| Machine & Agent Identity | 10% | Issuance of scoped, short-lived credentials for service accounts, workloads, and first-party APIs (OAuth client-credentials, workload identity federation), discovery and governance of non-human identities, secrets handling, and emerging support for AI-agent identities acting on a user’s behalf |
| Deployment, Integration & Commercial Fit | 10% | Pre-built connectors for your actual top applications (verified, not catalog-counted), migration tooling and coexistence, API and SDK quality, administrative usability, the pricing unit relative to your user and machine population, and the realism of support and professional services |
Which vendors lead in Identity & Access Management (IAM)?
Consider vendors based on their primary approach: Okta for neutral best-of-breed integration, Microsoft Entra ID for Microsoft-centric ecosystems, Ping Identity for orchestration depth, CyberArk (Palo Alto Networks) for identity security, and SailPoint for governance. JumpCloud serves the mid-market by unifying IAM and endpoint management. Recent ownership changes, like CyberArk joining Palo Alto Networks, impact vendor strategies.
| Vendor | Positioning | Best for |
|---|---|---|
| Okta Workforce Identity Cloud | Leader — Neutral Best-of-Breed | Heterogeneous, multi-cloud enterprises that want a vendor-neutral identity control plane and the broadest connector coverage |
| Microsoft Entra ID | Leader — Microsoft Ecosystem | Microsoft-centric organizations that want identity, conditional access, and security unified inside the stack they already run |
| Ping Identity | Leader — Orchestration Depth | Large enterprises with complex, high-assurance workforce and partner identity journeys and an appetite for orchestration-driven customization |
| CyberArk (Palo Alto Networks) | Leader — Identity Security | Security-led organizations that want workforce access governed with the same least-privilege rigor as their privileged accounts |
| SailPoint | Strong — Governance-Anchored | Regulated enterprises that need deep identity governance layered over their chosen workforce authentication platform |
| IBM Verify | Strong — Hybrid & Regulated | Large, regulated, hybrid enterprises — especially IBM-stack and mainframe estates — needing identity that reaches deep legacy systems |
| Oracle Access Management | Strong — Oracle Stack | Oracle-centric enterprises standardizing workforce access around OCI, Oracle Database, and Fusion applications |
| JumpCloud | Challenger — Unified Directory + Device | SME and mid-market organizations wanting unified identity and device management in one platform without the AD-plus-Okta-plus-MDM sprawl |
The workforce IAM field sorts into camps that explain most of the shortlist before any feature is scored. The neutral best-of-breed platforms — led by Okta — win on integration breadth and independence from any one cloud. The ecosystem incumbents — Microsoft Entra ID, and Oracle for Oracle-stack estates — win on gravity, because they are already in the tenant and bundled into the agreement. The identity-security-led vendors — CyberArk and Ping — approach workforce access from a security and orchestration heritage rather than a directory one. The governance-anchored player, SailPoint, comes at identity from compliance and pairs with a workforce IdP rather than replacing it. And the unified directory-plus-device challenger, JumpCloud, serves the mid-market and SME by collapsing IAM and endpoint management into one platform. Naming the camp first matters more than the feature grid, because most real shortlists end up comparing across camps.
Recent ownership moves reshaped the field and you should price them in. CyberArk is now part of Palo Alto Networks — the roughly $25 billion acquisition announced in July 2025 closed on 11 February 2026 — folding identity security into a platform security vendor. Ping Identity remains Thoma Bravo–owned and, after acquiring ForgeRock in 2023, has combined the two: PingAM and PingIDM (the former ForgeRock engines) now sit under the Ping brand alongside PingOne and its DaVinci orchestration. SailPoint returned to the public markets in February 2025 after Thoma Bravo took it private in 2022, though Thoma Bravo retained majority control at the IPO. And IBM Security Verify has been renamed: the on-prem access manager is now IBM Verify Identity Access. Verify current ownership, product naming, and roadmap directly with any vendor before you sign — in this category the labels move faster than the contracts.
Okta Workforce Identity Cloud
Leader — Neutral Best-of-BreedNeutrality is the product, and its own breach history is the thing to press on: the Workforce Identity Cloud pairs the deepest third-party application integration network with strong adaptive MFA, the FastPass and passkey path to phishing-resistant sign-in, and Universal Directory as a vendor-agnostic backbone, with Identity Threat Protection — built on the 2024 Spera acquisition — adding post-authentication risk evaluation and session revocation, from a consistent Gartner Access Management Leader. Pricing climbs as you stack SSO, MFA, Lifecycle, and governance, and scales with user count. Native governance and privileged access are lighter than the specialists’, and the 2023 support-system compromise means its identity hygiene and blast radius deserve direct scrutiny.
Microsoft Entra ID
Leader — Microsoft EcosystemThe strongest value when you already own it, and the licensing is where the surprises live: formerly Azure AD, Entra ID is the default identity layer for Microsoft 365 estates, with Conditional Access as a mature zero-trust policy engine, passkeys and certificate-based phishing-resistant auth first-class, the Entra Suite extending into ID Governance, Internet Access, Private Access, and Verified ID, and Defender for Identity and native ITDR tying authentication to the broader Microsoft security stack — a Gartner Access Management Leader. Licensing is genuinely complex across E3/E5, P1/P2, and the Suite, and capability depends on which tier you hold. Non-Microsoft app coverage and lifecycle still trail the neutral specialists, and an all-Microsoft identity estate concentrates risk in one vendor’s ecosystem and outage surface.
Ping Identity
Leader — Orchestration DepthDepth for complex, high-assurance journeys — and you should confirm which product line the roadmap puts you on: following the ForgeRock combination it fields PingOne for Workforce for SSO and MFA, DaVinci no-code orchestration across hundreds of connectors, PingOne Protect for risk, and the former ForgeRock PingAM and PingIDM engines for intricate, large-scale, hybrid deployments, with strong standards and partner-access support and a consistent Gartner Access Management Leader position. Those two lineages are still converging, so establish the migration path between them early. The orchestration-led approach brings implementation weight and a steeper learning curve, and Thoma Bravo ownership means tracking strategy as it evolves under private equity.
CyberArk (Palo Alto Networks)
Leader — Identity SecurityIt treats every identity as potentially privileged, which is a security heritage rather than a directory one: Workforce Identity, the former Idaptive line, delivers SSO, adaptive MFA, Workforce Password Management, and a Secure Browser, all wired into the Identity Security Platform that made the company the privileged-access leader, applying least-privilege thinking to ordinary workforce sessions and now backed by Palo Alto Networks’ platform reach. Workforce SSO and MFA are younger than the PAM core, so connector breadth trails the pure access-management specialists. The value compounds when you also run it for privileged access, which raises total cost, and the recently closed acquisition means integration direction and packaging are still settling.
SailPoint
Strong — Governance-AnchoredIt governs what an authenticated user may reach, which means it expands your stack rather than collapsing it: the Atlas-based platform leads on access certification, role mining, separation-of-duties enforcement, AI-driven access recommendations, and the joiner-mover-leaver lifecycle, pairing with an authentication IdP rather than replacing it, and after Thoma Bravo took it private in 2022 it returned to the public markets in February 2025. It is not a workforce SSO or MFA provider — you still need Okta, Entra, or Ping for authentication and this governs on top. Deep governance carries real implementation effort, and the SaaS migration from legacy IdentityIQ should be scoped carefully.
IBM Verify
Strong — Hybrid & RegulatedReach into deeply legacy systems is the differentiator, and the product split is the complication: the SaaS IBM Verify plus the on-prem IBM Verify Identity Access, formerly Security Verify Access, target hybrid, regulated, and mainframe-adjacent estates where access must span cloud and legacy alike, with adaptive access, risk-based MFA, support for digital and verifiable credentials, and the ability to front complex on-prem applications that cloud-only platforms struggle to reach. You must confirm which capabilities live where and how the two interoperate. The user and administrative experience is more enterprise-IT than developer-friendly, and momentum and ecosystem buzz trail the cloud-native leaders, so weigh roadmap conviction.
Oracle Access Management
Strong — Oracle StackWorth it where Oracle Database, Fusion, and OCI already anchor the estate, and a harder sell anywhere else: workforce access is covered across the on-prem Oracle Access Management suite, now at the 14c release, and cloud-native OCI Identity and Access Management, with Oracle Access Governance layered on for review and compliance, and OCI IAM adding Identity Assurance for native biometric verification with liveness and policy-based step-up. Outside an Oracle-centric footprint it competes harder against the neutral leaders on third-party connector breadth and modern UX. The on-prem and OCI lineages have different capabilities, so confirm fit per deployment, and licensing inside the broader Oracle relationship rewards careful negotiation.
JumpCloud
Challenger — Unified Directory + DeviceOne platform instead of Active Directory plus SSO plus a separate MDM, which is a real simplification at mid-market scale: an open directory platform fusing workforce IAM, cross-OS device management, and infrastructure access — SSO, MFA, conditional access, and unified Windows, Mac, and Linux MDM that few competitors handle together — with a 2026 Agentic IAM capability to discover and govern AI agents alongside human and non-human identities. The sweet spot is SME and mid-market rather than the largest, most complex enterprises. The connector catalog and advanced governance are narrower than the enterprise leaders’, and as an independent, venture-backed vendor it warrants the usual scrutiny of scale references and long-term roadmap for your size.
How much should you budget for Identity & Access Management (IAM)?
Workforce IAM pricing is per user per month, but costs are driven by module stacking (SSO, MFA, lifecycle, ITDR, governance) and the tier needed for advanced security. Bundling with Microsoft 365 E3/E5 or broader Oracle agreements impacts marginal cost. Surprise costs include non-human identities, implementation/migration, and required support tiers, often rivaling year-one license fees.
Workforce IAM is priced per user per month, but the headline rate is the least interesting number in the deal. Cost is driven by module stacking — SSO is the entry point, and MFA, lifecycle/provisioning, ITDR, and governance each step the bill up — and by the tier you must reach to get phishing-resistant authentication and advanced security. With the ecosystem incumbents the question is bundling: Entra ID P1 and P2 ride inside Microsoft 365 E3 and E5, and Oracle access pricing lives inside a broader Oracle agreement, so the marginal IAM cost depends entirely on what you already own.
The surprise costs hide in three places. First, the non-human population: machine identities, service accounts, and now AI agents can outnumber employees, and if the platform charges for them or you bolt on a separate tool to govern them, the model you built on headcount understates reality. Second, implementation and migration — connector work, legacy-app integration, and entitlement cleanup — routinely rivals year-one license. Third, the support tier and professional services you actually need to run a security-critical system at your uptime expectations. Model the three-year total against your real user and machine curve and the features you will genuinely switch on, because the advanced-security tier, not base SSO, is where the spend concentrates.
| Vendor | Pricing Model | Relative Tier | Key Cost Drivers |
|---|---|---|---|
| Okta Workforce Identity Cloud | Per-user/month, module-tiered | Moderate–Premium | Module stacking (SSO, MFA, Lifecycle, Identity Governance, Identity Threat Protection), user volume, and premium support; modules add up quickly at scale |
| Microsoft Entra ID | Bundled with M365 + per-user add-ons | Lower (if owned) | Which tier you hold (P1 in E3, P2 in E5), the Entra Suite add-on for governance/access, and external-identity usage; value hinges on existing Microsoft licensing |
| Ping Identity | Per-user / module subscription; suite licensing | Premium | Module selection (PingOne, DaVinci, Protect, plus PingAM/PingIDM), user bands, orchestration depth, and on-prem vs. cloud deployment model |
| CyberArk | Per-user/month by capability tier | Moderate–Premium | Workforce Identity tiers (SSO, Adaptive MFA, Lifecycle, Password Management, Compliance) and how much of the broader Identity Security Platform you adopt |
| SailPoint | Per-identity subscription (Atlas) | Premium | Number of governed identities, connector count, and advanced analytics/AI modules — priced as governance on top of, not instead of, your IdP |
| IBM Verify | Per-user subscription (SaaS) / licensed (on-prem) | Moderate–Premium | SaaS vs. on-prem Verify Identity Access mix, user volume, advanced/adaptive access features, and the professional services to integrate legacy systems |
| Oracle Access Management | Per-user / subscription within Oracle agreement | Moderate | On-prem suite (14c) vs. OCI IAM consumption, Access Governance add-on, and where it sits inside the broader Oracle and OCI relationship |
| JumpCloud | Per-user/month, packaged or a-la-carte | Lower–Moderate | Whether you take the full platform (IAM + device management + infra access) or individual modules, user count, and add-ons; designed to undercut a multi-tool stack |
How long does implementation take for Identity & Access Management (IAM)?
IAM implementation typically takes 15-18 months, progressing through phases. The initial Foundation & Authoritative Identity phase (Months 1-3) establishes the directory and top applications. Lifecycle & Coverage Expansion (Months 4-8) extends SSO and automates provisioning. Threat Detection & Governance (Months 9-14) focuses on risk evaluation and access certification. Finally, Machine Identity & Optimization (Months 15-18) integrates service accounts and refines policies.
Workforce IAM rollouts are among the most organizationally impactful IT programs because every application’s sign-in, every provisioning rule, and every access policy is in scope. Sequence around risk and login coverage, not the admin console: stand up the directory and phishing-resistant authentication for the apps and users that matter most first, then expand, then govern. The two parts that consistently run long are the legacy and non-standard applications that resist modern protocols, and the entitlement cleanup that reveals how much access was granted and never reviewed.
Deploy the directory, connect the HR system as the authoritative source, bridge to on-prem Active Directory for coexistence, and bring the top applications that cover the bulk of daily logins under SSO. Enforce phishing-resistant MFA for administrators and high-risk roles first. What goes wrong here is discovering the HR data is dirty — duplicate, stale, or mis-attributed identities that automation will faithfully propagate unless cleaned.
Extend SSO across the long tail of applications, automate joiner-mover-leaver provisioning and deprovisioning via SCIM, and roll passkeys to broad user populations with a tested recovery and lost-device path. The hard cases surface now: home-grown apps with no SCIM, header- or agent-based legacy systems, and contractor populations whose lifecycle does not match employees’.
Turn on ITDR and post-authentication risk evaluation, wire identity signals to the SIEM/XDR, launch access certification campaigns, and enforce least-privilege and separation-of-duties policies. This is where over-provisioning becomes visible and politically charged — expect to negotiate access removals, not just configure them, and budget for the conversations.
Bring service accounts, workload credentials, and AI-agent identities under the same lifecycle and least-privilege discipline as human users, retire interim and legacy tooling, and tune adaptive policies against real traffic and simulated attacks. IAM is operated, not finished — treat thresholds, certifications, and the machine-identity inventory as continuously maintained, not one-time projects.
What should you ask vendors about Identity & Access Management (IAM)?
Use this checklist during evaluation to make sure each shortlisted platform covers what actually decides a workforce IAM deployment — phishing-resistant authentication, reliable lifecycle, threat detection, and clean reach into the rest of your estate — proven on your own applications and populations, not on a slide.
Frequently asked questions about Identity & Access Management (IAM)
We’re a lean mid-market company with mixed Windows/Mac/Linux devices and no AD legacy. Would JumpCloud be a genuinely sufficient option, or should we budget for a full enterprise suite?
JumpCloud can be genuinely sufficient for your situation, as it’s designed to replace the AD-plus-SSO-plus-MDM stack at a scale where a full enterprise suite is overkill. It bundles IAM and device management, but you should verify its governance and connector depth match your specific compliance obligations.
We’re evaluating SailPoint for its governance strengths. What’s a key cost driver that might surprise us, given it’s not an IdP?
A key cost driver for SailPoint that might surprise you is that it’s priced as governance on top of, not instead of, your IdP. This means you still need to budget for an authentication provider like Okta, Entra, or Ping for SSO/MFA, effectively expanding your identity stack’s overall cost.