German companies are increasingly switching their security providers and preferentially investing in AI security and Identity and Access Management, while integration and value for money dominate purchasing decisions.
Microsoft is ending support for SMS and voice authentication in Entra ID from February 2027, forcing enterprises to switch to passkeys as the only remaining native MFA method.
Compromised AI gateways give attackers direct access to AI models, cloud infrastructure, and IAM data, making them a critical vector for enterprise compromise.
The three highest security risks of agentic AI are identity issues — tool misuse, privilege abuse, and rogue agents — requiring dedicated IAM controls beyond traditional service account governance.
AI agents require a rethinking of Zero-Trust strategies because classical onboarding processes do not work for short-lived, autonomous systems and have already led to database losses.
ITDR monitors identities directly for threats where classical IAM is blind — particularly in decentralized SaaS services purchased by business units without IT control.
The Claude apps gateway eliminates manual credential management per developer for CTOs and enables centralized access control, spending limits, and telemetry for Claude Code on Bedrock and Google Cloud.
The effective access of AI agents is not determined by IAM permissions alone, but by the interplay with firewall rules, cloud policies and microsegmentation — a policy governance task that most organizations systematically underestimate.
Zero-trust architectures are converging with IAM systems to transform authentication from a one-time event into an ongoing process that evaluates contextual signals such as device security status, geographic location, and behavioral patterns.