Fresh analysis on IAM, access, and digital identity.
Clear breakdowns of the standards, tools and threats shaping the industry.
Views and interviews from identity practitioners doing the work.
What vendors are launching, what is changing and what is actually worth paying attention to.
THIS NEWSLETTER IS POWERED BY CLUTCH
We held our New York Identity Summit in the past fortnight and it was a major success with over 200 identity leaders joining us for the event.
Thanks again to the Identity at the Center gang plus the Identibeers crew who supported us and helped make the event successful.
Now for the useful stuff, here were some of the major takeaways from the event:
New York Identity Summit top 4 Takeaways

There is a disconnected application problem in many large enterprises. 30% of enterprise applications and on average 80 per organisation are disconnected from the IDP.
Our session also found that most organisations still manage at least 20% of their apps manually via help desk and email.
This is creating a massive blind spot in organisations, especially as AI agents and prompt injection attacks create new ways for those applications to be accessed.
It is becoming key for organisations to extend their identity stack to disconnected apps.
Full slides here: Download Slides
NYDFS regulators are focusing hard now on NHI inventory and ownership lineage according to the real-life experiences of our panellists.
The room surveyed indicated that only 50% felt somewhat confident they could prove who had access to what tomorrow.
It is becoming ever more important to ensure you're audit ready and build a security program that hits the minimum requirements across all your regions, but also look at how those regulations may change in 3–5 years to try and get ahead of them.
We got a deep dive in our keynote from Nader Nassar, CapitalOne on his NHI Remediation Framework.
Key components included building an enterprise-wide registry of identities, with each identity given a trust tier such as low risk, elevated risk or high risk, with guardrails around each.
Most importantly there needs to be clear ownership of managing this framework with a chain of custody, so if one person misses something, the next responsible layer will catch it.
We are actually running our Identity Leaders Network Virtual Roundtable on this exact topic this month and you can find out more about joining here: APAC session and US Session.
Full slides here: Download Slides
The top source of user friction for our audience was step-up/re-authentication prompts from a survey we conducted at the event, with legacy technology being the biggest barrier for organisations trying to solve this friction.
The panellists' experience was that session timeouts were actually the biggest cause of abandonment they are seeing currently.
It is important not to make these arbitrary, so not just 15 minutes because the auditor said so, but build them dynamically based on context, device trust and user risk profile.
You can view the full list of session slides here.
The Big Story: Black Hat Research Shows Flaws in Passkey Implementations, Not Passkeys

Last issue our big story covered how Microsoft was making passkeys the default in Entra.
Passkeys are again the top story as several pieces of research presented around Black Hat showcased ways for passkey-protected identities to be compromised, with the focus mostly on the systems and processes around them.
Michael Grafnetter, Principal Security Researcher at SpecterOps, presented his new Pass-the-Passkey attack research which focused on failures in WebAuthn implementations.
Michael found that Microsoft was storing WebAuthn authentication responses, such as YubiKey signatures, in readable event logs that could be accessed by authenticated, unprivileged users.
Normally these old responses should be useless, but weaknesses in the wider WebAuthn validation process meant the researchers found ways they could be replayed.
This allowed them to impersonate privileged users while still bypassing controls designed to require phishing-resistant MFA.
Microsoft has since patched the Windows event logging issue.
The key point was that the private key inside the YubiKey was never stolen. The flaw was in how the authentication response was handled and validated around it.
Unit 42 also presented their similarly named Pass-Ta-Key attack research at Black Hat.
This research showed how malware already running on a compromised Windows machine could access passkey information and make Google Cloud Authenticator believe a legitimate trusted device was requesting the login.
They were able to show how this could lead to account takeover without user interaction and, in the most serious version of the attack, extraction of all of a user's synced passkeys.
Importantly, the attacker already needed malware running on the victim's machine.
Some of the specific issues were fixed after disclosure, but the research again showed that it wasn't the passkey cryptography itself that was the problem. It was the systems around it and the importance of protecting the endpoint.
Finally Dirk-Jan Mollema, Founder of Outsider Security, showed how malware inside an already logged-in Windows session can use a victim's Windows Hello for Business credentials without ever stealing the private key.
It worked simply in that malware running as the user can ask Windows to use the legitimate Windows Hello key to sign an authentication request without another biometric check or PIN being required.
This can potentially allow an attacker to satisfy Entra controls requiring phishing-resistant authentication and gain access to cloud systems.
There isn't a simple patch for this behaviour currently. The practical defence is stopping endpoint compromise and monitoring Windows Hello sign-ins with missing device IDs or unexpected new device registrations.
Across all three pieces of research the common trend was that it wasn't the passkeys themselves which were the problem, but the processes and systems around them.
This also follows directly from the enrolment attacks we covered in the last issue. Again the passkey itself held up, but attackers found another part of the process to target.
For teams rolling out passkeys, there are a few key questions to ask:
Are synced passkeys allowed, device-bound passkeys or both?
Should privileged accounts have different requirements?
What happens when the endpoint itself is compromised?
Are applications correctly validating WebAuthn responses?
Can unusual passkey registrations and authentications be detected?
What checks are required when someone needs a replacement credential?
The big takeaway is passkeys solve some very important problems with passwords and traditional MFA, but they do not remove the need to secure everything sitting around them.
Read more:
New Model Context Protocol Specification Makes Agent Connections Easier to Control

Model Context Protocol's major update has made connections between agents and enterprise tools easier to manage, as well as adding several authorization security improvements.
The update essentially makes it much easier to see which agent is calling which tool and what it is trying to do.
MCP has moved to a largely stateless model, meaning each request carries the information needed to understand it rather than relying on a continuing session.
This primarily makes MCP servers much easier to run and scale.
More importantly for security teams, the method and tool being called can now be exposed directly in HTTP headers.
So for example a security gateway can clearly see that an agent is trying to call a search or delete tool and apply controls to that individual request without having to dig through the full MCP message.
This means organisations can potentially have one control point in front of lots of MCP servers and more easily manage which tools different agents are allowed to use.
MCP has also tightened its OAuth security, including stronger checks around which authorization server issued a credential, binding credentials to the server that issued them and moving away from Dynamic Client Registration towards Client ID Metadata Documents.
So the big picture of the story is that this is another big step forward for MCP moving from a convenient way for agents to connect to tools towards something enterprises can put proper security and authorization controls around.
News Highlights
Okta Continues Move from IAM to SecOps with Permiso Deal
Okta has signed a definitive agreement to acquire Permiso Security.
Permiso is an identity security company specialising in identity threat detection across multi-cloud environments and human, non-human and agentic identities.
Okta plans to incorporate Permiso's identity risk signals, behavioural analytics and threat detections to expand its ITDR capabilities.
The deal further showcases Okta's push beyond pure identity management and further into security operations, with Okta itself saying the acquisition will expand its footprint into the core Security Operations Center.

Cyera moves into the Identity Space
Cyera has signed a letter of intent to acquire Oasis Security for approximately $1 billion as it makes a major move into the identity space.
Primarily a data security company, the deal showcases Cyera's view that data security and identity are increasingly becoming the same control problem.
Oasis Security specialises in non-human identities and agent access.
Cyera plans to combine Oasis' identity and access capabilities with its own ability to understand the context and sensitivity of the data being accessed, with the aim of building a combined identity and data security platform for AI agents.

Saviynt Launches Enterprise AI Identity Security Platform
Saviynt has launched Zuma, its new AI Agent Identity Security Platform.
Saviynt's point of difference is that access decisions can be made at runtime based on the specific action an agent is attempting.
So an agent might generally have access to Salesforce but still be blocked from a particular action if the context, permissions or risk are wrong.
Podcasts and Events to Catch
Podcasts
Identity at the Center’s recent episodes include several more interviews they ran at Identiverse and can be found here.
Upcoming Events
Clutch Events’ Melbourne Identity, Authentication and Access Management Summit is coming up on 16 September. The event is run by the publisher of Identity Briefing, and registration is free for identity practitioners. Register for the Melbourne Summit here.
FIDO has released the program for Authenticate U.S. 2026, taking place from 19–21 October at the Omni La Costa Resort in Carlsbad, California. View the full program here.
Over to you!
A question the Identity Leaders Network WhatsApp group has been grappling with is:
Is anyone governing AI agent identities in production today?
We want to hear from you if you are open to talking about this issue.
It does not need to be a complete program. We are interested in what teams are actually doing now, rather than what appears in the strategy deck.
Share what is working and where the gaps remain. We will bring the patterns together anonymously under Chatham House Rule for Issue #2.
Get in touch at danny@clutchgroup.co if you would be interested in sharing some insights for the next newsletter.
Identity Briefing is published fortnightly by Clutch Group, which runs the Identity Leaders Network, Identity Briefing and the Global Identity Summit series.
Know someone who should be reading it? Forward this on.