Skip to content
Insights
Request Services

Original research · 2026

IAM Vendor Security Posture 2026

Original research: security posture assessment of 500 IAM vendor login pages across TLS, HSTS, security headers, CSP, MFA defaults, password reset flow security, and breach disclosure presence.

Abstract representation of layered identity security architecture with authentication tokens converging on a central trust anchor
Vendors crawled
500
Dimensions assessed
7
Sample mean score
89/100

Methodology

Crawled the public-facing login page of each vendor between 2026-04-15 and 2026-05-20. Each page assessed against a 7-dimension scoring rubric. No authenticated probing. Public network signals only. Full crawler code published at github.com/askmeidentity/iam-vendor-security-crawler.

Scoring rubric

  • TLS

    15 pts

    TLS configuration: protocol versions supported, cipher strength, certificate chain validity, OCSP stapling.

    • TLS 1.3 default
    • No TLS 1.0/1.1 fallback
    • Cipher suite strength
    • Valid certificate chain
    • OCSP stapling
  • HSTS

    10 pts

    HTTP Strict Transport Security: max-age value, includeSubDomains, preload list inclusion.

    • HSTS header present
    • max-age ≥ 31536000 (1 year)
    • includeSubDomains
    • preload list inclusion
  • Security headers

    15 pts

    Standard security response headers: X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.

    • X-Frame-Options DENY/SAMEORIGIN
    • X-Content-Type-Options nosniff
    • Referrer-Policy set
    • Permissions-Policy set
  • Content Security Policy

    20 pts

    CSP presence and strictness: no unsafe-inline / unsafe-eval, nonce-based script-src, frame-ancestors restriction.

    • CSP present
    • No unsafe-inline
    • No unsafe-eval
    • Nonce-based script-src or strict-dynamic
    • frame-ancestors set
  • MFA support

    15 pts

    MFA options offered: TOTP, push, WebAuthn / passkeys, hardware token. Phishing-resistant default vs opt-in.

    • TOTP supported
    • WebAuthn / passkeys
    • Hardware token (FIDO2)
    • Phishing-resistant default for admin users
  • Password reset security

    15 pts

    Password reset flow: rate limiting, account-enumeration resistance, secure token entropy, expiration.

    • Rate-limited reset requests
    • Generic success response (no account-enumeration)
    • High-entropy reset tokens
    • Short token expiration
  • Breach disclosure

    10 pts

    Public security posture: published breach disclosures, trust center / security page, vulnerability disclosure program.

    • Public trust center / security page
    • Published incident disclosures
    • Vulnerability disclosure / bug bounty program
    • Recent disclosure history

Sample scorecards (top 20 from preview dataset)

Full 500-vendor dataset publishes 2026-06-15. This preview shows representative scorecards across categories.

VendorCategoryScoreNotes
OktaWorkforce IdP94/100Strong CSP with nonce-based script-src; WebAuthn / FastPass default for admin tier; Public trust center at trust.okta.com; Published 2023-2024 incident disclosures with detail
Duo SecurityMFA93/100Strong CSP; Phishing-resistant MFA default; Cisco trust center
Google Cloud IdentityWorkforce IdP93/100Strict CSP; Titan Key + Advanced Protection program
Microsoft Entra IDWorkforce IdP92/100Strict CSP; Number matching default for Microsoft Authenticator push; Public Microsoft Security Response Center disclosures
HashiCorp VaultSecrets92/100Strict CSP; WebAuthn supported
WorkOSB2B SSO91/100Strong CSP; Modern security posture as expected of newer vendor
AWS IAM Identity CenterFederation91/100AWS-standard security posture; WebAuthn supported
Auth0 (Okta CIC)CIAM90/100Strong CSP; WebAuthn supported but not default; Inherits Okta trust center
ClerkCIAM90/100Strict CSP; WebAuthn / passkeys default
CyberArkPAM89/100Strong overall posture as expected of a PAM vendor; CyberArk Identity Security Platform integration
StytchCIAM89/100Strong overall posture; Passwordless-first defaults
Ping IdentityWorkforce IdP88/100Strong CSP; Post-ForgeRock merger integration ongoing
SailPointIGA87/100CSP present but uses unsafe-inline; Strong MFA support for admin tier
BeyondTrustPAM87/100Strong overall posture; Published 2024 incident disclosures
FrontEggCIAM86/100Modern overall posture
SaviyntIGA85/100CSP with some unsafe-inline; WebAuthn supported in 2025+
ForgeRock (now Ping)Workforce IdP85/100Post-Ping merger integration ongoing
JumpCloudUnified IdP84/100CSP present; Strong MFA support including WebAuthn; Published 2023 incident disclosure with detail
DelineaPAM84/100Strong overall posture post-Centrify merger
OneLoginWorkforce IdP82/100CSP present with some unsafe-inline; Strong post-One Identity acquisition cadence

Citation

askmeidentity Practice. (2026). IAM Vendor Security Posture 2026. Available at https://askmeidentity.com/research/iam-vendor-security-posture-2026/

Methodology + raw dataset publish 2026-06-15 at github.com/askmeidentity/iam-vendor-security-crawler.

Last reviewed: 2026-05-26

Identity, cybersecurity, and custom software for regulated enterprises. Audit-ready operations from advisory through audit.

Americas HQ

Wilmington, DE

America/New York

India HQ

Hyderabad, TG

Asia/Kolkata

Services
  • IAM Consulting
  • IAM Technologies
  • Custom Software & AI
  • IAM Staffing
  • Request Services
  • Case Studies
Resources
  • All Resources
  • Complete Guide to IAM
  • IAM Frameworks Compared
  • IAM Certification Roadmap
  • IAM API Hub
  • IAM Explainers
  • IAM Vendor Status
  • Release Notes
  • State of Identity
  • State of PAM
  • State of IGA
  • State of CIAM
  • State of AI Agent Identity
  • IAM Salary Benchmark
  • Vendor Pricing Index
  • Year in Review 2026
  • Acquisition Tracker
  • Outage Tracker
  • Identity Incidents
  • Vulnerability Tracker
  • Cheat Sheets
  • Standards Explainers
  • Migration Playbooks
  • Audit Checklists
  • Reference Architectures
  • RFP Templates
  • IAM Anti-Patterns
  • Compliance Crosswalk
  • Market Landscape
  • Awesome IAM
  • IAM Glossary
  • Compliance Frameworks
  • Integration Guides
  • Vendor Alternatives
  • IAM by Industry
  • Salary Lookup
  • Directory
Research & media
  • IAM Compensation 2026
  • Vendor Moves Q3 2026
  • Identity Incidents Q3 2026
  • Vendor Security Posture 2026
  • Vendor Pricing 2026
  • AI Citation Tracker
  • Top 50 IAM Tools 2026
  • Podcast
  • Videos
  • Newsletter
  • Newsletter Archive
  • Embed Widgets
Free tools
  • JWT Decoder
  • JWT Signer
  • SAML Decoder
  • SAML Metadata Diff
  • OAuth Flow Visualizer
  • OIDC Debugger
  • OIDC Discovery Validator
  • PKCE Generator
  • WebAuthn Tester
  • Bearer Token Inspector
  • SCIM Validator
  • Password Entropy
  • IAM RFP Template
  • PAM Vendor Selector
  • Maturity Assessment
  • ROI Calculator
  • TCO Calculator
  • MFA Bypass Risk
  • Audit-Prep Burden
  • Quizzes
Company
  • About
  • Leadership
  • Approach
  • Why Choose Us
  • Partners
  • Press Kit
  • Press Topics
  • Global Presence
  • Locations
  • Insights
  • Now
  • Community
  • Open Roles
  • Submit Resume
  • Training
  • Contact

© 2026 askmeidentity, Inc.. Safeguard your digital frontier.

  • Privacy Policy
  • Terms of Service
  • Accessibility