Identity and Access Management is the discipline of deciding who, or what, gets to access which systems, under what conditions, and proving it after the fact. As the perimeter dissolved into SaaS, cloud, and remote work, identity became the control plane, and it is now the most attacked one: most breaches start with stolen or misused credentials, not malware. The category spans the full lifecycle, from authenticating humans (Access Management, MFA & Passwordless, CIAM) to governing what they can touch (Identity Governance, Privileged Access Management) to the fast-growing problems of machine and cloud identity (Non-Human Identity, Secrets Management, Certificate Lifecycle Management, CIEM) and catching identity attacks in progress (ITDR). It is broad enough that most buyers assemble a stack across several subcategories rather than betting on one platform that claims to do everything.
We cover 909 IAM tools, 64 free and 845 commercial.
Accuracy and depth improve over time. Last reviewed Oct 2026. Is something off? Reach out.
New to this category? What is Identity and Access Management (IAM)?
A simple drop-in library for managing users, permissions, and groups in your application.
Project hosting scripts for implementing Pass the Hash mitigations with PtHTools module commands.
Principal Mapper is a Python tool that models AWS IAM configurations as directed graphs to identify privilege escalation risks and alternative attack paths in AWS environments.
A Docker-based utility that monitors TLS certificate expiration dates and exposes the data as Prometheus metrics with support for Kubernetes ingress discovery and configurable domain filtering.
SOPS is an encrypted file editor that supports multiple formats and integrates with various key management services including AWS KMS, GCP KMS, Azure Key Vault, age, and PGP.
A command-line password manager that encrypts credentials using GnuPG and stores them in YAML files with git synchronization support.
A secret management service that stores encrypted secrets in DynamoDB for secure credential and sensitive data management.
kube2iam provides IAM credentials to Kubernetes containers by intercepting EC2 metadata API calls and retrieving temporary AWS credentials based on pod annotations.
A Helm plugin that decrypts encrypted value files using sops encryption and integrates with cloud secret managers for secure secrets management in Kubernetes deployments.
CredStash is a credential management tool that securely stores and retrieves sensitive information using AWS KMS encryption.
SkyWrapper analyzes temporary token behaviors in AWS accounts to detect suspicious activities and generates Excel reports with findings summaries.
Encrypt Kubernetes Secrets into SealedSecrets for safe storage and controlled decryption within the cluster.
Safely store secrets in version control repositories with GPG encryption support.
An automated script that configures Active Directory domains using customizable XML configuration files.
A tool for securely backing up and versioning production secrets or shared passwords
AWS Vault securely stores AWS IAM credentials in the operating system's keystore and generates temporary credentials for development environments.
OpenIAM offers a unified identity governance platform featuring CIAM, MFA, and PAM integration.
Secure and manage passwords across devices with Bitwarden's open-source, encrypted password manager.
A list of disposable email domains to detect or block disposable accounts
909 tools across 13 specializations · 64 free, 845 commercial
Identity Governance and Administration
Identity Governance and Administration (IGA) platforms for joiner-mover-leaver lifecycle, access certification, and separation-of-duties.
Identity Threat Detection and Response
Identity Threat Detection and Response (ITDR) solutions for detecting identity-based attacks, credential theft, and compromised accounts in real-time.
Identity Verification
Identity verification services for digital identity proofing and identity assurance during onboarding and authentication.
Tool roundups, buying guides, and strategic analysis from the CybersecTools resource library.
Common questions about IAM tools, selection guides, pricing, and comparisons.
IAM is the set of tools and processes that control who can reach an organization's systems and data, what they can do once inside, and how that access is proven and revoked. It spans authenticating users with passwords, MFA, SSO, and passkeys, governing permissions over time, securing privileged and machine accounts, and detecting identity-based attacks. With identity now the primary target in most breaches, IAM is foundational to modern security.
Start by identifying which specific identity problem you have, because IAM covers many distinct ones. Workforce login, customer identity, access governance, privileged access, machine and cloud identity, and identity threat detection are separate disciplines. Match your biggest risk and compliance gap to the corresponding subcategory, then judge tools on how deeply they integrate with your existing identity provider, cloud, and HR systems.
IAM is the broad discipline covering all identities and their access. Privileged Access Management is a subcategory focused on high-risk accounts: administrators, root, service accounts, and anyone with elevated permissions. PAM adds credential vaulting, session recording, and just-in-time elevation that general IAM does not. Most organizations need both: IAM for everyone, PAM for the accounts that can do the most damage.
Open-source identity providers handle authentication and SSO well and make a strong foundation, especially for engineering-heavy teams comfortable operating them. Governance, privileged access, identity threat detection, and audit-ready reporting are where commercial platforms pull ahead, in both features and support. Many organizations run open-source for core authentication and buy commercial tools for governance, PAM, and ITDR, where the operational burden and stakes climb.