Identity at the Center
The longest-running weekly show on identity and access management programs, hosted by two practitioners. The best single feed for keeping up with the field.
- Hosts
- Jeff Steadman, Jim McDonald
- Publisher
- Independent · Independent
- Pillar
- Workforce Identity, Privileged & Governance
- Level
- Practitioner
- Format
- Co-host interview
- Cadence
- Weekly, often twice a week, 60 to 80 min
- Status
- Active, last episode 2026-09-30
- Since
- 2019
- Episodes
- 451
What it is
Identity at the Center is a weekly conversation about identity security in the context of IAM, hosted by Jim McDonald and Jeff Steadman since July 2019. With more than 450 episodes it is the deepest archive in this directory. Formats include guest interviews, "Decoded" deep dives on specifications (for example Transaction Tokens with George Fletcher), conference recordings, and a "New to Identity" strand with people early in their careers.
Who it suits
Practitioners running or joining an identity program. Episodes assume you know what SSO and IGA are, but rarely assume protocol fluency, so motivated beginners keep up.
Editor note
The breadth is the strength: careers, governance, standards, and conference coverage in one feed, from hosts who have run programs themselves. Episodes run long, often over an hour, and the "Sponsor Spotlight" episodes are paid vendor features, so skip or discount those. For standards depth, start with the Decoded episodes.
Where to start
- #294 - Navigating Privileged Access Management with Michiel Stoop2024-07-15 · 45 min · Learner · Privileged access management
Why PAM matters, how to sell a PAM program to management, how to choose PAM products, and ways to shrink the privileged attack surface.
- #56 - What is FIDO with Andrew Shikiar2020-08-10 · 47 min · Learner · Passkeys and FIDO
What the FIDO Alliance is and which authentication problems its standards are meant to solve, explained by the Alliance's executive director.
- #37 - Access Management with Andy2020-03-30 · 36 min · Learner · SAML and enterprise federation
An entry-level tour of access management: why OIDC and SAML exist, and how scopes and protocol flows fit into single sign-on.
Also in our learning paths
- #449 - Decoded - Transaction Tokens with George Fletcher2026-09-21 · 71 min · Architect · OAuth and OpenID Connect
How OAuth Transaction Tokens secure requests across microservices, including their claims, time to live, immutability, and use with AI agents.
- #433 - Sponsor Spotlight - FusionAuth2026-07-08 · 56 min · Practitioner · Customer identity (CIAM)
CIAM design choices: progressive registration, balancing friction against usability, customization, risk-based MFA, and build versus buy for customer authentication.
- #428 - Modernizing IGA with Thomas Zarnhofer2026-06-15 · 42 min · Architect · Identity governance (IGA)
Lessons from replacing a decade-old on-premises IGA system: person-based identity models, cleaning data first, and running old and new platforms in parallel.
- #422 - Decoded - Securing AI Agents with Standards You Already Have2026-05-15 · 78 min · Architect · OAuth and OpenID Connect · Non-human and AI agent identity
How existing OAuth specifications such as JWT authorization grant, token exchange, and client ID metadata, plus SPIFFE, apply to securing AI agents as workloads.
- #409 - Q1 2026 Identity Threat Report Roundup2026-03-23 · 59 min · Practitioner · Identity threats and ITDR
Summarizes seven Q1 2026 threat reports and the identity patterns they share, including MFA gaps, machine identity abuse, deepfakes, and faster breach timelines.
- #402 - An Update on SSF and CAEP with Atul Tulshibagwale2026-02-16 · 62 min · Architect · Zero trust
Updates the state of the Shared Signals Framework and CAEP standards, including adoption by major technology companies.
- #393 - Breaking the Tyranny of Joiner, Mover, Leaver with Ian Glazer2026-01-05 · 58 min · Architect · Identity governance (IGA)
A critique of the batch joiner-mover-leaver model and the case for continuous identity driven by shared signals.
- #390 - Identity Management for Agentic AI with Tobin South2025-12-08 · 56 min · Architect · Non-human and AI agent identity
Identity challenges raised by AI agents, the role of MCP, and recursive delegation and scope attenuation, drawing on the OpenID Foundation agentic AI whitepaper.
- #388 - Fraud Reduction Intelligence Platforms with John Tolbert2025-12-01 · 59 min · Architect · Customer identity (CIAM)
The capabilities of fraud reduction platforms and how identity verification, device intelligence, behavioral biometrics and shared signals combine in customer-facing fraud defense.
- #384 - The FIDO Alliance's Next Frontier: Digital Credentials and Wallets2025-11-10 · 31 min · Practitioner · Verifiable credentials and digital wallets
Covers why the FIDO Alliance is extending from passkeys into digital credentials and wallets, and how the two fit together.
- #376 - Understanding Device Identity in a Zero Trust Framework with Shea McGrew2025-09-29 · 74 min · Practitioner · Zero trust
A county government CTO explains how device identity fits into a zero trust program alongside human identity in a complex public-sector organization.
- #373 - Going Passkey Phishing with Nishant Kaushik2025-09-15 · 58 min · Practitioner · Passkeys and FIDO
Common concerns about passkey security and adoption, discussed with the FIDO Alliance CTO, plus an overview of the Alliance's ongoing work.
- #365 - Exploring the Future of Machine Identity with Felix Gaehtgens2025-08-04 · 62 min · Learner · Non-human and AI agent identity
How machine identities differ from human ones, why static credentials like API keys and service accounts create technical debt, and the case for dynamic, ephemeral credentials.
- #354 - Kristina Yasuda & Torsten Lodderstedt on the EUDI Wallet and its Global Impact2025-06-09 · 52 min · Architect · Verifiable credentials and digital wallets
Two architects of the EUDI Wallet ecosystem explain the EU plan to give every citizen a digital identity wallet and its effect beyond Europe.
- #337 - Adaptive Authentication and Fraud Prevention with Ping's Patrick Harding2025-03-17 · 58 min · Practitioner · SAML and enterprise federation
The practical trade-offs between SAML and OpenID Connect for SaaS single sign-on, and what it takes to modernize older applications onto newer federation protocols.
- #329 - Discovering Effective User Access Reviews with Stephen Washington2025-02-03 · 70 min · Practitioner · Identity governance (IGA)
How a regulated financial firm runs user access reviews, with practical steps for better certifications and for governing service accounts.
- #318 - SailPoint Navigate 2024 - SSF, CAEP, RISC, and SCIM Events with SailPoint's Mike Kiser2024-11-18 · 50 min · Architect · Identity governance (IGA)
How event-based standards such as the Shared Signals Framework, CAEP, RISC and SCIM events can make provisioning and governance react in near real time.
- #296 - Allan Foster Walks Down IAM Memory Lane2024-07-29 · 70 min · Learner · SAML and enterprise federation
The history behind SAML through the Liberty Alliance and Kantara, and why trust frameworks and federations mattered as much as the protocol itself.
- #276 - CloudSec with Kat Traxler of TrustOnCloud2024-04-22 · 62 min · Practitioner · Privileged access management
How cloud IAM differs between GCP and AWS, why resource hierarchy and policy inheritance matter, and the tradeoff between least privilege and zero standing privilege.
- #267 - PAM & IGA with Paul Mezzera2024-03-15 · 71 min · Practitioner · Privileged access management
What is driving change in privileged access management, predictions for where PAM is heading, and how it relates to the identity governance market.
- #266 - Identity Wallets with Nick Mothershaw of The Open Identity Exchange2024-03-11 · 62 min · Practitioner · Verifiable credentials and digital wallets
Describes how digital identity wallets work, the role governments play in issuing them, and where smart and roaming wallets may go next.
- #260 - Passkeys with Daniel Grube of TikTok2024-02-19 · 49 min · Practitioner · Passkeys and FIDO
How TikTok rolled out passkeys for its users, including offering them at sign-up and the adoption and user messaging challenges, from its product manager.
- #255 - CAEP and SSF 101 with Atul from SGNL and Sean from Disney2024-01-22 · 53 min · Architect · Zero trust
Explains the Shared Signals Framework and CAEP with real examples, and how they connect continuous access decisions to identity threat detection.
- #248 - Decentralized Identity with the Identity Woman Kaliya Young2023-11-27 · 62 min · Learner · Verifiable credentials and digital wallets
Covers what decentralized identity means, why governments struggle to implement it, and how competing standards and politics shape digital wallets.
- #242 - Authenticate 2023: Passkeys with Pedro Martinez of Thales Group2023-10-30 · 42 min · Practitioner · Passkeys and FIDO
Security and user experience trade-offs of passkeys in financial services, including how platform vendors control passkey synchronization.
- #237 - OAuth 2.0 Step Up Authentication Challenge Protocol with Vittorio Bertocci2023-10-09 · 36 min · Practitioner · OAuth and OpenID Connect
What the OAuth 2.0 Step Up Authentication Challenge Protocol (RFC 9470) does, from its co-author.
- #232 - Just in Time Access with John Morton of Britive2023-09-25 · 54 min · Practitioner · Privileged access management
How just-in-time access works, how it relates to zero standing privileges, and where it fits across cloud, on-prem, Snowflake, and DevOps automation.
- #223 - CIAM with Cassio Sampaio of Okta2023-07-24 · 77 min · Learner · Customer identity (CIAM)
What customer identity is, how it differs from workforce IAM, the role of self-service, and common challenges when a business first adopts CIAM.
- #222 - Identity Standards with Justin Richer of Bespoke Engineering2023-07-17 · 90 min · Architect · OAuth and OpenID Connect
How OpenID Connect might be designed differently today and what the Grant Negotiation and Authorization Protocol (GNAP) aims to change.
- #211 - Carolinas Identity Roundtable RBAC Discussion2023-05-08 · 77 min · Practitioner · Identity governance (IGA)
Practitioners from banking, manufacturing and retail compare how they build and maintain role-based access control in real IAM programs.
- #197 - GSA & CISA PAM Playbook with Ken Myers and Ross Foard2023-01-30 · 63 min · Learner · Privileged access management
What the federal GSA and CISA privileged identity playbook covers, explained by two government practitioners involved with it.
- #154 - Customer MFA vs. Workforce MFA2022-07-11 · 47 min · Learner · Customer identity (CIAM)
Why multifactor authentication for customers is a different problem from MFA for employees, and which of the two is harder to get right.
- #141 - 2022: Year of the MFA Bypass2022-04-11 · 55 min · Learner · Passkeys and FIDO
Why attackers increasingly bypass traditional MFA and how FIDO possession-based authentication gives IAM practitioners a phishing-resistant alternative.
- #129 - Zero Trust in 2022 with Den Jones2022-01-17 · 64 min · Learner · Zero trust
A security chief who led zero trust programs explains what zero trust looks like in practice and how an organization can get started.
Last verified 2026-09-30 against the show's feed, recent episode notes, and the publisher's own pages. Status and last-episode date update weekly from the feed.
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].
Related on Start with Identity
- PodcastA Digital Identity Digest
Short weekly episodes from standards veteran Heather Flanagan that "translate geek to human" on identity standards, wallets, and the web platform.
- BlogA loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signat
- GlossaryAccess Certification
Periodic review of who has access to what, with managers or resource owners attesting that access is still appropriate. A regulatory requirement in many industr
- BlogAgent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The
- PodcastAuth0
The late Vittorio Bertocci's interviews with the authors of OAuth, OpenID Connect, FIDO, and SAML. Ended in 2022, and still the best audio archive on identity s
- GlossaryCIAM
Customer Identity and Access Management. The identity stack for end users of a product, distinct from workforce IAM. CIAM optimizes for self-service signup, con