# IAM

Identity and access management (IAM) is a cybersecurity discipline for provisioning and protecting digital identities and managing access permissions in IT systems.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

DevFeed: [Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection](<https://devfeed.tech/articles/unmasking-cloud-identities-from-behavioral-clustering-to-automated-detection-17391.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/>)

Author: Osher Jacob

Published: 2026-09-14T10:00:01Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [AWS CloudTrail](<https://devfeed.tech/topics/aws-cloudtrail.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [Algorithms](<https://devfeed.tech/topics/algorithms.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [algorithms](<https://devfeed.tech/tags/algorithms.md>), [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [aws-cloudtrail](<https://devfeed.tech/tags/aws-cloudtrail.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-cybersecurity-research](<https://devfeed.tech/tags/cloud-cybersecurity-research.md>), [cloud-detection](<https://devfeed.tech/tags/cloud-detection.md>), [devops](<https://devfeed.tech/tags/devops.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [post](<https://devfeed.tech/tags/post.md>), [sql](<https://devfeed.tech/tags/sql.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

This article presents a behavioral clustering model for mapping cloud identities to functional roles using activity patterns from audit logs. It applies unsupervised machine learning with UMAP and HDBSCAN to data from more than 40,000 identities across 125 cloud environments, and shows how the resulting map can support automated threat detection. The article also explains how lightweight heuristics extracted from the map can classify identities at scale using standard SQL, reducing the need for continuous resource-intensive machine learning pipelines.

### Source excerpt

We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.

## Infrastructure identity for platform engineers

DevFeed: [Infrastructure identity for platform engineers](<https://devfeed.tech/articles/infrastructure-identity-for-platform-engineers-12177.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/infrastructure-identity-for-platform-engineers>)

Author: Sam Barlien

Published: 2026-09-08T12:20:22Z

Content type: tutorial

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [internal developer platform](<https://devfeed.tech/topics/internal-developer-platform.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>)

Tags: [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [internal-developer-platform](<https://devfeed.tech/tags/internal-developer-platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

A guide for platform engineers on adopting infrastructure identity: assigning cryptographic identities and short-lived, just-in-time access to people, machines, workloads, and AI agents. It argues that this approach can replace static secrets and network-based trust in an internal developer platform.

### Source excerpt

Discover how platform engineers can eliminate static secrets and embed Zero Trust into their IDP using short-lived, cryptographic infrastructure identities.

## Password spraying campaign targets AWS root user accounts across 150+ organizations

DevFeed: [Password spraying campaign targets AWS root user accounts across 150+ organizations](<https://devfeed.tech/articles/password-spraying-campaign-targets-aws-root-user-accounts-across-150-organizations-8272.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/>)

Author: Martin McCloskey

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-iam](<https://devfeed.tech/tags/aws-iam.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Datadog Security Research describes a password spraying campaign that repeatedly targeted AWS root user accounts at more than 150 organizations between July 24 and August 23, 2026. The campaign used Chrome and Firefox user-agent fingerprints and proxy infrastructure; no successful authentications were observed, and the attackers' motive remains undetermined. The article explains the privileges and safeguards associated with AWS root users and recommends reducing reliance on persistent root credentials.

### Source excerpt

Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.

## How Does CockroachDB Automate SQL User Lifecycle Management?

DevFeed: [How Does CockroachDB Automate SQL User Lifecycle Management?](<https://devfeed.tech/articles/how-does-cockroachdb-automate-sql-user-lifecycle-management-23818.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/sql-user-lifecycle-management-automation>)

Author: Pritesh Lahoti,Biplav Saraf,Sourav Sarangi

Published: 2026-08-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [okta](<https://devfeed.tech/topics/okta.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [okta](<https://devfeed.tech/tags/okta.md>)

### AI overview

The article addresses how CockroachDB automates SQL user lifecycle management and notes that large enterprises commonly rely on identity provider and identity and access management platforms such as Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory.

### Source excerpt

Fortune 1000 enterprises widely rely on major Identity Provider (IdP) and Identity and Access Management (IAM) platforms like Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory.

## Fine-Grained Access Control Now Available for All Heroku Customers

DevFeed: [Fine-Grained Access Control Now Available for All Heroku Customers](<https://devfeed.tech/articles/fine-grained-access-control-now-available-for-all-heroku-customers-26403.md>)

Original publisher: [Read original article](<https://www.heroku.com/blog/fine-grained-access-control-now-available-all-customers/>)

Author: Alberto Sigismondi

Published: 2026-08-21T17:07:29Z

Content type: release

Language: en

Sources: [Heroku](<https://devfeed.tech/sources/heroku.md>)

Topics: [Heroku](<https://devfeed.tech/topics/heroku.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Security](<https://devfeed.tech/topics/security.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [legacy](<https://devfeed.tech/topics/legacy.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [deploy](<https://devfeed.tech/tags/deploy.md>), [heroku](<https://devfeed.tech/tags/heroku.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [news](<https://devfeed.tech/tags/news.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [security-compliance](<https://devfeed.tech/tags/security-compliance.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

Heroku announces that Fine-Grained Access Control is available to all customers. The feature replaces fixed legacy roles with capability-based roles and app-specific permissions for roles such as view, deploy, operate, and manage.

### Source excerpt

Fine-Grained Access Controls is now available to all Heroku customers. Heroku's legacy system gave you predefined roles like admin, member, or collaborator, each with a fixed bundle of permissions. It replaces that system with fine-grained roles like view, deploy, operate, and manage, with specific capability sets. Access control is managed at an app-specific layer, giving [...] The post Fine-Grained Access Control Now Available for All Heroku Customers appeared first on Heroku.

## Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway

DevFeed: [Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway](<https://devfeed.tech/articles/implement-custom-authentication-for-tools-integration-using-request-lambda-interceptor-in-agentcore-gateway-4684.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/implement-custom-authentication-for-tools-integration-using-request-lambda-interceptor-in-agentcore-gateway/>)

Author: Nishant Mainro

Published: 2026-08-18T20:46:26Z

Content type: tutorial

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Amazon Bedrock AgentCore](<https://devfeed.tech/topics/amazon-bedrock-agentcore.md>), [Amazon Bedrock](<https://devfeed.tech/topics/amazon-bedrock.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [amazon-bedrock](<https://devfeed.tech/tags/amazon-bedrock.md>), [amazon-bedrock-agentcore](<https://devfeed.tech/tags/amazon-bedrock-agentcore.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [aws-identity-and-access-management-iam](<https://devfeed.tech/tags/aws-identity-and-access-management-iam.md>), [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [model-context-protocol](<https://devfeed.tech/tags/model-context-protocol.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>), [technical-how-to](<https://devfeed.tech/tags/technical-how-to.md>)

### AI overview

This tutorial explains how to use a request Lambda interceptor in Amazon Bedrock AgentCore Gateway to support legacy Basic Authentication for downstream tool APIs. The interceptor retrieves service credentials from AWS Secrets Manager and constructs the authentication header while keeping credentials isolated from the AI agent. The article also describes the inbound MCP request flow and cautions that Basic Auth should be treated as an interim measure, with modernization toward OAuth 2.0, SAML, OpenID Connect, or IAM recommended.

### Source excerpt

When deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use legacy authentication mechanisms such as HTTP Basic Authentication (Basic Auth) (RFC 7617). The extensible architecture of AgentCore [...]

## Introducing 1Password Privileged Access: Zero standing privileges for every identity

DevFeed: [Introducing 1Password Privileged Access: Zero standing privileges for every identity](<https://devfeed.tech/articles/introducing-1password-privileged-access-zero-standing-privileges-for-every-identity-1933.md>)

Original publisher: [Read original article](<https://1password.com/blog/introducing-1password-privileged-access>)

Author: info@1password.com (Rom Carmel)

Published: 2026-07-28T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [databases](<https://devfeed.tech/tags/databases.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password Privileged Access introduces just-in-time access for human and agent identities across cloud and hybrid environments, databases, and Kubernetes. It aims to eliminate standing privileges by granting task-scoped access when needed and automatically removing it when work is complete.

### Source excerpt

Here's a moment that comes up in nearly every compliance review: a security engineer pulls a list of IAM roles in the AWS environment. The list is long. Some roles were created for a migration project that closed two quarters ago, a few belong to contractors who haven't worked there in over a year, and others are attached to agentic identities without any way to see which human they were acting on behalf of. There's no ticket to clean them up, no alert when the access outlived its purpose, and no record of who approved it in the first place. That's standing access in practice; that long list of overprovisioned IAM roles is simply the product of how access has always been provisioned. Admins create it when the work starts, then rely on someone else to clean it up when it's done. But the cleanup rarely happens. The gap between the access granted and the access that's actually needed becomes the gap that shows up in audit findings, and that attackers learn to exploit. That problem has grown harder to manage as AI agents have joined human engineers in operating on production infrastructure. Agents don't request access through a ticket queue. They act continuously, respond to changing inputs, and can be steered in ways that static standing permissions were never designed to contain. Governing agents with the same legacy PAM tools built for human logins carries the risk forward instead of containing it. That's why we're introducing 1Password Privileged Access. It brings Apono's proven just-in-time access engine into the 1Password Unified Access platform, eliminating standing privileges for both human and agent identities across cloud and hybrid environments, databases, and Kubernetes. Access is created at the moment of the request, scoped to the task, and deprovisioned automatically when the work is done. Standing access became the default, and the cost kept growing Cloud infrastructure can change by the hour. New services get spun up, roles get reshuffled, and permission

## Privilege separation and the validation loop: The two controls that make AI agents safe in regulated industries

DevFeed: [Privilege separation and the validation loop: The two controls that make AI agents safe in regulated industries](<https://devfeed.tech/articles/privilege-separation-and-the-validation-loop-the-two-controls-that-make-ai-agents-safe-in-regulated-industries-12215.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/privilege-separation-and-the-validation-loop-the-two-controls-that-make-ai-agents-safe-in-regulated-industries>)

Author: Eric Paulsen

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Developer Platform](<https://devfeed.tech/topics/developer-platform.md>), [internal developer platform](<https://devfeed.tech/topics/internal-developer-platform.md>), [iac-security](<https://devfeed.tech/topics/iac-security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer-platform](<https://devfeed.tech/tags/developer-platform.md>), [governance](<https://devfeed.tech/tags/governance.md>), [iam](<https://devfeed.tech/tags/iam.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [internal-developer-platform](<https://devfeed.tech/tags/internal-developer-platform.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that regulated organizations can deploy useful AI agents safely by combining privilege separation with validation loops into one governance system. It assigns platform teams responsibility for the execution environment, including internal developer platforms, CI/CD pipelines, and policy enforcement, while highlighting risks such as hallucinations, excessive IAM permissions, and prompt injection.

### Source excerpt

How platform teams can safely deploy AI agents in regulated industries. Unifying privilege separation and the validation loop creates a single governance system that satisfies security and compliance

## Automating cloud infrastructure with Cursor

DevFeed: [Automating cloud infrastructure with Cursor](<https://devfeed.tech/articles/automating-cloud-infrastructure-with-cursor-17776.md>)

Original publisher: [Read original article](<https://encore.dev/blog/automating-cloud-infrastructure-with-cursor>)

Author: Ivan Cernja

Published: 2026-07-07T00:00:00Z

Content type: article

Language: en

Sources: [Encore Updates](<https://devfeed.tech/sources/encore-updates.md>)

Topics: [cursor](<https://devfeed.tech/topics/cursor.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Code](<https://devfeed.tech/topics/code.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [database](<https://devfeed.tech/tags/database.md>), [gcp](<https://devfeed.tech/tags/gcp.md>), [github](<https://devfeed.tech/tags/github.md>), [iam](<https://devfeed.tech/tags/iam.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [postgres](<https://devfeed.tech/tags/postgres.md>), [typescript](<https://devfeed.tech/tags/typescript.md>)

### AI overview

Encore describes how Cursor can provision cloud infrastructure declared alongside application code, allowing teams to deploy services to their own AWS or GCP accounts while retaining platform-team controls and review.

### Source excerpt

Now a Cursor agent can provision your cloud infrastructure from the same code it writes, on your own AWS or GCP.

## The unmanaged stack: Governing SaaS apps and AI tools outside SSO

DevFeed: [The unmanaged stack: Governing SaaS apps and AI tools outside SSO](<https://devfeed.tech/articles/the-unmanaged-stack-governing-saas-apps-and-ai-tools-outside-sso-1967.md>)

Original publisher: [Read original article](<https://1password.com/blog/the-unmanaged-stack-governing-saas>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-05-29T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Security](<https://devfeed.tech/topics/security.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-tools](<https://devfeed.tech/tags/ai-tools.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [iam](<https://devfeed.tech/tags/iam.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article recaps a 1Password webinar about governing SaaS applications and AI tools that operate outside traditional SSO and IAM controls. It describes the unmanaged stack, its governance and supply-chain risks, and 1Password integrations intended to help teams discover, review, and govern high-risk accounts and usage.

### Source excerpt

Note: This blog is a recap of 1Password's recent webinar, "The unmanaged stack: Governing SaaS apps and AI tools outside SSO." Head here to watch the complete webinar recording. In the constantly evolving world of enterprise tech, there's one thing that IT and security teams have always been able to count on: users won't follow policy if they think it's standing in the way of their productivity. Case in point: 1Password's most recent annual report found that 52% of employees have downloaded apps without IT approval. These shadow IT apps typically sit outside a company's SSO provider, and introduce both unmanaged risk and cost. That governance gap has become more pressing with the growing adoption of AI tools and agents, which introduce new and worsening threats. This issue was the focus of 1Password's recent webinar, "The unmanaged stack: Governing SaaS apps and AI tools outside SSO." What is the unmanaged stack? It refers to all of the SaaS apps and AI-based tools that can't be managed by traditional IAM tools, whether that's due to software constraints or the infamous "SSO tax." During the webinar, Evan Sandhu, 1Password Product Marketing Specialist, and Ethan Stoler, Senior Demo Engineer, explored how 1Password's solutions can help IT and security teams secure and govern these unapproved or unmanaged access points. Key takeaways from the webinar: SaaS and AI tools outside SSO create governance blind spots and can introduce supply chain risk. 1Password SaaS Manager helps discover unmanaged SaaS and AI usage, and help IT teams centralize provisioning, auditing, and lifecycle management. New integrations within 1Password support governance for ChatGPT, Claude, Cursor, and Gemini. Read on for an in-depth recap of the webinar's key themes. New integration features to manage high-risk SaaS and AI IT and security teams need solutions to manage those apps that fall outside the purview of SSO. Thankfully, new integrations between 1Password Enterprise Password Manager (EPM

## Modernizing Administrative Access for CMMC Level 2

DevFeed: [Modernizing Administrative Access for CMMC Level 2](<https://devfeed.tech/articles/modernizing-administrative-access-for-cmmc-level-2-29606.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/cmmc-level-2-admin-access/>)

Author: info@goteleport.com (Nicolas Morris)

Published: 2026-05-27T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Access Control](<https://devfeed.tech/topics/access-control.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [audit](<https://devfeed.tech/tags/audit.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [governance](<https://devfeed.tech/tags/governance.md>), [iam](<https://devfeed.tech/tags/iam.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [visibility](<https://devfeed.tech/tags/visibility.md>), [vpn](<https://devfeed.tech/tags/vpn.md>)

### AI overview

The article discusses administrative access challenges faced by organizations pursuing CMMC Level 2 readiness. It describes fragmented access across VPNs, local accounts, static SSH keys, cloud IAM, and disconnected authentication workflows, and presents Teleport as an identity-native approach to centralize governance, reduce standing privileges, and improve audit readiness.

### Source excerpt

Defense contractors pursuing CMMC Level 2 face persistent AC, IA, and AU findings. Coalfire outlines how Teleport addresses the enforcement and audit gaps assessors require.

## Announcing Keycloak's Identity Summit: KEYCONF26

DevFeed: [Announcing Keycloak's Identity Summit: KEYCONF26](<https://devfeed.tech/articles/announcing-keycloak-s-identity-summit-keyconf26-31774.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/05/keyconf26-prague-announce>)

Author: Nathalia Pinesi, Alexander Schwartz

Published: 2026-05-02T00:00:00Z

Content type: article

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [conference](<https://devfeed.tech/tags/conference.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [idm](<https://devfeed.tech/tags/idm.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oauth2](<https://devfeed.tech/tags/oauth2.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [summit](<https://devfeed.tech/tags/summit.md>)

### AI overview

Keycloak announces KEYCONF26, its annual Identity Summit for the Keycloak user community, taking place in Prague on October 8, 2026. The event will feature interactive sessions, practical discussions, networking, and a call for speakers and sponsors.

### Source excerpt

Our annual conference dedicated to the Keycloak user community returns, with even more content and networking opportunities than last year. It's the perfect place to interact, learn, share, and exchange insights and real-world use cases, network with fellow experts, users, and contributors. 📍 Introducing KEYCONF26 - taking place in Prague on October 8th, 2026! This year's edition of the Keycloak Identity Summit features interactive sessions, and even more opportunities to engage with the people shaping the future of identity and access management. Call for sessions The call for sessions is open until May 24th, 2026 -- we'd love to hear from you! We're looking for sessions on topics such as: Keycloak deployment and operations at scale Human and non-human identities in the world of AI OAuth2, OIDC, and evolving identity standards Security best practices and hardening EU Digital Identity Wallets and eIDAS Migration stories and real-world use cases Extending and customizing Keycloak Submit your proposal now! What to expect at KEYCONF26 Inspiring Keynote Speaker Hear from Hannah Short, Team Lead for Identity and Access Management at CERN, how they are using Keycloak as a highly performant and reliable SSO running on Kubernetes. Connect with like-minded professionals From long-time contributors to those just starting their IAM journey, KEYCONF26 is the perfect place to meet others working with identity, OAuth2, OIDC, and more. Networking lunch Our extended lunch break is designed to help you meet fellow attendees, swap ideas, and build meaningful professional connections in a relaxed setting. Business drinks Stick around after the last session for informal networking over drinks. Want to sponsor this year's Business Drink? Get in touch with us--we'd love to partner with you! Expert sessions and real-world use cases Gain practical insights into Keycloak implementation, security improvements, OAuth2 best practices, and evolving identity standards. Learn how to use EU Digital

## Guide: How to Unify Identity Across Cloud and Data Center Infrastructure

DevFeed: [Guide: How to Unify Identity Across Cloud and Data Center Infrastructure](<https://devfeed.tech/articles/guide-how-to-unify-identity-across-cloud-and-data-center-infrastructure-29954.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/unify-identity-cloud-data-centers/>)

Author: info@goteleport.com (Mayur Pipaliya)

Published: 2026-05-01T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [IAM](<https://devfeed.tech/topics/iam.md>), [trust](<https://devfeed.tech/topics/trust.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [SPIFFE](<https://devfeed.tech/topics/spiffe.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [data centers](<https://devfeed.tech/topics/data-centers.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [data-center](<https://devfeed.tech/tags/data-center.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-and-access](<https://devfeed.tech/tags/identity-and-access.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>)

### AI overview

This guide explains identity fragmentation across cloud accounts, data centers, and colocated infrastructure. It describes siloed identity systems, credential sprawl, and differing access models, and presents approaches including hardware roots of trust, short-lived certificates, shared certificate authorities, SPIFFE workload identities, reverse tunnels, and protocol-level enforcement.

### Source excerpt

Inside this guide, discover the root causes of identity fragmentation across cloud and data center environments -- and what it takes to unify identity.

## SCIM Realm API as an Experimental Feature

DevFeed: [SCIM Realm API as an Experimental Feature](<https://devfeed.tech/articles/scim-realm-api-as-an-experimental-feature-31770.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/04/scim-as-experimental-feature>)

Author: Keycloak Core IAM Team

Published: 2026-04-10T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [API](<https://devfeed.tech/topics/api.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [experimental](<https://devfeed.tech/tags/experimental.md>), [feature](<https://devfeed.tech/tags/feature.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.6 introduces the SCIM Realm API as an experimental feature. It enables clients using the SCIM protocol to manage users and groups, with compatibility work focused on Microsoft Entra ID. The article also explains how to enable and try the API.

### Source excerpt

If you have been following the latest blog posts, you may have noticed that we have been working on implementing the System for Cross-domain Identity Management (SCIM) protocol in Keycloak. We are excited to announce that the SCIM Realm API is now available as an experimental feature in Keycloak 26.6. The SCIM Realm API allows you to manage users and groups in Keycloak using the SCIM protocol. This means that you can use any SCIM client to manage the user and group resource types in your realm. This is a great step towards improving the integrability of Keycloak with other (cross-domain) IAM solutions and downstream applications, thereby enabling common cloud use cases for identity (de)provisioning. In terms of integration, we focused on making the API as compatible as possible with Microsoft Entra ID, which is the integration most demanded by the community. To do that, we have used the EntraID SCIM Validator to validate our implementation and ensure that it meets the requirements of Microsoft Entra ID. In essence, the SCIM Realm API is the Admin API but compliant with SCIM. How to try it out? Since this is an experimental feature (not enabled by default), you need to enable it when starting the server: docker run --name kc-scim-api -d \ -e KEYCLOAK_ADMIN=admin \ -e KEYCLOAK_ADMIN_PASSWORD=admin \ -p 8080:8080 \ quay.io/keycloak/keycloak:nightly \ start-dev --features=scim-api Let us create a realm myrealm and enable the SCIM API for it. To do that, you can use the kcadm.sh script to create the realm and enable the API. First, you need to configure the credentials for the kcadm.sh script to be able to connect to the server: ./kcadm.sh config credentials --server http://localhost:8080 --realm master --user admin --password admin Create the realm myrealm: ./kcadm.sh create realms -s realm=myrealm -s enabled=true -s scimApiEnabled=true Using the administration console, go to the Realm Settings page of your realm, and check that the SCIM API setting is enabled. Once the

## NIST and AI agents: 1Password's approach to agent identity

DevFeed: [NIST and AI agents: 1Password's approach to agent identity](<https://devfeed.tech/articles/nist-and-ai-agents-1password-s-approach-to-agent-identity-1893.md>)

Original publisher: [Read original article](<https://1password.com/blog/agent-identity>)

Author: info@1password.com (Jacob DePriest; Nancy Wang; Jeff Malnick)

Published: 2026-04-08T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article presents 1Password's approach to agent identity for AI agents. It describes identity as a set of challenges involving identification, attestation, enrollment, authentication, and authorization, with an emphasis on interoperability, continuous access decisions, and Zero Trust for reasoning workloads.

### Source excerpt

NIST published a concept paper stating, "Organizations need to understand how identity principles such as identification, authentication, and authorization can apply to agents to provide appropriate protections while enabling business value." This post, and the series that follows, is 1Password's response to NIST's call for input on how those principles should apply to agents. At 1Password, we approach security through simplicity. We are developing an agent identity architecture to simplify and enhance the security of AI agents, ensuring interoperability with existing systems. Our approach is built in collaboration with customers, partners, and the standards community. As part of this work, we recently responded to NIST's AI agent authorization paper. Our view is that agent identity is not a single problem. It is a set of challenges spanning identification, attestation, enrollment, authentication, and authorization for machine workloads with reasoning capabilities. The ability to reason is what sets AI agents apart from traditional machine workloads. This post is the first in a multi-part series on why agent-driven systems require us to rethink identity to enable continuous authentication and authorization for reasoning agents, and how that shapes both our response to NIST and our own approach to agent identity. The agent identity problem Where traditional machine workloads have a "set and forget" policy, the nature of reasoning workloads means a static policy can become out of date as the agent interprets and takes its next action. Agents that automatically deploy software are a great example of this escalation chain. A deployment agent begins with access to QA resources, but its access needs evolve when tests pass and may then require access to production services. The principle of Zero Trust maintains that you should provide only the minimum access needed, but infinitely evolving logic makes it difficult to apply the correct access for the lifetime of an agent pr

## KeycloakCon Japan 2026 Opens Call for Papers and Registration

DevFeed: [KeycloakCon Japan 2026 Opens Call for Papers and Registration](<https://devfeed.tech/articles/submit-to-keycloakcon-japan-call-for-papers-31763.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/03/keycloakcon-26-japan-call-for-papers>)

Author: Alexander Schwartz

Published: 2026-03-15T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [conference](<https://devfeed.tech/tags/conference.md>), [events](<https://devfeed.tech/tags/events.md>), [idm](<https://devfeed.tech/tags/idm.md>), [japan](<https://devfeed.tech/tags/japan.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [networking](<https://devfeed.tech/tags/networking.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

KeycloakCon Japan 2026 has opened its call for papers and registration. The half-day, single-track conference will take place in Yokohama on July 28, 2026, with sessions focused on Keycloak, IAM, SSO, features, updates, and real-world use cases. Submissions are due April 12, 2026, at 23:59 JST.

### Source excerpt

The call for papers and the registration for KeycloakCon Japan 2026 is now open! Submit your talks to KeycloakCon in Japan. KeycloakCon Japan 2026 is a half-day single-track conference in Yokohama, Japan on July 28 where the community of Keycloak gathers. It provides opportunities for technical presentations, growth, and networking with talks related to Identity and Access Management (IAM) and Single Sign On (SSO). This event is designed to share insights from developers and maintainers, as well as the latest features, updates, and real-world use cases of Keycloak. Participants will have the valuable opportunity to interact directly with Keycloak experts and other users, deepening their knowledge. Accepted session formats include presentations (25 min), panel discussions (35 min), and lightning talks (10 min). The call for papers deadline is April 12, 2026 (23:59 JST). Submit now! Registration KeycloakCon is a co-located event at KubeCon + CloudNativeCon Japan and requires a separate registration in addition to a KubeCon + CloudNativeCon Japan ticket. Accepted speakers receive a full access pass to KubeCon + CloudNativeCon Japan and the co-located event. Related Events The next day, on July 29-30, KubeCon Japan 2026 takes place in Yokohama as well. The Keycloak team will be on-site for KubeCon Japan, so join us and a lot of other CNCF projects for this event as well. See you in Yokohama!

## Keycloak outlines experimental SCIM support planned for version 26.6

DevFeed: [Keycloak outlines experimental SCIM support planned for version 26.6](<https://devfeed.tech/articles/thanks-for-your-feedback-on-scim-support-in-keycloak-31759.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/02/scim-support-survey-feedback>)

Author: Keycloak Core IAM Team

Published: 2026-02-26T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [implementation](<https://devfeed.tech/topics/implementation.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak describes early development of experimental SCIM support targeted for version 26.6. The initial focus is using Keycloak as a SCIM service provider for user provisioning and deprovisioning, while SCIM client support and integrations with external identity providers are also being explored.

### Source excerpt

First of all, we want to thank everyone who took the time to fill out our survey on SCIM support in Keycloak. Your feedback is invaluable to us as we work on implementing this feature. We are currently in the early stages of development, and we are using your feedback to guide our efforts. The survey results have shown us that there is a strong demand for SCIM support in Keycloak, and one of the most common use case is to use Keycloak as a SCIM service provider to manage user provisioning and deprovisioning for external applications. We are prioritizing this use case and driving the design and implementation of SCIM support in Keycloak to meet core set of requirements for this use case. In parallel, we are also exploring other use cases and requirements for SCIM support in Keycloak, such as using Keycloak as a SCIM client to integrate with external identity providers. As a result of this initial work, we are implementing a SCIM client that will allow in the future to address use cases where Keycloak can act as a SCIM client to integrate external SCIM service providers. Even though we are still delivering this feature as an experimental feature in the 26.6 release, the feedback we have received should allow us to deliver a solid implementation that meets the core requirements for the most common use case of using Keycloak as a SCIM service provider, and enable integrations any SCIM-compliant client, such as Microsoft Entra ID. That said, we have identified the initial scope for SCIM support in Keycloak targeting the 26.6 release, which will include the following capabilities: Expose realm users via the /Users endpoint with support for POST, PUT, PATCH, GET, and DELETE operations Expose realm groups via the /Groups endpoint with support for POST, PUT, PATCH, GET, and DELETE operations Support for a limited set of SCIM filters for querying resource types Support for pagination of results when querying resource types Support for fine-grained permissions to control acces

## Mastering IAM in Ceph: Multi-Tenancy, Access Control, and Why ACLs Must Die

DevFeed: [Mastering IAM in Ceph: Multi-Tenancy, Access Control, and Why ACLs Must Die](<https://devfeed.tech/articles/mastering-iam-in-ceph-multi-tenancy-access-control-and-why-acls-must-die-12334.md>)

Original publisher: [Read original article](<https://ceph.io/en/news/blog/2026/mastering-iam/>)

Author: Daniel Alexander Parkes, Anthony D'Atri

Published: 2026-01-24T00:00:00Z

Content type: article

Language: en

Sources: [Ceph Blog](<https://devfeed.tech/sources/ceph-blog.md>)

Topics: [IAM](<https://devfeed.tech/topics/iam.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Security](<https://devfeed.tech/topics/security.md>), [Multi-tenancy](<https://devfeed.tech/topics/multi-tenancy.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [ceph](<https://devfeed.tech/tags/ceph.md>), [defense-in-depth](<https://devfeed.tech/tags/defense-in-depth.md>), [en-article](<https://devfeed.tech/tags/en-article.md>), [en-blog-post](<https://devfeed.tech/tags/en-blog-post.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [multi-tenancy](<https://devfeed.tech/tags/multi-tenancy.md>), [operations](<https://devfeed.tech/tags/operations.md>), [production](<https://devfeed.tech/tags/production.md>), [rgw](<https://devfeed.tech/tags/rgw.md>), [s3](<https://devfeed.tech/tags/s3.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains why ACLs in Ceph Object Gateway should be disabled in favor of centralized IAM policies. It discusses S3 permission failures, multi-tenant access problems, AWS's ACL-disabled defaults, and defense-in-depth measures such as Block Public Access and explicit denies for ACL operations.

### Source excerpt

Introduction ¶ Introduction: When Security Theater Becomes a Real Disaster ¶ In March 2017, a misconfigured S3 bucket at Verizon exposed the personal information of 14 million customers. The root cause wasn't a sophisticated attack; it was a simple oversight in access permissions. The bucket was set to be publicly accessible due to S3 permission misconfiguration, and no one noticed because ACLs were managed separately from the company's centralized IAM policies. The security team had implemented careful, identity-based access controls, but a resource-level ACL silently bypassed them by granting access to "All Users." This scenario repeats constantly across the industry: ACLs creating invisible access paths that security teams don't know exist, buckets accidentally exposed to the public internet, and contractors uploading data that the bucket owner cannot reliably read or administer, while still consuming capacity. Between 2017 and 2019, major companies exposed hundreds of millions of records via misconfigured S3 permissions (ACLs and/or bucket policies): Verizon (2017): 14 million customers - An AWS S3 bucket configured for public access exposed names, addresses, account PINs Facebook (2019): 540 million records - Third-party apps stored user data in publicly accessible S3 buckets Instagram (2019): 49 million records - Marketing firm left influencer database unprotected in AWS S3 The AWS response was clear: since April 2023, all new S3 buckets default to "ACLs disabled" (BucketOwnerEnforced) and Block Public Access enabled. AWS strongly recommends disabling ACLs on existing buckets and migrating to a pure policy-based model with IAM Accounts architecture. If you're running the Ceph Object Gateway (RGW), you have access to the same IAM Accounts model introduced in Ceph Squid 19.2.0. This post explains why ACLs must be disabled immediately and how to implement modern, secure access control with IAM policies. Do This First (Quick Security Wins) Before reading further,

## SCIM Support Survey

DevFeed: [SCIM Support Survey](<https://devfeed.tech/articles/scim-support-survey-31752.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/01/scim-support-survey>)

Author: Keycloak Core IAM Team

Published: 2026-01-19T00:00:00Z

Content type: article

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [IAM](<https://devfeed.tech/topics/iam.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [survey](<https://devfeed.tech/tags/survey.md>), [use-cases](<https://devfeed.tech/tags/use-cases.md>)

### AI overview

Keycloak is targeting version 26.6 to begin supporting System for Cross-domain Identity Management (SCIM). The project is conducting a survey to understand community use cases and prioritize capabilities for the initial scope.

### Source excerpt

We are targeting Keycloak 26.6 to start supporting System for Cross-domain Identity Management (SCIM). The initial scope have been defined in this issue, but we want to ensure that we are addressing the most important use cases for our community. In order to better understand your needs and use cases around SCIM, we would greatly appreciate your participation in a brief survey. Your feedback will be invaluable in helping us to prioritize capabilities and ensure we are addressing the use cases that matter most to you. You can find the survey here.

## Keycloak's Bug Bounty Program on YesWeHack

DevFeed: [Keycloak's Bug Bounty Program on YesWeHack](<https://devfeed.tech/articles/keycloak-s-bug-bounty-program-on-yeswehack-31742.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/01/bugbounty-yes-we-hack>)

Author: Alexander Schwartz

Published: 2026-01-16T00:00:00Z

Content type: news

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak announces its public bug bounty program on YesWeHack as part of an EU-sponsored initiative. The program is currently paused while submissions are reviewed after receiving many submissions.

### Source excerpt

As a Cloud Native Computing Foundation (CNCF) project, Keycloak is the open-source IAM backbone for countless applications. This is your chance to secure a core piece of the cloud-native ecosystem in this public bug bounty program!. We are proud to be part of this EU sponsored initiative. Projects like ours fuel a lot of public and private infrastructure in the EU and worldwide. Thank you for choosing our project for this initiative to help us to improve and provide secure services to our users! We received a lot of good submissions to the program. While we sort out the submissions, the program is paused.

## 2026 Cybersecurity Predictions by Teleport CEO Ev Kontsevoy

DevFeed: [2026 Cybersecurity Predictions by Teleport CEO Ev Kontsevoy](<https://devfeed.tech/articles/2026-cybersecurity-predictions-by-teleport-ceo-ev-kontsevoy-29541.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/2026-cybersecurity-predictions/>)

Author: ev@goteleport.com (Ev Kontsevoy)

Published: 2025-12-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [non-human-identity](<https://devfeed.tech/tags/non-human-identity.md>), [predictions](<https://devfeed.tech/tags/predictions.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Teleport CEO Ev Kontsevoy presents predictions for 2026 cybersecurity, arguing that AI identities will drive a unified approach to identity management, greater engineering involvement in security, and more granular definitions of agentic AI.

### Source excerpt

AI has broken identity security--2026 is when the cracks become impossible to ignore. Teleport CEO Ev Kontsevoy shares predictions and what leaders should do.

## AWS re:Invent serverless features available in Serverless Framework v4

DevFeed: [AWS re:Invent serverless features available in Serverless Framework v4](<https://devfeed.tech/articles/newsletter-use-new-aws-re-invent-features-today-14460.md>)

Original publisher: [Read original article](<https://www.serverless.com/blog/use-new-aws-re-invent-features-today>)

Author: Serverless Team

Published: 2025-12-09T00:00:00Z

Content type: article

Language: en

Sources: [Serverless Blog](<https://devfeed.tech/sources/serverless-blog.md>)

Topics: [Serverless](<https://devfeed.tech/topics/serverless.md>), [serverless framework](<https://devfeed.tech/topics/serverless-framework.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Streaming](<https://devfeed.tech/topics/streaming.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [networking](<https://devfeed.tech/topics/networking.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [cloud-computing](<https://devfeed.tech/tags/cloud-computing.md>), [faas](<https://devfeed.tech/tags/faas.md>), [features](<https://devfeed.tech/tags/features.md>), [framework](<https://devfeed.tech/tags/framework.md>), [function-as-a-service](<https://devfeed.tech/tags/function-as-a-service.md>), [iam](<https://devfeed.tech/tags/iam.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [livestream](<https://devfeed.tech/tags/livestream.md>), [networking](<https://devfeed.tech/tags/networking.md>), [news](<https://devfeed.tech/tags/news.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [serverless-architecture](<https://devfeed.tech/tags/serverless-architecture.md>), [serverless-framework](<https://devfeed.tech/tags/serverless-framework.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [subscription](<https://devfeed.tech/tags/subscription.md>)

### AI overview

Serverless Framework v4 already includes several AWS re:Invent serverless launches, including new runtimes, streaming APIs, tenant isolation, and expanded IAM and networking controls. The article also mentions a livestream deep-dive and a limited-time subscription offer.

### Source excerpt

AWS re:Invent's biggest serverless launches are already live in Serverless Framework v4, with new runtimes, streaming APIs, tenant isolation, enriched IAM and networking controls, and more - all ready to use today, alongside a livestream deep-dive and a limited-time subscription offer.

## Newsletter: Improved Python Support, Merging Plugins into Core, and more

DevFeed: [Newsletter: Improved Python Support, Merging Plugins into Core, and more](<https://devfeed.tech/articles/newsletter-improved-python-support-merging-plugins-into-core-and-more-14289.md>)

Original publisher: [Read original article](<https://www.serverless.com/blog/newsletter-nov-2025-improved-python-support-merging-plugins-into-core-and-more>)

Author: Serverless Team

Published: 2025-11-18T00:00:00Z

Content type: news

Language: en

Sources: [Serverless Blog](<https://devfeed.tech/sources/serverless-blog.md>)

Topics: [serverless framework](<https://devfeed.tech/topics/serverless-framework.md>), [Python](<https://devfeed.tech/topics/python.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [cloud-computing](<https://devfeed.tech/tags/cloud-computing.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [faas](<https://devfeed.tech/tags/faas.md>), [function-as-a-service](<https://devfeed.tech/tags/function-as-a-service.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [iam](<https://devfeed.tech/tags/iam.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [news](<https://devfeed.tech/tags/news.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [plugins](<https://devfeed.tech/tags/plugins.md>), [python](<https://devfeed.tech/tags/python.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [serverless-architecture](<https://devfeed.tech/tags/serverless-architecture.md>), [serverless-framework](<https://devfeed.tech/tags/serverless-framework.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

A Serverless Framework newsletter recaps built-in Python support, plugin consolidation into core, reliability improvements during upstream outages, IAM changes, and planned OpenTelemetry configuration and expanded variable resolution. It also mentions a limited-time discount and hiring for the Framework team.

### Source excerpt

Serverless Framework is closing out the year with major updates--new Python support built in, improved reliability during upstream outages, key IAM changes, and upcoming features like OpenTelemetry configuration and expanded variable resolution--while also offering a limited-time 20% end-of-year discount and actively hiring for the Framework team. This post recaps what's new, what's coming next, and how to get involved.

## Keycloak reaches 30,000 GitHub stars

DevFeed: [Keycloak reaches 30,000 GitHub stars](<https://devfeed.tech/articles/keycloak-celebrates-30k-stars-31725.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/10/30k-stars-celebration>)

Author: Keycloak Team

Published: 2025-10-08T00:00:00Z

Content type: opinion

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [IAM](<https://devfeed.tech/topics/iam.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [contributors](<https://devfeed.tech/tags/contributors.md>), [github](<https://devfeed.tech/tags/github.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak marks reaching 30,000 GitHub stars and credits its users and contributors. The article also notes that more than 1,350 contributors have helped develop the project.

### Source excerpt

This is a huge moment for all of us! 🚀🎉 Reaching 30,000 stars on GitHub is not just another number -- it is a powerful signal of how far Keycloak has come, how much trust the community has placed in it, and how essential it has become in the world of open source Identity and Access Management (IAM). 30,000 stars is a testament to a thriving global community, the trust of developers and enterprises, and Keycloak's place as the go-to open source solution for securing apps and services. It is a milestone that reflects years of collaboration, contribution, and community passion -- and we couldn't be prouder. We're deeply grateful to our users and contributors whose support and contributions turned this milestone into reality -- this wouldn't have been possible without you! As seen on the graph below, Keycloak just keeps getting more and more love on GitHub, with stars growing faster every year. It is clear that more people are discovering and relying on it for their IAM needs. Keycloak is on a great track and the community momentum is stronger than ever. 🚀 Thank YOU! Over the years, more than 1,350+ contributors have shaped Keycloak into what it is today. From fixing bugs and adding features to improving docs and helping others, every contribution has played a role in making the project thrive. This incredible community effort is what turned Keycloak into one of the most trusted open source solutions for securing applications and services. We're grateful to every single contributor who has helped make Keycloak better and better! 🎉 Let's give it up for Keycloak's top contributors (more than 10 contributions): Thank you all!

[Next page](<https://devfeed.tech/topics/iam.md?cursor=WyIyMDI1LTEwLTA4VDAwOjAwOjAwKzAwOjAwIiwgImViOWY5Y2JmLTJjZWMtNGU3NC04ZjA4LWZhYjExMzg0MWZhYiJd>)