IT & Spend Operations

Identity & Access Management Software

Identity and access management (IAM) software controls who can sign in to which applications and what they can do there. It holds a directory of user identities, provides single sign-on and multi-factor authentication, creates and removes accounts in connected apps, and records who has access to what.

capabilities we evaluate
10
product research
In progress
last updated

LeadChange may earn a fee when you request pricing through our site or follow a sponsored link. Rankings are computed without knowing which vendors pay us.

Research in progress

We are verifying identity & access management products against vendors’ official documentation and pricing pages. A ranking by LeadChange Score appears here once at least 3 products pass our research checks. Until then, this page explains what the software does, what we evaluate and how to choose.

What we evaluate

  • Single sign-on

    Lets users sign in once to reach connected applications.

  • Multi-factor authentication

    Requires additional factors at sign-in, enforced by policy.

  • User directory

    Holds identities, groups and attributes in one place.

  • HR-driven provisioning

    Uses the HRIS as the source of truth for hires, moves and terminations.

  • App provisioning and deprovisioning

    Creates, updates and removes accounts in connected apps.

  • Role-based access

    Assigns access by group, role or attribute rules.

  • Access requests and approvals

    Lets users request access with approvals on record.

  • Access reviews

    Runs campaigns where managers confirm or revoke access.

  • Adaptive sign-in policies

    Uses device, location and risk signals in access decisions.

  • Audit logs

    Records sign-ins, access changes and approvals for export.

Who needs identity & access management software?

You need identity and access management software when employees juggle separate passwords for many apps, when new hires wait for accounts, or when you cannot prove that a former employee lost access on their last day. Customer security questionnaires and audits that ask how access is granted, reviewed and removed are another common trigger.

The workforce angle is central. Joiners need the right accounts on day one, movers need access added and removed as their role changes, and leavers must be cut off everywhere at once. Tying IAM to the HRIS turns those steps from tickets into rules.

A very small company using a few apps can rely on the built-in identity features of its email and productivity suite. Move to a dedicated IAM platform when the number of apps, people or audit requests makes manual account management unreliable.

How to choose identity & access management software

Start from your app inventory and your employee lifecycle. List the applications people use, how accounts are created and removed in each today, and who approves access. The gaps show which features matter.

In the demo, connect a test HRIS record, hire a test employee, change their department and terminate them, and watch what happens in each connected app.

  1. Single sign-on coverage

    Single sign-on only reduces risk and friction if it covers the apps your people actually use.

  2. Multi-factor authentication options

    Authenticator strength varies, and phishing-resistant methods matter for privileged users.

  3. HR-driven provisioning

    Using the HRIS as the source of truth lets hires, moves and terminations change access automatically.

  4. Automated provisioning and deprovisioning in apps

    Single sign-on alone does not remove local accounts or reclaim licenses in each app.

  5. Role and group based access

    Access granted by role scales better and is easier to review than one-off grants.

  6. Access requests and approvals

    Employees need a clear path to request access beyond their role, with an approver on record.

Requirements by company size

  • Small businesses

    • Single sign-on and multi-factor authentication for core apps
    • One-click deprovisioning for leavers
    • Simple setup without a dedicated identity team

    Watch out for

    • Key features such as provisioning reserved for top tiers
    • Per-app connector fees
    • Paying for governance features you will not use
  • Mid-sized companies

    • HRIS as the source of truth for identities
    • SCIM provisioning for most of your apps
    • Access reviews for audit evidence

    Watch out for

    • Apps that support single sign-on but not provisioning
    • Group rules that grow unmanageable
    • Governance features sold as a separate product
  • Enterprises

    • Fine-grained role and policy management
    • Access certification campaigns and segregation of duties checks
    • Integration with privileged access, device management and security monitoring

    Watch out for

    • Long role-modeling projects before value
    • Coexistence with legacy directories during migration
    • Custom connectors that need ongoing maintenance

Red flags

  • No integration with your HRIS as a source of identity data
  • Deprovisioning only disables the single sign-on account and leaves app accounts active
  • Multi-factor authentication cannot be enforced by policy
  • No exportable audit log of access changes and approvals
  • Access reviews cannot actually revoke access

Learn

Full HR glossary

Frequently asked questions

What is identity and access management software?

Identity and access management software manages user identities and controls which applications and data each person can reach. It typically provides a user directory, single sign-on, multi-factor authentication, automated account provisioning and deprovisioning, and audit logs of access changes.

What is the difference between IAM and single sign-on?

Single sign-on is one feature of IAM: it lets users sign in once to reach many apps. IAM also covers multi-factor authentication, creating and removing accounts in each app, role-based access, access reviews and audit reporting. Single sign-on alone does not remove a leaver's local app accounts or licenses.

How does HR-driven provisioning work?

The HRIS is set as the source of identity data. When HR records a hire, the IAM system creates the identity and the accounts for that role. When a department or title changes, group rules add and remove access. When HR records a termination, the identity is disabled and connected app accounts are deprovisioned, often through the SCIM standard or app APIs.

What are examples of identity and access management tools?

The main tool types are workforce identity platforms that provide single sign-on, multi-factor authentication and lifecycle management; identity governance tools focused on access requests, reviews and certifications; privileged access management for administrator accounts; and directory services. Many buyers start with a workforce identity platform and add governance later.

What standards apply to digital identity and authentication?

NIST SP 800-63, the Digital Identity Guidelines, covers the process and technical requirements for digital identity assurance levels for identity proofing, authentication and federation. It is a useful reference when deciding how strong authentication should be for different users and apps, even outside government.

Do small businesses need IAM software?

A small business on one productivity suite can often use its built-in identity features for single sign-on and multi-factor authentication. Dedicated IAM becomes worth it when you use many apps, hire and lose staff often, or face customer security reviews asking how access is removed.

How much does identity and access management software cost?

Most workforce IAM is priced per user per month, with tiers or separate products for single sign-on, multi-factor authentication, lifecycle management and governance. Ask for a quote that lists every product needed for HR-driven provisioning and access reviews, minimum user counts and any connector fees.

How we research

Products are ranked by the LeadChange Score, computed only from verified facts: capability coverage (30%), pricing transparency and value (20%), integrations and API (15%), security and compliance (15%), fit and support (10%) and data confidence (10%), times a category fit that lowers products built for another job. Payment never changes a score or a position.

Read the full methodology

  • Facts, not impressions

    Every input is a fact verified against vendors’ official documentation, with the date we last checked it.

  • Missing data scores zero

    We never assume a feature; unverified items lower the confidence label.

  • Independent of revenue

    Rankings are computed before and without knowing which vendors pay us.

Tell us what you need

We are still verifying products in this category, so no shortlist is shown yet. Tell us about your team and we keep your request; it is shared only with your consent.