TL;DR: Cybersecurity has stayed fragmented because specialist vendors keep solving narrow problems faster than large platforms can absorb them, especially in on-premises environments where Active Directory still leaves gaps in MFA, session control, and contextual access, according to IS Decisions. The lesson for identity teams is that platform consolidation does not erase control-plane complexity.
At a glance
What this is: This is an analysis of why specialist security point solutions continue to matter, with UserLock used as an example of closing Active Directory gaps around concurrent logins, MFA, and session-level control.
Why it matters: It matters because IAM teams still operate mixed estates where platform coverage is incomplete, and NHI, autonomous, and human identity governance all fail when controls stop at authentication.
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
👉 Read IS Decisions' analysis of why specialist identity controls still matter
Context
Identity security does not collapse neatly into a single platform problem. In mixed environments, authentication is only the first control point, while session context, remote access path, and post-login privilege still determine whether the identity model actually holds. That is why the primary keyword, identity security, continues to be a governance problem rather than a product category.
The article argues that on-premises and Active Directory environments still create practical control gaps that cloud-first IAM stacks do not fully address. For IAM practitioners, the real issue is not whether consolidation is attractive in theory, but whether a platform can govern the full identity lifecycle across human, non-human, and session-level access without leaving blind spots.
IS Decisions presents UserLock as a case study in solving one operational gap at a time, starting with concurrent logins and then extending into MFA, SSO, and contextual access controls. That is a typical pattern in enterprise identity, not an edge case: the hardest controls often emerge where native directory capabilities stop.
Key questions
Q: What is the main identity security gap that point solutions still fill in enterprise environments?
A: Point solutions still fill the gap between authentication and full session governance. In mixed estates, native directory or cloud IAM tools may authenticate a user, but they do not always control concurrent sessions, contextual access paths, or post-login privilege use. That is where specialist controls remain necessary.
Q: Why do cloud IAM platforms often fall short in on-premises identity governance?
A: Cloud IAM platforms are usually optimised for a single login flow and a central policy layer. On-premises estates include RDP, RemoteApp, internal network access, and offline conditions, so the control problem is broader than sign-in. The risk is assuming one front door governs the whole estate.
Q: What do security teams get wrong about MFA for non-human identities?
A: They often assume one access-control pattern can cover both humans and machines. That is the mistake. Human MFA strengthens interactive sign-in, but it does not govern an automation identity that is meant to run without user input. NHI governance has to start with the identity type, not the authentication ceremony.
Q: When should organisations rely on specialist identity controls instead of one platform?
A: Organisations should rely on specialist controls when the environment includes legacy applications, air-gapped systems, or access paths that do not fit a standard cloud SSO model. In those cases, a single platform may centralise policy but still leave enforcement gaps that need targeted controls.
Technical breakdown
Why authentication is not the same as session control
Authentication answers who or what signed in. Session control answers what that identity can do after sign-in, from which device, over which protocol, and under which contextual policy. In on-premises estates, those are separate problems because RDP, RemoteApp, server access, and internal network sessions behave differently from cloud login flows. A control plane that stops at the login event cannot see concurrent sessions, abnormal reuse, or post-authentication privilege drift. That distinction matters in identity security because many breaches begin after authentication succeeds, not before.
Practical implication: Map controls beyond sign-in so session policy, not just MFA, governs what happens after authentication.
Why Active Directory alone leaves contextual access gaps
Active Directory remains foundational, but its native controls were not built to fully answer modern questions about contextual access, concurrent logins, or device-sensitive policy enforcement. When organizations use only directory-native functions, they often compensate with manual reviews or accept residual risk around remote access and session visibility. The technical issue is not that AD is broken, but that its default capabilities do not cover the whole decision tree for access governance in mixed estates. That is why specialist controls keep appearing around the directory rather than being fully absorbed by it.
Practical implication: Assess where directory-native access logic ends, then apply compensating controls for remote, contextual, and concurrent-session risk.
Why platform consolidation does not erase edge-case identity problems
Large platforms optimize for common paths, especially federated authentication and centralized policy administration. They are much weaker where the environment is heterogeneous, offline, or operationally messy. Air-gapped networks, legacy applications, and site-specific access patterns produce governance requirements that do not fit a single cloud login model. In practice, that means the last mile of identity security often remains a composition problem: one system handles identity proofing or SSO, another handles session governance, and a third handles edge conditions. Security architecture still has to integrate those pieces deliberately.
Practical implication: Design for composable identity controls where one platform cannot reliably govern every access path.
NHI Mgmt Group analysis
Specialist controls persist because the control problem is still fragmented. The article shows that cybersecurity consolidation has not removed the need for narrow tools that solve specific identity gaps. Authentication, session control, and contextual enforcement are different control problems, and enterprise estates still need separate answers for each. For identity teams, the practical conclusion is that platform breadth does not replace control precision.
On-premises identity governance remains structurally different from cloud IAM governance. Cloud-first models assume a single front door and a consistent authentication flow, while on-premises environments include RDP, RemoteApp, internal sessions, and air-gapped conditions. That means least privilege and access enforcement have to be evaluated against the actual access path, not just the login event. IAM programmes that ignore this distinction will keep missing their real enforcement boundary.
Session-level governance is the named concept here: access must be governed after authentication, not only before it. The article's core lesson is that sign-in success is not the end of the control problem. Once an identity is active, session context and privilege use determine whether the access model holds or fails. Practitioners should treat session governance as a separate control layer, especially where native directory functions stop.
Platform dependency can create blind spots when organisations assume the stack is complete. The article makes clear that larger platforms often centralise common IAM functions while leaving edge conditions to be solved elsewhere. That assumption is unsafe in mixed estates because the hardest access cases are usually the least standardised ones. The implication is that teams should evaluate governance by coverage, not by platform count.
Continuous improvement is the operating model identity security actually requires. The article's historical arc is useful because it shows that each solved problem reveals a deeper one. MFA, SSO, session monitoring, and privilege oversight are not final states, they are successive layers responding to changing threat conditions. For practitioners, that means identity governance should be measured by how fast it closes the next gap, not by how complete the current stack looks.
From our research:
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to The 2024 Non-Human Identity Security Report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
- A useful next read is OWASP Agentic AI Top 10 for understanding how dynamic tool use expands identity and access risk.
What this signals
Session-level governance will remain the differentiator in hybrid estates. Teams that centralise authentication but ignore protocol-specific enforcement will keep finding gaps at the point where users move from login to active use. The programme question is no longer whether identity is federated, but whether the access decision still holds once the session begins.
Platform consolidation does not eliminate the need for composable identity control. In practice, security teams will keep stitching together directory controls, contextual access policy, and post-authentication monitoring because no single stack cleanly covers every estate condition. The strongest programmes will measure coverage across connection types, not just control adoption counts.
With 88.5% of organisations saying their non-human IAM lags human IAM, per The 2024 Non-Human Identity Security Report, the same structural problem is visible in machine and agent access governance: broad platforms rarely close the last-mile enforcement gap on their own.
For practitioners
- Inventory identity control gaps beyond sign-in List where authentication, session control, and contextual enforcement are handled by different systems or by manual exception handling. Prioritise remote access, RDP, RemoteApp, server access, and air-gapped segments first.
- Separate cloud login governance from on-premises session governance Do not assume a central SSO layer covers post-authentication behaviour in legacy estates. Define which controls must inspect device, protocol, and session context after sign-in.
- Review concurrent access and shared-session risk Check for identities that can open multiple simultaneous sessions or reuse access paths without detection. Tie any exceptions to explicit business need and monitoring requirements.
- Use compensating controls where native directory logic stops Apply targeted monitoring and privilege constraints where Active Directory does not natively enforce the policy you need. Treat this as a control coverage problem, not a product preference.
Key takeaways
- Identity security still breaks at the boundary between authentication and session governance, not just at login.
- Mixed estates keep specialist controls relevant because cloud-style access models do not fully cover on-premises complexity.
- Practitioners should measure control coverage by access path, session behaviour, and post-login privilege, not by platform count.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | The article centres on access enforcement across mixed identity paths. |
| Recommendation: Map access enforcement to PR.AC-4 and verify each access path has a matching control. | ||
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is relevant where session scope and access path must be constrained. |
| Recommendation: Apply AC-6 to limit post-authentication privilege by role, path, and business need. | ||
| NIST SP 800-53 Rev 5 | IA-2 | The article begins with authentication, then shows why that is not enough. |
| Recommendation: Use IA-2 to strengthen authentication while separately governing session activity. | ||
| NIST Zero Trust (SP 800-207) | 3.1 | Zero trust is relevant where each session and path requires separate verification. |
| Recommendation: Treat each access path as independently verifiable instead of assuming a trusted network. | ||
| NIST CSF 2.0 | DE.CM-1 | Session-level monitoring is central to the article's control-gap argument. |
| Recommendation: Use DE.CM-1 to continuously monitor access behaviour after authentication. | ||
Key terms
- Session Governance: The practice of binding access to a specific task, time window, and execution context, then revoking it when the work is done. For non-human identities, session governance matters because tokens and delegated permissions often persist longer than the action they were created to support.
- Contextual Access Control: Contextual access control changes access decisions based on factors such as device posture, application risk, location, or data sensitivity. In cloud security, it helps move access policy from static entitlements toward decisions that reflect the actual conditions of use.
- Concurrent Logins: Concurrent logins occur when one user account is active in more than one session at the same time. In identity security, that can mask credential sharing, weaken audit clarity, and increase the blast radius of stolen credentials. Limiting concurrent sessions is often used to tighten control around sensitive or privileged access.
What's in the full article
IS Decisions' full analysis covers the operational detail this post intentionally leaves for the source:
- How UserLock addresses concurrent logins and session-level access enforcement in on-premises environments
- The stepwise feature evolution from MFA and SSO into contextual controls for Active Directory estates
- Why the vendor frames air-gapped and remote access as distinct control problems rather than a single IAM category
- Practical examples of how small, specialist tools fit alongside larger cloud IAM platforms
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building a stronger identity security programme, it is worth exploring.
Published by the NHIMG editorial team on September 5, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org