Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

SAML, agentic AI, and PQC: what identity teams need to do


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: Government agencies cannot treat SAML modernization, agentic AI access, and post-quantum cryptography as separate projects because legacy federation, machine-speed delegation, and cryptographic transition are colliding in the same access path, according to Ping Identity. The real problem is that human-era identity assumptions no longer match runtime agent behaviour or long-lived protocol dependencies, and the edge becomes the practical control point.

NHIMG editorial — based on content published by Ping Identity: How Gateway Addresses Quantum and AI Threats to Government SAML

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agent access in legacy SAML environments?

A: They should keep SAML for what it does well, but move decision-making to the request path.

Q: What breaks when organisations rely on SAML alone for agentic AI?

A: The failure is contextual blind spots.

Q: When should agencies prioritise gateway controls over full application replacement?

A: They should prioritise the gateway when mission systems must stay online and the application estate cannot be modernised all at once.

Practitioner guidance

  • Map the full identity transaction path Inventory identity providers, service providers, certificates, signing and encryption algorithms, libraries, and backend dependencies so you know which segments still rely on classical trust or legacy federation.
  • Move authorisation into the request path Require policy checks at the edge for agent and service requests so a single login event does not grant broad standing access across multiple tools and applications.
  • Separate gateway protection from PQC claims Treat gateway deployment as a control and visibility layer, then track each downstream assertion, certificate, and internal connection that still needs cryptographic modernization.

What's in the full article

Ping Identity's full article covers the operational detail this post intentionally leaves for the source:

  • How the gateway mediates OAuth 2.0, OIDC, SAML assertions, headers, and cookies in mixed estates
  • The phased migration roadmap for inventorying certificates, signing algorithms, and backend trust relationships
  • Specific edge enforcement patterns for AI agent requests before they reach protected APIs
  • How agencies should separate gateway protection from end-to-end PQC compliance

👉 Read Ping Identity's analysis of gateway controls for SAML, agentic AI, and PQC →

SAML, agentic AI, and PQC: what identity teams need to do?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

Legacy federation becomes a liability when it is treated as a universal authorisation layer. SAML still has a place for browser-era applications, but it cannot describe the full context of agent-driven requests or machine-speed delegation. The article correctly points to the edge because authorisation now has to follow the request path, not sit only at login. The practitioner conclusion is that identity architecture must distinguish session establishment from action approval.

A few things that frame the scale:

  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which means most identity teams cannot reliably scope the blast radius of machine access.

A question worth separating out:

Q: How can teams tell whether a gateway is actually improving identity security?

A: Look for narrower standing access, policy enforcement before backend exposure, clearer audit trails for each request, and a documented inventory of remaining SAML and cryptographic dependencies. If requests still reach applications without edge policy or if ownership is unclear, the gateway is only partial protection.

👉 Read our full editorial: Gateway-based identity control for SAML, AI agents, and PQC



   
ReplyQuote
Share: