TL;DR: Legacy IAM tools still centre on authentication and perimeter-era access patterns, but modern attackers are stealing credentials, hijacking sessions, and exploiting fragmented identity data to move laterally, according to Zluri and a 2025 Forbes Technology report that puts identity-based attacks at 87% of breaches. Legacy IAM is failing because access control now has to follow identity context, not just validate login events.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Why Legacy IAM Fails Against Modern Identity-Centric Attacks”.
Key questions
Q: What breaks when legacy IAM still stops at authentication?
A: Authentication-only IAM breaks when attackers reuse stolen credentials or session tokens, because the system accepts the login without evaluating whether the requested action fits the user’s device, behaviour, or privilege context.
Q: Why do fragmented identity records increase risk in large organisations?
A: Fragmented identity records increase risk because defenders cannot reliably tell which accounts belong to the same person, task, or workload.
Q: How should security teams reduce overprovisioned access in IAM?
A: Security teams should replace broad group membership with task-aware, context-aware provisioning that ties access to responsibility, sensitivity, and current need.
Practitioner guidance
- Audit identity visibility across all account types Map employees, contractors, vendors, service accounts, bots, and APIs into a single inventory so hidden access paths are not left outside governance.
- Add authorization controls after authentication Require post-login checks for device posture, session context, and risk signals before granting sensitive actions or elevated access.
- Reconcile fragmented identity records Match and merge duplicate identity records across SSO, MFA, PAM, and lifecycle tools so offboarding and recertification target every active account.
Bottom line: Legacy IAM is vulnerable because it treats successful authentication as a sufficient trust signal even when attackers reuse stolen credentials or hijacked sessions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Legacy IAM is built on a perimeter-era assumption that identity proves trust once at login. That assumption fails when the adversary’s entry point is stolen identity material rather than network intrusion. The result is a control plane that treats authenticated presence as sufficient evidence of legitimacy. The implication is that access governance now has to evaluate identity state continuously, not just admit the session.
A question worth separating out:
Q: What should teams do when identities span SSO, PAM, and lifecycle tools?
A: Teams should build a reconciled identity source that matches records across systems before making offboarding or access review decisions. Without reconciliation, one system can deactivate an identity while another keeps it alive. That is an accountability problem as much as a technical one, because no single control view can prove access has actually ended.
👉 Read our full editorial: Legacy IAM leaves identity-centric attacks with too many gaps