Skip to content
By IAM

Top Identity Governance and Administration (IGA) Solutions Compared

IGA platforms compared on access certifications, separation of duties, role management and AI agent governance, with verified pricing and 2026 market changes.

If an auditor has asked you to prove who approved a finance user's access, or your quarterly access review still runs on spreadsheets, you need an identity governance and administration (IGA) platform. Short answer: large regulated enterprises should shortlist SailPoint, Saviynt, Omada and One Identity. Microsoft-first shops should price Microsoft Entra ID Governance first. SaaS-heavy mid-market teams should look at C1 (formerly ConductorOne), Lumos, Zluri or tenfold. SAP-centric finance teams should add Pathlock.

IGA answers a governance question: should this person, service account or AI agent hold this access, who approved it, and can you prove it to an auditor? That means access certifications, separation of duties (SoD), role mining and role management, policy, and audit evidence. This page ranks the platforms that do that work. Account creation and HR-driven joiner-mover-leaver automation have their own guides, linked at the end.

Last verified: September 2026. Vendor ownership, product names, acquisitions and every listed price were checked against vendor-owned pages, investor relations releases and SEC filings. See How we evaluated below.

What changed in the IGA market in 2025 and 2026

The IGA market consolidated fast, and the biggest theme is governing non-human identities (NHIs) and AI agents alongside employees.

  • SailPoint went public again. It priced its upsized IPO at $23 per share and began trading on Nasdaq as SAIL on February 13, 2025 (SailPoint press release). It then bought key assets of SaaS-visibility startup Savvy in 2025 (Savvy), launched Agentic Fabric on May 11, 2026 (SailPoint), and closed its acquisition of NHI security vendor Entro on June 29, 2026 (SailPoint).
  • CyberArk bought an IGA product, then was bought itself. CyberArk acquired AI-driven IGA vendor Zilla Security in February 2025 (CyberArk release). Palo Alto Networks completed its acquisition of CyberArk on February 11, 2026 (Palo Alto Networks). The CyberArk platform, including its governance capabilities, is now sold as Idira (Palo Alto Networks).
  • ServiceNow now owns Veza. The deal was announced December 2, 2025 (ServiceNow) and closed March 2, 2026 (Veza). Veza's access graph maps effective permissions and now sits inside the ServiceNow platform.
  • CrowdStrike bought SGNL. Announced January 8, 2026 (CrowdStrike IR), completed February 20, 2026 per CrowdStrike's 10-Q filing. SGNL's site now says it is part of CrowdStrike. SGNL is continuous, risk-based authorization rather than a certification-driven IGA suite.
  • Independent vendors raised big rounds. Saviynt raised $700M at roughly a $3B valuation in a KKR-led round in December 2025 (Saviynt). ConductorOne, now rebranded as C1, raised a $79M Series B led by Greycroft (Greycroft).

For the wider picture of machine and agent access, see the non-human identity vendor map and the guide to identity for AI agents.

Quick comparison

PlatformBest forGovernance strengthDeploymentPublic pricing
SailPoint Identity Security (and IdentityIQ)Large regulated enterprisesCertifications, role mining, SoD, AI agent governanceSaaS or self-managedQuote only
Saviynt Identity CloudConverged IGA across apps, cloud and privileged accessCertifications, SoD for ERP, AI agent governanceSaaSQuote only
Microsoft Entra ID GovernanceMicrosoft-first organizationsAccess reviews, entitlement management, lifecycle workflowsSaaS$7 per user per month add-on
Omada Identity CloudRegulated firms wanting SaaS IGA in their own Azure tenantCertifications, role management, policySaaS or private tenantQuote only
One Identity ManagerComplex hybrid estatesSoD, risk-based governance, broad connectorsSelf-managed or SaaSQuote only
Okta Identity GovernanceOkta Workforce customersCertifications, access requests, entitlements, AI agent reviewsSaaSQuote only
Oracle Identity Governance / Access GovernanceOracle-invested enterprisesRole modeling, SoD, identity analyticsSelf-managed (OIG) or OCI cloud (Access Governance)Quote only
IBM Verify Identity GovernanceRegulated enterprises with IBM estatesSoD, risk analytics, certificationsSelf-managed or cloudQuote only
Ping Identity (PingOne Advanced Identity Cloud governance)Ping and former ForgeRock customersCertifications, SoD policies, request workflowsSaaSQuote only
Symantec IGA (Broadcom)Existing Broadcom/CA identity estatesRBAC, certifications, compliance reportingSelf-managedQuote only
RSA Governance & LifecycleAudit-heavy enterprisesRisk-ranked access reviews, policySelf-managed or RSA cloudQuote only
PathlockSAP and ERP-heavy finance teamsFine-grained SoD and application controlsSaaS or hybridQuote only
C1 (formerly ConductorOne)Fast-moving cloud and SaaS companiesAutomated reviews, just-in-time access, AI tool accessSaaSQuote only
LumosSaaS-heavy mid-market and enterpriseAgent-driven reviews and access governanceSaaSQuote only
ZluriSaaS discovery plus governanceAccess reviews, access requests, SaaS discoverySaaSQuote only
tenfoldMid-market, AD and Microsoft 365 estatesNo-code reviews, role-based access, reportingSelf-managed or SaaSFrom $0.90 per identity per month
ManageEngine ADManager PlusActive Directory and Microsoft 365 administrationAD access certification campaigns, reportingSelf-managedFrom $595 per year

Also covered below: Bravura Identity, Netwrix Identity Manager, EmpowerID, Evolveum midPoint and Imprivata Identity Governance.

1. SailPoint

SailPoint is the reference IGA platform for large regulated enterprises. It now markets SailPoint Identity Security, with Human Fabric for workforce identities and Agentic Fabric for AI agents; IdentityIQ remains the self-managed option (SailPoint). Both cover access certifications, role mining and role management, SoD policy, access requests and audit reporting across cloud, on-premises and directory sources.

The 2026 story is non-human identity. Agentic Fabric, launched May 11, 2026, extends discovery, governance and authorization to AI agents, sold as Agentic Business and Agentic Business Plus packages (SailPoint). The Entro acquisition adds NHI and credential security, offered standalone while native integration continues. Savvy's technology feeds SailPoint's SaaS application discovery.

  • Strengths: deepest certification and role-management tooling on this list, a large connector and partner ecosystem, and a clear AI agent roadmap.
  • Weaknesses: implementation is a program, not a project. Budget for integrator services and role-model design. Pricing is quote-only.
  • Best for: enterprises with SOX, HIPAA or banking audits and thousands of applications.

2. Saviynt

Saviynt Identity Cloud is a converged, cloud-native platform that combines IGA with application access governance, cloud entitlement governance and privileged access. It is strong in ERP SoD (SAP, Oracle, Workday) and in governing cloud infrastructure entitlements.

In March 2026 Saviynt released Identity Security for AI, which governs AI agents from discovery through runtime authorization (Saviynt). Its December 2025 raise of $700M gives it the balance sheet to keep investing as an independent vendor.

  • Strengths: one data model for human, NHI and AI agent access; strong ERP and cloud entitlement coverage.
  • Weaknesses: breadth brings configuration depth; plan for admin training. Quote-only pricing.
  • Best for: enterprises that want IGA and application SoD from one SaaS vendor.

3. Microsoft Entra ID Governance

Entra ID Governance adds access reviews, entitlement management (access packages), lifecycle workflows and privileged identity management on top of Entra ID. Microsoft lists it at $7 per user per month as an add-on for Entra ID P1 and P2 customers, and includes governance features in the $12 Entra Suite (Microsoft Entra pricing).

Microsoft is also treating AI agents as directory objects through Entra Agent ID, so owners, access and sign-in policy can apply to agents the way they apply to people.

  • Strengths: the lowest-friction choice when Entra ID is already your directory; transparent list pricing.
  • Weaknesses: thinner role mining and cross-application SoD than dedicated IGA suites; non-Microsoft and on-premises apps need connector work.
  • Best for: Microsoft 365 organizations that need auditable access reviews without a separate platform.

4. Omada Identity Cloud

Omada is a governance-first SaaS IGA vendor with strong certification, role management and policy tooling. In May 2026 it launched Omada Identity Cloud Private, which runs the full platform inside the customer's own Microsoft Azure tenant for regulated and government buyers (Omada). Its April 2026 release improved reviewer visibility during certifications (Omada).

  • Strengths: mature governance processes, a prescriptive deployment method, and a tenant-ownership option auditors like.
  • Weaknesses: smaller ecosystem than SailPoint in North America. Quote-only pricing.
  • Best for: European and regulated organizations that want SaaS IGA with data-residency control.

5. One Identity Manager

One Identity Manager is known for breadth of connectors and strong SoD enforcement across heterogeneous, hybrid estates. Version 10.0, released January 2026, added risk-based governance, identity threat detection and response (ITDR) playbooks, and optional AI-assisted natural-language reporting (One Identity). The vendor also positions it for governing AI agents as identities.

  • Strengths: deep SoD and policy controls, detailed audit trails for SOX, HIPAA and GDPR evidence, scale for very large user counts.
  • Weaknesses: complex to implement and tune; enterprise-level cost.
  • Best for: large regulated enterprises with many on-premises and cloud systems.

6. Okta Identity Governance

Okta Identity Governance adds access certifications, self-service access requests (with Slack and Teams approvals), fine-grained entitlement management and governance reporting to Okta Workforce Identity (Okta). In 2026 Okta added resource access certifications for AI agents, so agent connections go through the same review campaigns as people (Okta).

  • Strengths: fast time to value for existing Okta tenants; clean reviewer experience.
  • Weaknesses: lighter on role mining and ERP-grade SoD than SailPoint or Saviynt. No public price.
  • Best for: cloud-first companies already standardized on Okta.

7. Oracle Identity Governance and Oracle Access Governance

Oracle Identity Governance (OIG) is the long-standing self-managed suite with sophisticated business and IT role modeling, SoD policies and deep integration with Oracle E-Business Suite and Fusion (Oracle). Oracle Access Governance is the newer cloud-native service on OCI, offering access reviews, provisioning and identity analytics, and it can run alongside an on-premises OIG deployment (Oracle).

  • Strengths: strong role modeling and SoD; natural fit for Oracle application estates.
  • Weaknesses: OIG needs specialist skills and significant implementation effort; licensing is quote-only.
  • Best for: large enterprises and government bodies invested in Oracle.

8. IBM Verify Identity Governance

IBM Verify Identity Governance is the current name of what was IBM Security Identity Governance and Intelligence (IGI) and later IBM Security Verify Governance. Version 11 unified provisioning, governance and identity risk analytics (IBM). It automates access reviews, manages SoD conflicts, and produces audit evidence for SOX, HIPAA, GLBA and similar regimes.

  • Strengths: business-activity-based SoD modeling and risk analytics that surface unusual access.
  • Weaknesses: complex to deploy and operate without IBM expertise; enterprise pricing on quote.
  • Best for: regulated enterprises with existing IBM security investments.

9. Ping Identity

Ping's governance capability comes from ForgeRock, which Ping's owner Thoma Bravo combined with Ping in 2023. It runs in PingOne Advanced Identity Cloud and covers access requests, access certifications, SoD policies and configurable approval workflows (Ping documentation). See the Ping Identity profile for its broader platform.

  • Strengths: governance, access management and lifecycle from one vendor.
  • Weaknesses: governance is newer than its access-management core; integration effort for diverse application estates.
  • Best for: Ping and former ForgeRock customers consolidating identity vendors.

10. Symantec IGA (Broadcom)

Symantec IGA, now a Broadcom product, combines provisioning, an access request catalog, role-based access control and periodic certifications (Broadcom). Broadcom documents version 15.0 in 2026 (Broadcom TechDocs).

  • Strengths: mature RBAC and compliance reporting at large scale.
  • Weaknesses: self-managed and complex; Broadcom's enterprise-agreement licensing model suits large existing customers more than new buyers.
  • Best for: enterprises already running the Broadcom (formerly CA) identity suite.

11. RSA Governance & Lifecycle

RSA Governance & Lifecycle covers access reviews, policy management, access requests and birthright access, deployed on-premises or as RSA-managed cloud (RSA). In April 2026 RSA updated access reviews with AI-derived risk ranking, so reviewers see high, medium and low risk items first (RSA).

  • Strengths: audit-oriented reviews and a long compliance track record.
  • Weaknesses: interface and connector model feel older than cloud-native rivals. Quote-only.
  • Best for: RSA customers and audit-driven programs that want risk-ranked certifications.

12. Pathlock

Pathlock specializes in application-level governance for SAP, Oracle, Workday and other ERP systems: fine-grained SoD analysis, access risk and controls monitoring (Pathlock). It is often paired with a general IGA platform rather than replacing one. Its SAP solutions are certified for clean core with RISE with SAP.

  • Strengths: transaction-level SoD that general IGA tools approximate.
  • Weaknesses: narrower scope outside ERP. Quote-only.
  • Best for: CFO and internal-audit teams facing SOX findings on SAP or Oracle ERP.

13. C1 (formerly ConductorOne)

ConductorOne now operates as C1, and conductorone.com redirects to its new site (C1). It is a cloud-native governance platform built around automated access reviews, just-in-time access requests and connectors for SaaS and cloud infrastructure. In 2026 it added AI Access Management to govern access to AI tools, agents and MCP connections.

  • Strengths: quick deployment, a developer-friendly connector model, and time-bound access that cuts standing privilege.
  • Weaknesses: less depth in role mining and ERP SoD than legacy suites. Quote-only.
  • Best for: cloud-first companies preparing for SOC 2, SOX or ISO 27001 audits.

14. Lumos

Lumos, which now calls itself an autonomous identity platform (Lumos), governs access for employees, NHIs and AI agents across SaaS-heavy estates. In June 2026 it launched the Identity Agent Force, a set of AI agents that run access reviews and governance tasks continuously (Lumos release).

  • Strengths: modern reviewer experience, access requests in chat tools, SaaS spend visibility.
  • Weaknesses: younger platform with lighter on-premises and ERP coverage. Quote-only.
  • Best for: growth-stage and mid-market companies replacing spreadsheet reviews.

15. Zluri

Zluri, still independent, pairs SaaS discovery with IGA modules for access reviews, access requests and access management, and now positions them for both human and non-human identities (Zluri). Discovery finds the shadow apps that a connector-only IGA tool never sees, which makes certification scope more complete.

  • Strengths: SaaS visibility plus automated review campaigns and audit trails.
  • Weaknesses: less suited to complex on-premises estates and ERP SoD. No public pricing.
  • Best for: mid-sized and large companies whose access sprawl is mostly SaaS.

16. tenfold

tenfold is a no-code IGA product aimed at the mid-market, with access reviews, role-based access, self-service requests and compliance reporting for GDPR, SOX and HIPAA evidence. It publishes pricing: Essentials from $0.90 and Essentials 365 from $1.25 per managed identity per month, with a 100-user minimum. Enterprise, covering apps such as SAP and Workday, is custom-priced, and a free Community edition covers up to 150 users (tenfold pricing).

  • Strengths: transparent pricing and a short deployment for AD, file server and Microsoft 365 estates.
  • Weaknesses: automated workflows need careful configuration to avoid over-provisioning; broader app coverage sits in the custom tier.
  • Best for: mid-sized regulated organizations that need certifications without an enterprise program.

17. ManageEngine ADManager Plus

ADManager Plus is an Active Directory and Microsoft 365 administration tool with governance features, not a full IGA suite. It runs access certification campaigns across AD and Microsoft 365 with peer-based recommendations (ManageEngine), plus compliance reports and a self-service portal. Annual subscriptions start at $595 (Standard) and $795 (Professional) per domain (ManageEngine pricing).

  • Strengths: affordable, domain-based licensing with unlimited objects; strong AD reporting.
  • Weaknesses: limited governance beyond the Microsoft ecosystem; learning curve across a very wide feature set.
  • Best for: Microsoft-centric IT teams that need auditable AD access reviews.

Also worth shortlisting

  • Bravura Identity (formerly Hitachi ID): identity lifecycle, access certification campaigns, multi-step approvals and policy based on roles and attributes (Bravura Security). Quote-only. Fits mid-to-large enterprises with heavy certification needs.
  • Netwrix Identity Manager (formerly Usercube): SaaS or on-premises IGA with access review campaigns and role-based access across AD and Entra ID (Netwrix).
  • EmpowerID: IGA with role mining analytics for role modeling, and a 2026 push into AI agent governance (EmpowerID).
  • Evolveum midPoint: the leading open-source IGA platform. Release 4.10 added a compliance dashboard and was on update 4.10.4 as of August 2026 (Evolveum). Free to run; support is paid.
  • Imprivata Identity Governance: role-based lifecycle and governance built for healthcare, with agentic identity management for AI agents announced in March 2026 (Imprivata).
  • Idira by Palo Alto Networks (formerly CyberArk): governance across human and machine identities, built partly on the Zilla acquisition (Palo Alto Networks). Best evaluated by teams already using CyberArk for privileged access.

Which IGA platform fits your situation

SituationStart with
Large regulated enterprise, thousands of apps, SOX or banking auditsSailPoint, Saviynt, One Identity or Omada. Budget for services and role-model design.
Microsoft 365 and Entra ID is the backboneMicrosoft Entra ID Governance; add tenfold or ADManager Plus for AD-centric reviews.
Oracle application estateOracle Identity Governance or Oracle Access Governance.
SOX findings on SAP or other ERPPathlock, or Saviynt for ERP SoD inside a broader IGA platform.
Cloud-first, SaaS-heavy company preparing for auditsC1, Lumos, Zluri or Okta Identity Governance.
Governing AI agents and NHIs alongside peopleSailPoint Agentic Fabric, Saviynt Identity Security for AI, Okta, or C1.
Limited budget, strong engineering teamEvolveum midPoint.

How we evaluated

We scored each platform on the governance jobs auditors actually test: access certification campaigns, SoD policy and detection, role mining and role management, access request approvals, audit evidence, and coverage of non-human identities and AI agents. Provisioning connectors counted only as far as they feed governance.

For every vendor we checked, in September 2026, the vendor's own product and pricing pages, documentation and release notes, and ownership changes from press releases, investor relations pages and SEC filings. Prices appear only where the vendor publishes them. We did not run hands-on tests, and no vendor paid for placement.

Deepak Gupta founded LoginRadius, a customer identity platform he scaled to over a billion users. That is a practitioner vantage on identity programs, not an IGA vendor one. For the broader category map, see the identity governance vendor map.

Removed in this update: Prove Pinnacle. Prove is an identity verification and authentication company, and Pinnacle is its authentication platform, not an IGA product (Prove).

Which regulations drive IGA

  • SOX Section 404: management must assess internal control over financial reporting, which in practice means access controls and SoD on financial systems.
  • PCI DSS v4.0: requirement 7.2.4 calls for reviewing user accounts and access privileges at least every six months (PCI SSC).
  • HIPAA Security Rule: information access management and audit controls for protected health information (45 CFR Part 164, Subpart C).
  • NYDFS Part 500: limits and periodically reviews user access privileges at covered financial entities (NYDFS).
  • GDPR, GLBA and NERC CIP: each expects demonstrable control over who can reach personal, financial or critical-infrastructure systems.

Frequently Asked Questions

What are the best IGA tools right now?

For large regulated enterprises, SailPoint, Saviynt, Omada and One Identity lead. Microsoft Entra ID Governance is the default for Microsoft-first shops at $7 per user per month. C1 (formerly ConductorOne), Lumos, Zluri and tenfold suit SaaS-heavy and mid-market teams.

What is identity governance and administration (IGA)?

IGA is the set of policies, processes and tools that decide and prove who should have access to what. It covers access certifications, role management, separation of duties enforcement, access requests and the audit evidence regulators ask for, across employees, service accounts and AI agents.

How does IGA differ from IAM?

IAM handles authentication and real-time authorization: can this user sign in and reach this app now? IGA handles the governance question: should this user hold this access at all, who approved it, and is it still appropriate? Most organizations need both.

Can IGA platforms govern AI agents and non-human identities?

Increasingly, yes. SailPoint, Saviynt, Okta, One Identity, Lumos and C1 all shipped AI agent governance in 2026, typically assigning a human owner and putting agent access into certification campaigns. Coverage is still maturing, so test it against your own agents and service accounts.

How long does an IGA implementation take?

It depends on the number of applications, the quality of HR source data, and how much role modeling you need. Enterprise suites are usually phased programs measured in quarters. SaaS-first tools can run a first review campaign much sooner. Phase by risk: start with financial and regulated systems.

What does IGA cost?

Most enterprise vendors price on quote, usually per managed identity and module. Published list prices include Microsoft Entra ID Governance at $7 per user per month, tenfold from $0.90 per identity per month, and ADManager Plus from $595 per year.

Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:

Get the newsletter

New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.

Tell us what you read most (optional)