Identity lifecycle news from January to September 2026, grouped by theme
ILM Reference editors · Published 2026-09-25 · 4 minute read
This note covers announcements from January to September 2026 that matter for identity lifecycle programs, grouped by theme rather than by date. The largest changes were a SailPoint product reorganization, ServiceNow's acquisition of Veza, Saviynt's Zuma platform, generally available account discovery in Microsoft Entra, and Orchid Security's Identity Audit and SailPoint partnership. Each item links to the original announcement.
What changed among the governance platforms?
SailPoint announced SailPoint Identity Security on 4 August 2026, combining Agentic Fabric, now generally available, with Human Fabric, which SailPoint says evolved from Identity Security Cloud. For buyers of Identity Security Cloud the practical point is naming: confirm which product and packaging a quote or renewal refers to. Source.
Saviynt launched Zuma on 28 July 2026, an identity security platform with Zuma Insights, Zuma Access and Zuma Governance, and stated that it has passed $300 million in annual recurring revenue. Source.
C1 opened an EU instance on 15 September 2026. European customers can run C1 with tenant data held in the EU, on AWS Frankfurt with Ireland as the disaster-recovery region. Source.
Which acquisitions closed?
Veza's CEO wrote on 2 March 2026 that ServiceNow had completed its acquisition of Veza, with Veza's Access Graph to be integrated across the ServiceNow platform. Source.
SailPoint completed its acquisition of Tel Aviv-based Entro Security on 29 June 2026. Entro secures non-human identities, secrets and tokens; financial terms were not disclosed. Source.
Neither acquisition changes the scores on this site, which are based on the product pages we reviewed in September 2026. Both are reasons to ask vendors how packaging and contracts work now.
What did Orchid Security release?
Orchid Security made three announcements relevant to lifecycle work. On 5 February 2026 it launched Identity Audit, which combines audit data captured inside unmanaged applications with logs from governed IAM systems into one view of identity activity (source). On 19 May 2026 it published the Identity Gap: 2026 Snapshot, based on anonymized telemetry from enterprise applications in North America and Europe between April 2025 and March 2026, which states that 67% of non-human accounts are created directly within applications (source). On 23 August 2026 it joined the SailPoint Technology Alliance Partner ecosystem, with Orchid discovering applications and analyzing identity inside them and SailPoint providing the governance layer (source).
What did Microsoft add for lifecycle work?
Microsoft's Entra what's new page lists two lifecycle items as generally available in April 2026: Account Discovery, which gives visibility into accounts in connected applications, including orphan accounts, and prefetching of Workday termination data to customize account disable logic. The page gives a month, not a day, which is why these items appear in this recap but not in the dated news log. Source.
For Microsoft Entra ID Governance customers, account discovery is the quickest way to produce a first orphan-candidate list for connected applications. Disconnected applications still follow the documented CSV process.
Which standards moved?
On 12 January 2026, OpenID Foundation members approved the AuthZEN Working Group's Authorization API 1.0 as a Final Specification, with 81 votes to approve, 1 to object and 25 abstentions. It defines a standard API between applications and authorization engines. Source.
On 15 September 2026, NIST published IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse, as final, with implementation recommendations for agencies and cloud service providers. The OpenID Foundation noted the next day that it recommends the Shared Signals Framework and CAEP. For lifecycle teams, that is relevant to ending a leaver's live sessions, covered in our Shared Signals note. Source.
What should a lifecycle program take from this?
- Check product names and packaging in contracts and renewals where a vendor has reorganized or been acquired.
- If Microsoft Entra is your identity provider, run the account discovery report on connected applications before the next review.
- If data residency matters, ask each vendor where tenant data is held; C1 now documents an EU option.
- Audit evidence for applications outside the IGA is becoming a product category of its own. Ask any tool you evaluate what it records for applications it did not provision.
The full dated list is in the news log. The comparison reflects the product pages as reviewed in September 2026.
Sources
- SailPoint press release, SailPoint Identity Security
- Saviynt press release, Zuma
- C1 blog, C1 in Europe
- Veza blog, ServiceNow acquisition
- SailPoint press release, Entro Security acquisition
- Orchid Security, Identity Audit launch
- Orchid Security, Identity Gap: 2026 Snapshot
- Orchid Security, SailPoint partnership
- Microsoft Learn, What's new in Microsoft Entra
- OpenID Foundation, AuthZEN Authorization API 1.0
- NIST IR 8587
- OpenID Foundation, on NIST IR 8587
Reviewed Sep 2026