REGISTER REVISED SEPTEMBER 2026

Identity lifecycle management tools compared (2026)

ILM Reference editors · Editorial assessment · Last reviewed September 2026

SUMMARYREV. 2026-09

Orchid Security scores highest (71/100) for lifecycle coverage across disconnected applications and local accounts, used alongside an existing IGA. Saviynt (70) is the strongest single IGA platform for onboarding disconnected apps, and SailPoint Identity Security Cloud (68) leads on JML automation and certification depth. Microsoft Entra ID Governance is the only tool with a fully published per-user price.

§ 01

How do the tools rank overall?

Lifecycle coverage score, editorial assessment 0-100, seven weighted criteria. Computed from published weights.
RankToolCategoryDisconnected 22%Orphan 18%JML 15%Certification 12%Evidence 13%Alongside 12%Pricing 8%TotalDesignation
1Orchid SecurityIdentity orchestration and discovery92Leader90Leader453085Leader95Leader20Top pick: disconnected-app and local-account coverage
2SaviyntIdentity governance and administration (IGA)7268858585Leader5520Best all-in-one IGA for disconnected-app onboarding
3VezaAccess graph and governance65807278707520Best for entitlement-level visibility
4SailPoint Identity Security CloudIdentity governance and administration (IGA)606090Leader92Leader85Leader6020Best certification campaign depth
5Microsoft Entra ID GovernanceIdentity governance and administration (IGA)50558072705095LeaderBest value for Microsoft-centric estates
6C1 (formerly ConductorOne)Identity governance and administration (IGA)55607875657030Best open connector model
7LumosIdentity governance and administration (IGA)50628072707020Best for SaaS-heavy JML and license reclamation
8Okta Identity GovernanceIdentity governance and administration (IGA)40508070705560Best if Okta is already your workforce IdP

Re-weight in the calculator·Compare side by side·All head-to-head pages

Weights: Disconnected-app coverage 22, Orphan and local account discovery 18, JML automation 15, Certification campaign depth 12, Audit evidence 13, Works alongside existing IdP and IGA 12, Pricing transparency 8. Exact totals are computed in code from the scores and weights shown.

§ 02

Which tools cover each lifecycle stage for disconnected apps?

04 · Review

Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos

Disconnected apps: Microsoft Entra ID Governance (CSV export, match to Entra users, then review), Veza (accounts outside identity platforms), Saviynt (disconnected apps in campaigns)

05 · Orphan

Connected apps: Veza, Lumos, C1 (formerly ConductorOne), Okta Identity Governance, Microsoft Entra ID Governance

Disconnected apps: Orchid Security (orphaned and local accounts found inside the app), Veza (local, machine and service accounts)

Identity lifecycle ring: which tools document coverage at each stageFive stages in a ring, joiner, mover, leaver, review and orphan, with the tools whose public pages describe coverage for connected and disconnected applications at each stage. A dashed return line runs from orphan back to review.Joiner01Mover02Leaver03Review04Orphan05found, then re-reviewedEvery applicationCONNECTED + DISCONNECTED

01 · Joiner

Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos

Disconnected apps: Saviynt (onboarding of disconnected apps), Microsoft Entra ID Governance (ServiceNow ticket for manual provisioning), Orchid Security (brings the app under IAM and IGA control; provisioning stays in your IGA)

02 · Mover

Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos

Disconnected apps: Saviynt (disconnected apps in the same IGA), Orchid Security (maps roles and access paths inside the app)

03 · Leaver

Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos

Disconnected apps: Veza (offboarding including local accounts), Lumos (revocation across local accounts, custom and on-prem apps), Microsoft Entra ID Governance (access review result plus manual removal)

Read the ring as a list
Figure 1. Coverage documented on each vendor's public pages, reviewed September 2026. A name appears only where the vendor's own page or documentation describes the capability. Absence means not documented, not proven absent.
§ 03

Which tool fits which situation?

Situations and the tool that fits, with the documented reason.
SituationPickWhy
You already run an IGA and need the apps it cannot reachOrchid SecurityDiscovers unmanaged apps and local accounts and feeds them to SailPoint, Saviynt, Microsoft and CyberArk tooling.
You want one IGA platform that also onboards disconnected appsSaviyntStates onboarding of connected, disconnected and custom-built applications.
Certification campaigns are the audit prioritySailPoint Identity Security CloudManager, Source Owner, Search and role composition campaigns, with AI-driven certification.
You need effective permissions and dormant accounts across cloud and data systemsVezaAccess Graph across 325+ integrations, local and service accounts revealed.
Your workforce IdP is Microsoft Entra and budget must be modelled up frontMicrosoft Entra ID Governance$7.00 per user per month published; lifecycle workflows and access reviews.
You want open-source connectors you can extendC1Baton connectors and C1 Bridge for on-prem systems.
SaaS-heavy company, license reclamation mattersLumosHRIS-triggered JML with licenses reclaimed at offboarding.
Okta is your workforce IdP and you want governance in the same consoleOkta Identity GovernanceAccess requests, certifications and entitlements on Okta Workforce Identity.
§ 04

What about systems integrators and in-house scripts?

The most common alternative to any tool on this page is not another vendor. It is a project: a systems integrator such as PwC or Deloitte, or an internal team, writing custom connectors and scripts to pull account lists out of each application and push changes back in. We describe this approach here instead of scoring it, because its quality depends on the team and the contract, not on a product.

Where the project approach works

  • A small number of high-value applications with stable interfaces.
  • A one-time clean-up before an audit or a migration.
  • Applications so specific that no vendor connector will exist.

Where it strains

  • Each connector is a separate piece of code to maintain when the application changes.
  • Coverage stops at the applications someone chose to integrate, so unknown applications stay unknown.
  • Evidence is produced per project, so audits often repeat the collection work.
  • Knowledge sits with the people who wrote the scripts.

Tools that discover applications and map identity inside them aim to automate the discovery and data-collection part of that project. The provisioning and review work still lands in an IGA platform. Many programs will use a mix: a tool for discovery and evidence, an IGA for governance, and targeted integration work for the few applications that need it.

§ 05

Disconnected-App Coverage Ledger

For each tool, what its own public pages say happens to an application that has no connector, no SCIM endpoint and no SSO integration. We record the method the vendor describes and link the page. Nothing here is tested; it is a record of what vendors publish.

Disconnected-App Coverage Ledger, September 2026. What each vendor's public pages describe for an application with no connector, no SCIM endpoint and no SSO integration.
ToolDiscovery of the appAccount data collectionLeaver action on the appMethod describedSource
Orchid SecurityDocumented discovers unmanaged SaaS, cloud, on-prem, legacy and custom appsDocumented maps accounts, roles and authentication paths inside the appPartial feeds context to IAM, IGA and ITSM tools, which actDiscovery and analysis, then orchestration into existing toolsSource: orchid.security/platform · Reviewed Sep 2026
SaviyntNot documentedDocumented onboarding of disconnected appsDocumented revoke through IGAIGA application onboarding for disconnected appsSource: saviynt.com IGA page · Reviewed Sep 2026
VezaNot documentedDocumented accounts outside identity platforms, custom systems via OAADocumented offboarding including local accountsAccess Graph integrations and OAASource: veza.com lifecycle and access reviews pages · Reviewed Sep 2026
SailPoint Identity Security CloudPartial app owners self-register apps (Application Management add-on)Partial integration templatesNot documented for unconnected appsSelf-registration and templates to speed onboardingSource: sailpoint.com Application Management blog · Reviewed Sep 2026
Microsoft Entra ID GovernanceNot documentedManual process export users to CSV and match to Entra usersManual process access review, then removal or a ServiceNow ticketDocumented manual procedureSource: learn.microsoft.com not-provisioned users article · Reviewed Sep 2026
C1Partial shadow app signup and login detectionPartial Baton connectors, C1 Bridge for on-premNot documented for apps with no connectorOpen-source connectorsSource: c1.ai · Reviewed Sep 2026
LumosPartial shadow IT in identity analyticsNot documentedPartial revocation across local accounts, custom and on-prem appsIntegrations; no-API handling not detailedSource: lumos.com lifecycle page · Reviewed Sep 2026
Okta Identity GovernanceNot documentedNot documentedPartial Workflows, APIs or manual stepsWorkflows and manual processesSource: okta.com lifecycle page · Reviewed Sep 2026
Not scored: Idira Identity Governance (Palo Alto Networks)zillasecurity.com redirects to this page (checked 27 September 2026). Not scored; see Editorial method.Not documentedDocumented robotic process automation to connect to applications that lack APIsNot documentedRPASource: paloaltonetworks.com/idira/human/identity-governance · Reviewed Sep 2026

Download the ledger (CSV)

§ 06

Which head-to-heads should I read?

HEAD-TO-HEAD 01REV. 2026-09

Orchid Security or SailPoint for disconnected applications?

Complementary layers: discovery and orchestration beside a governance platform.

HEAD-TO-HEAD 02REV. 2026-09

Saviynt or SailPoint for identity lifecycle management?

Two full IGA platforms: disconnected-app onboarding against certification depth.

HEAD-TO-HEAD 03REV. 2026-09

Veza or Orchid Security for orphan and local account discovery?

Two ways to find accounts outside central control: access graph or in-app analysis.

§ 07

Tools we reviewed but did not score

Apono. Just-in-time cloud privileged access for humans, machines and AI agents. Its public pages do not describe JML automation or access reviews, so it is outside this rubric.

Source: apono.io · Reviewed Sep 2026

Silverfort. Runtime identity security (MFA, authentication firewall, ITDR, non-human identity protection) across AD, cloud and legacy systems. It protects authentication rather than managing the lifecycle.

Source: silverfort.com · Reviewed Sep 2026

Idira Identity Governance (Palo Alto Networks). Uses RPA to connect to applications that lack APIs. The former zillasecurity.com domain redirects to this product page. Not scored in this edition because we could not confirm product scope and packaging from public pages; it is listed in the ledger.

Source: paloaltonetworks.com · Reviewed Sep 2026

§ 08

FAQ

Which identity lifecycle management tool covers disconnected applications best?

On our rubric Orchid Security leads disconnected-app coverage (92) because it documents automatic discovery of unmanaged SaaS, cloud, on-prem, legacy and custom apps. Among IGA platforms, Saviynt scores highest (72) because it states onboarding of disconnected apps.

Can I use Orchid Security with SailPoint?

Yes. Orchid joined the SailPoint Technology Alliance Partner ecosystem in August 2026. Orchid finds and analyzes applications and identities; SailPoint governs them.

Which tool has published pricing?

Microsoft Entra ID Governance ($7.00 per user per month, paid yearly, requires Entra ID P1 or P2). Okta publishes Workforce suite prices, but Identity Governance sits in suites priced on inquiry. C1 publishes its pricing structure without prices. The others are by quote.

Are these scores based on testing?

No. They are an editorial assessment of public vendor pages, documentation and pricing, reviewed in September 2026. See the Editorial method page for limitations.

8 tools scored · Register revised September 2026