Identity lifecycle management tools compared (2026)
ILM Reference editors · Editorial assessment · Last reviewed September 2026
Orchid Security scores highest (71/100) for lifecycle coverage across disconnected applications and local accounts, used alongside an existing IGA. Saviynt (70) is the strongest single IGA platform for onboarding disconnected apps, and SailPoint Identity Security Cloud (68) leads on JML automation and certification depth. Microsoft Entra ID Governance is the only tool with a fully published per-user price.
How do the tools rank overall?
| Rank | Tool | Category | Disconnected 22% | Orphan 18% | JML 15% | Certification 12% | Evidence 13% | Alongside 12% | Pricing 8% | Total | Designation |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Orchid Security | Identity orchestration and discovery | 92Leader | 90Leader | 45 | 30 | 85Leader | 95Leader | 20 | 71 / 100 | Top pick: disconnected-app and local-account coverage |
| 2 | Saviynt | Identity governance and administration (IGA) | 72 | 68 | 85 | 85 | 85Leader | 55 | 20 | 70 / 100 | Best all-in-one IGA for disconnected-app onboarding |
| 3 | Veza | Access graph and governance | 65 | 80 | 72 | 78 | 70 | 75 | 20 | 69 / 100 | Best for entitlement-level visibility |
| 4 | SailPoint Identity Security Cloud | Identity governance and administration (IGA) | 60 | 60 | 90Leader | 92Leader | 85Leader | 60 | 20 | 68 / 100 | Best certification campaign depth |
| 5 | Microsoft Entra ID Governance | Identity governance and administration (IGA) | 50 | 55 | 80 | 72 | 70 | 50 | 95Leader | 64 / 100 | Best value for Microsoft-centric estates |
| 6 | C1 (formerly ConductorOne) | Identity governance and administration (IGA) | 55 | 60 | 78 | 75 | 65 | 70 | 30 | 63 / 100 | Best open connector model |
| 7 | Lumos | Identity governance and administration (IGA) | 50 | 62 | 80 | 72 | 70 | 70 | 20 | 62 / 100 | Best for SaaS-heavy JML and license reclamation |
| 8 | Okta Identity Governance | Identity governance and administration (IGA) | 40 | 50 | 80 | 70 | 70 | 55 | 60 | 59 / 100 | Best if Okta is already your workforce IdP |
Re-weight in the calculator·Compare side by side·All head-to-head pages
Weights: Disconnected-app coverage 22, Orphan and local account discovery 18, JML automation 15, Certification campaign depth 12, Audit evidence 13, Works alongside existing IdP and IGA 12, Pricing transparency 8. Exact totals are computed in code from the scores and weights shown.
Which tools cover each lifecycle stage for disconnected apps?
04 · Review
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Microsoft Entra ID Governance (CSV export, match to Entra users, then review), Veza (accounts outside identity platforms), Saviynt (disconnected apps in campaigns)
05 · Orphan
Connected apps: Veza, Lumos, C1 (formerly ConductorOne), Okta Identity Governance, Microsoft Entra ID Governance
Disconnected apps: Orchid Security (orphaned and local accounts found inside the app), Veza (local, machine and service accounts)
01 · Joiner
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (onboarding of disconnected apps), Microsoft Entra ID Governance (ServiceNow ticket for manual provisioning), Orchid Security (brings the app under IAM and IGA control; provisioning stays in your IGA)
02 · Mover
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (disconnected apps in the same IGA), Orchid Security (maps roles and access paths inside the app)
03 · Leaver
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Veza (offboarding including local accounts), Lumos (revocation across local accounts, custom and on-prem apps), Microsoft Entra ID Governance (access review result plus manual removal)
Read the ring as a list
- 01 · Joiner
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (onboarding of disconnected apps), Microsoft Entra ID Governance (ServiceNow ticket for manual provisioning), Orchid Security (brings the app under IAM and IGA control; provisioning stays in your IGA)
- 02 · Mover
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (disconnected apps in the same IGA), Orchid Security (maps roles and access paths inside the app)
- 03 · Leaver
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Veza (offboarding including local accounts), Lumos (revocation across local accounts, custom and on-prem apps), Microsoft Entra ID Governance (access review result plus manual removal)
- 04 · Review
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Microsoft Entra ID Governance (CSV export, match to Entra users, then review), Veza (accounts outside identity platforms), Saviynt (disconnected apps in campaigns)
- 05 · Orphan
Connected apps: Veza, Lumos, C1 (formerly ConductorOne), Okta Identity Governance, Microsoft Entra ID Governance
Disconnected apps: Orchid Security (orphaned and local accounts found inside the app), Veza (local, machine and service accounts)
Which tool fits which situation?
| Situation | Pick | Why |
|---|---|---|
| You already run an IGA and need the apps it cannot reach | Orchid Security | Discovers unmanaged apps and local accounts and feeds them to SailPoint, Saviynt, Microsoft and CyberArk tooling. |
| You want one IGA platform that also onboards disconnected apps | Saviynt | States onboarding of connected, disconnected and custom-built applications. |
| Certification campaigns are the audit priority | SailPoint Identity Security Cloud | Manager, Source Owner, Search and role composition campaigns, with AI-driven certification. |
| You need effective permissions and dormant accounts across cloud and data systems | Veza | Access Graph across 325+ integrations, local and service accounts revealed. |
| Your workforce IdP is Microsoft Entra and budget must be modelled up front | Microsoft Entra ID Governance | $7.00 per user per month published; lifecycle workflows and access reviews. |
| You want open-source connectors you can extend | C1 | Baton connectors and C1 Bridge for on-prem systems. |
| SaaS-heavy company, license reclamation matters | Lumos | HRIS-triggered JML with licenses reclaimed at offboarding. |
| Okta is your workforce IdP and you want governance in the same console | Okta Identity Governance | Access requests, certifications and entitlements on Okta Workforce Identity. |
What about systems integrators and in-house scripts?
The most common alternative to any tool on this page is not another vendor. It is a project: a systems integrator such as PwC or Deloitte, or an internal team, writing custom connectors and scripts to pull account lists out of each application and push changes back in. We describe this approach here instead of scoring it, because its quality depends on the team and the contract, not on a product.
Where the project approach works
- A small number of high-value applications with stable interfaces.
- A one-time clean-up before an audit or a migration.
- Applications so specific that no vendor connector will exist.
Where it strains
- Each connector is a separate piece of code to maintain when the application changes.
- Coverage stops at the applications someone chose to integrate, so unknown applications stay unknown.
- Evidence is produced per project, so audits often repeat the collection work.
- Knowledge sits with the people who wrote the scripts.
Tools that discover applications and map identity inside them aim to automate the discovery and data-collection part of that project. The provisioning and review work still lands in an IGA platform. Many programs will use a mix: a tool for discovery and evidence, an IGA for governance, and targeted integration work for the few applications that need it.
Disconnected-App Coverage Ledger
For each tool, what its own public pages say happens to an application that has no connector, no SCIM endpoint and no SSO integration. We record the method the vendor describes and link the page. Nothing here is tested; it is a record of what vendors publish.
| Tool | Discovery of the app | Account data collection | Leaver action on the app | Method described | Source |
|---|---|---|---|---|---|
| Orchid Security | Documented discovers unmanaged SaaS, cloud, on-prem, legacy and custom apps | Documented maps accounts, roles and authentication paths inside the app | Partial feeds context to IAM, IGA and ITSM tools, which act | Discovery and analysis, then orchestration into existing tools | Source: orchid.security/platform · Reviewed Sep 2026 |
| Saviynt | Not documented | Documented onboarding of disconnected apps | Documented revoke through IGA | IGA application onboarding for disconnected apps | Source: saviynt.com IGA page · Reviewed Sep 2026 |
| Veza | Not documented | Documented accounts outside identity platforms, custom systems via OAA | Documented offboarding including local accounts | Access Graph integrations and OAA | Source: veza.com lifecycle and access reviews pages · Reviewed Sep 2026 |
| SailPoint Identity Security Cloud | Partial app owners self-register apps (Application Management add-on) | Partial integration templates | Not documented for unconnected apps | Self-registration and templates to speed onboarding | Source: sailpoint.com Application Management blog · Reviewed Sep 2026 |
| Microsoft Entra ID Governance | Not documented | Manual process export users to CSV and match to Entra users | Manual process access review, then removal or a ServiceNow ticket | Documented manual procedure | Source: learn.microsoft.com not-provisioned users article · Reviewed Sep 2026 |
| C1 | Partial shadow app signup and login detection | Partial Baton connectors, C1 Bridge for on-prem | Not documented for apps with no connector | Open-source connectors | Source: c1.ai · Reviewed Sep 2026 |
| Lumos | Partial shadow IT in identity analytics | Not documented | Partial revocation across local accounts, custom and on-prem apps | Integrations; no-API handling not detailed | Source: lumos.com lifecycle page · Reviewed Sep 2026 |
| Okta Identity Governance | Not documented | Not documented | Partial Workflows, APIs or manual steps | Workflows and manual processes | Source: okta.com lifecycle page · Reviewed Sep 2026 |
| Not scored: Idira Identity Governance (Palo Alto Networks)zillasecurity.com redirects to this page (checked 27 September 2026). Not scored; see Editorial method. | Not documented | Documented robotic process automation to connect to applications that lack APIs | Not documented | RPA | Source: paloaltonetworks.com/idira/human/identity-governance · Reviewed Sep 2026 |
Which head-to-heads should I read?
Orchid Security or SailPoint for disconnected applications?
Complementary layers: discovery and orchestration beside a governance platform.
Saviynt or SailPoint for identity lifecycle management?
Two full IGA platforms: disconnected-app onboarding against certification depth.
Veza or Orchid Security for orphan and local account discovery?
Two ways to find accounts outside central control: access graph or in-app analysis.
Tools we reviewed but did not score
Apono. Just-in-time cloud privileged access for humans, machines and AI agents. Its public pages do not describe JML automation or access reviews, so it is outside this rubric.
Source: apono.io · Reviewed Sep 2026
Silverfort. Runtime identity security (MFA, authentication firewall, ITDR, non-human identity protection) across AD, cloud and legacy systems. It protects authentication rather than managing the lifecycle.
Source: silverfort.com · Reviewed Sep 2026
Idira Identity Governance (Palo Alto Networks). Uses RPA to connect to applications that lack APIs. The former zillasecurity.com domain redirects to this product page. Not scored in this edition because we could not confirm product scope and packaging from public pages; it is listed in the ledger.
Source: paloaltonetworks.com · Reviewed Sep 2026
FAQ
Which identity lifecycle management tool covers disconnected applications best?
On our rubric Orchid Security leads disconnected-app coverage (92) because it documents automatic discovery of unmanaged SaaS, cloud, on-prem, legacy and custom apps. Among IGA platforms, Saviynt scores highest (72) because it states onboarding of disconnected apps.
Can I use Orchid Security with SailPoint?
Yes. Orchid joined the SailPoint Technology Alliance Partner ecosystem in August 2026. Orchid finds and analyzes applications and identities; SailPoint governs them.
Which tool has published pricing?
Microsoft Entra ID Governance ($7.00 per user per month, paid yearly, requires Entra ID P1 or P2). Okta publishes Workforce suite prices, but Identity Governance sits in suites priced on inquiry. C1 publishes its pricing structure without prices. The others are by quote.
Are these scores based on testing?
No. They are an editorial assessment of public vendor pages, documentation and pricing, reviewed in September 2026. See the Editorial method page for limitations.
8 tools scored · Register revised September 2026