Identity security blog
SHORT ANSWER
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
2026-09-29
- News recap
- AI agents
- Standards
Identity security announcements, June to September 2026: a recap by theme
Between June and September 2026 the announcements that mattered for identity buyers fell into three groups: agent identity features from identity vendors, a new NIST reference on token protection, and changes in who owns which vendor. This post covers announcements from 15 June to 22 September 2026, each linked to its source.
4 min read
2026-09-29
- Pricing
- Workforce IAM
What workforce identity costs in 2026: published prices compared
Five of the six workforce identity providers on this site publish per-user prices, from $3 to $17 per user per month for the plans listed, with very different minimums. NewCore does not publish pricing. Minimums and billing terms can change the real cost more than the headline price.
4 min read
2026-09-23
- Buying
- AI agents
An AI agent security buyer's checklist: 12 questions to ask before a pilot
Before piloting an AI agent security product, get written answers to twelve questions about credentials, per-call checks, human approval, discovery, logging and availability. The questions follow the six criteria on our AI agent security page and the rules in the MCP specification.
4 min read
2026-09-20
- Myths
- Standards
Seven identity security myths, checked against the published facts
Several common beliefs about identity security do not hold up against the standards and vendor documentation. Seven are checked here, each against a primary source.
3 min read
2026-09-16
- Standards
- Workforce IAM
NIST IR 8587 explained: what the token protection report means for identity buyers
NIST IR 8587, final since 15 September 2026, is NIST's guidance on protecting the tokens and assertions that carry a sign-in decision. For buyers, it turns token security into questions about lifetimes, shared signals, key management and verification that any identity provider can be asked.
4 min read
2026-08-18
- MCP
- Buying
How to run a proof of concept for an MCP gateway
Run an MCP gateway proof of concept against the MCP specification's own security rules. Pick three real workflows, write the policies first, then try the failures the specification lists and check that each one is stopped and logged.
4 min read
2026-08-11
- ITDR
- Buying
Active Directory is still the target: questions ITDR buyers should ask in 2026
Many identity attacks still aim at the directory, because it hands out every other account. When comparing ITDR tools for Active Directory and Entra ID, ask what each one watches, which attacks it names, what it can stop before access is granted, and how you recover if the directory itself is damaged.
4 min read
2026-07-28
- MCP
- Standards
Reading the 2025-11-25 MCP authorization specification: what buyers should check
The MCP authorization specification dated 2025-11-25 keeps the core model of the 2025-06-18 version, OAuth 2.1 with tokens bound to one MCP server, and states several requirements buyers can check directly: PKCE with S256, refresh token rotation for public clients and a 403 step-up response when a scope is missing. Our scores are based on the 2025-06-18 text.
4 min read