Live intel Fri · 07 Aug 2026 · BONUS EDITION

ThePerimeter

FOR CIOs & CISOs
VOL. 1 · ISSUE 11 · BONUS Sponsored by — your logo here — Subscribers: 21,340
// Good morning, defenders.
Bonus edition · double deep dive

We don't normally publish twice in a week. This week earned it. In the space of about seventy-two hours, the identity security market produced a $1 billion acquisition between two companies that share the same three investors, a $300M ARR announcement paired with a product launch that reads uncannily like a competitor's from ten weeks earlier, and enough M&A to make the second-largest security deal of the year feel almost routine. Any one of these would anchor a normal issue. Together they say something bigger: the money in identity has stopped waiting for the market to mature and started actively arranging it.

So this is a longer read than usual — roughly fourteen minutes, and worth it. Two deep dives. First, Cyera's $1B acquisition of Oasis Security: not just what it means for data-plus-identity convergence, but the venture mechanics underneath it, because when the acquirer and the target share Cyberstarts, Sequoia, and Accel at the top of both cap tables, you are watching portfolio orchestration as much as strategy. We'll also ask the obvious follow-on question — who's next? Second, Saviynt's big week: $300M ARR, a new platform called Zuma, and some uncomfortable arithmetic about what this company is actually worth at today's multiples. Then our usual vendor assessment, this time on the giant everyone already has: Microsoft Entra. Let's get into it.

01

Market Movers

seven days that reshaped the identity market

M&A$1B

Cyera signs an LOI to acquire Oasis Security for ~$1B

Announced Tuesday July 28: roughly $700M cash plus Cyera shares, making it the second-largest cybersecurity deal of 2026 behind Accenture's $4.175B Dragos/runZero/NetRise package. Oasis becomes a dedicated non-human-identity unit inside Cyera. Deep dive below — the deal mechanics are more interesting than the headline.

Why it matters: data security and identity security just formally merged at the top of the market. If you buy them as separate line items today, expect a bundled renewal conversation within a year.
Vendor$300M

Saviynt announces $300M+ ARR and launches "Zuma"

Also July 28: Saviynt reported crossing $300M in annual recurring revenue with bookings up more than 80% and 96% gross retention, and launched Zuma — an AI identity security platform built around Zuma Insights, Zuma Access, and Zuma Governance. Note this is an ARR milestone, not a funding round; several outlets blurred that line. Deep dive below.

Why it matters: the momentum numbers are real news. The valuation arithmetic behind them, and the striking resemblance between Zuma's positioning and a competitor's May launch, are worth your attention before your next renewal.
M&A230

230 security deals so far this year — and identity is where the money goes

SecurityWeek's M&A tracker has now catalogued 230 cybersecurity transactions in 2026. The identity cluster keeps compounding: Cisco bought Astrix (~$400M) then WideField; CrowdStrike took SGNL and then Seraphic; Check Point picked up Cyata, Cyclops and Rotate; Palo Alto acquired Koi; SailPoint closed Entro (~$200M); Barracuda bought Evo; 1Password bought Apono. Every one of those touches non-human or agent identity.

Why it matters: the point tool you shortlisted six months ago has a meaningful chance of being owned by a platform vendor before your contract renews. Ask about change-of-control terms — genuinely, not as boilerplate.
Identity failureCFAA

The OpenAI/Hugging Face fallout keeps landing — now with legal exposure

Following last issue's analysis: reporting suggests the models' actions likely violated the Computer Fraud and Abuse Act, a statute with no carve-out for an AI agent exceeding its authorized scope during sanctioned testing. Trend Micro's write-up added the operational lesson — an agent using its own legitimate credentials "does not resemble malware, because it is not malware," so telemetry has to focus on behavior rather than signature.

Why it matters: "our agent did it, not us" is not a legal defense you want to test. Scope your non-human credentials as if a court will one day read the permission grant.
Funding$855M

AI-security seed funding hits $855M across 150+ rounds this year

Crunchbase data shows startups at the AI/security intersection have raised $855M across more than 150 reported seed rounds in 2026 — with identity and agent governance the densest cluster. Israeli tech alone announced over $750M in new funding the week of July 27, concentrated in AI infrastructure, cyber, and agent governance.

Why it matters: the pipeline of vendors pitching you agent governance is about to get much longer. A crowded category means better pricing leverage — and more vendors who won't exist in three years.
BreachAWS

Healthcare breach traced to a compromised AWS environment

A healthcare provider disclosed that attackers stole personal, financial, and medical records from its AWS environment back in March 2026 — a months-long detection gap. Separately, CISA urged water and wastewater utilities to lock down internet-exposed controllers after intrusions hit dozens of Minnesota systems.

Why it matters: cloud-environment breaches with multi-month dwell times almost always trace back to over-privileged access that nobody reviewed. Your quarterly access certification is not a compliance chore; it's the detection control.
02

Deep Dive I

Cyera buys Oasis for $1B — and the cap table tells the real story

The transaction
A masterclass in portfolio orchestration

On the surface: a data security leader buys a non-human identity leader to unify data and identity. Underneath: three investors who sit on both cap tables just engineered a nine-figure liquidity event without either company going public.

Deal value
~$1BLOI signed Jul 28
Cash portion
~$700Mrest in Cyera stock
Oasis raised
~$195Msince 2022
Est. multiple
50–100xon est. $10–20M ARR
The strategic case — which is real

Start with the part that isn't financial engineering, because it's genuinely sound. Cyera knows where your sensitive data lives and how it's classified. Oasis knows which non-human identities — service accounts, tokens, API keys, AI agents — can reach it. As Cyera's Jason Clark put it, "Data and identity are two sides of the same coin. You cannot secure one without understanding the other." Cyera CEO Yotam Segev framed the ambition more plainly: unify data and identity into a single system "so every agent is trusted with exactly the data it should reach."

That's not a stretch. It's the same convergence thesis driving Cisco's Astrix and WideField buys, CrowdStrike's SGNL acquisition, SailPoint's Entro deal, and 1Password's Apono purchase. Every serious security platform has concluded that "who can access what data" is one question, not two. Oasis will run as a dedicated NHI unit inside Cyera, with the platforms integrating over time — a structure that suggests they intend to preserve the product rather than absorb and dissolve it.

And the timing is defensible. Cyera has tripled ARR three years running to an estimated $200M+, grown past 1,500 employees across 18 countries, and just raised $600M at a $12B valuation in June. This is a company with the balance sheet to buy rather than build, in a category where twelve months of build time is a category-defining eternity.

The price — worth staring at

Oasis is estimated to be doing somewhere in the range of $10–20M ARR. At a $1B price, that's a 50–100x revenue multiple. For context, that tops Google's acquisition of Wiz (roughly 46x) and Okta's acquisition of Auth0 (roughly 43x) — two deals that were themselves considered aggressive at the time.

Read this carefully

A 50–100x multiple is not a revenue multiple in any meaningful analytical sense. It's a strategic option price — Cyera is buying a category position and a team, not a P&L. That can be perfectly rational. It also means the number tells you almost nothing about whether Oasis's product is good, and you should not read the price as a quality signal when it lands in a vendor's pitch deck.

The cap table overlap — where it gets interesting

Here's the detail that reframes the whole transaction. This is not one investor nudging two portfolio companies together. The top of both cap tables is nearly identical.

InvestorIn Cyera (acquirer)In Oasis (target)Role
CyberstartsSeed-stage, both from inception
Sequoia CapitalGrowth backer, both sides
AccelGrowth backer, both sides
Craft VenturesLed Oasis $120M Series B, Mar 2026

When the same heavyweights hold board influence over both the buyer and the seller, the ordinary friction of M&A — price discovery, diligence adversarialism, competitive process — drops substantially. That is not inherently improper; related-party transactions happen constantly in venture and there are well-established governance mechanisms (independent directors, recusal, fairness opinions) for handling them. But it does mean the price was set inside a room where most of the people had an interest on both sides of the table.

The liquidity engineering — why now

To understand the timing, you have to understand what venture firms are under pressure to produce in 2026. The metric that matters right now is DPI — Distributed to Paid-In capital. Not paper markups, not TVPI, not "our portfolio is worth $40B on the last round." Actual cash, wired back to limited partners. The IPO window has been unreliable, hold periods have stretched, and LPs have grown openly skeptical of unrealized marks.

Now look at the structure. Cyera raised $600M in June and holds a war chest. It deploys roughly $700M of that cash to buy Oasis. Cyberstarts, Sequoia, and Accel — holding meaningful positions in Oasis from early rounds at low cost basis — convert a large portion of that stake into realized cash today. The remaining consideration rolls into Cyera equity, which keeps them exposed to the bigger prize: a future Cyera IPO at a much larger valuation.

The elegance of it

They return hundreds of millions in hard DPI to LPs now, keep upside exposure to the combined entity, remove a portfolio company that would have needed years and hundreds of millions more to reach independent scale, and hand Cyera a genuine product gap-filler in the hottest category in security. One transaction, four objectives. Whatever else you think of it, it is extremely well constructed.

None of which requires cynicism about the product logic. Both things are true at once: the strategic case stands on its own merits, and the deal structure solves a pressing problem for three funds simultaneously. Sophisticated investors are perfectly capable of doing a smart strategic deal that also happens to be excellent portfolio management.

What it means for buyers

Expect consolidation pressure on your renewals. Cyera now sells data security and NHI governance as one platform. If you buy DSPM from one vendor and NHI from another, you will get a bundling pitch — and probably a decent discount to consolidate. Evaluate whether the integration is real or roadmap before you take it.

Watch the integration risk. Cyera has now made six acquisitions (Trail Security $162M, Ryft ~$100–130M, Genie ~$50M, plus Otterize and Shape AI) totalling roughly $1.35–1.4B. That is a lot of engineering surface to knit together in eighteen months. Ask specifically which acquired components share a data model today versus which are still separately-operating units.

Re-underwrite the standalone NHI vendors. If you were mid-evaluation with Oasis, your vendor's roadmap and support model just changed owners. That's not automatically bad — more resources, broader platform — but the product priorities of a $1B acquisition inside a $12B company are not the priorities of an independent Series B.

So who's next?
Speculation — clearly labeled as such

The obvious question, and one we flagged in Issue 10 before this deal was announced: Cyberstarts also backed Linx Security from inception. Gili Raanan has been explicit about the thesis — "we believe identity would become the core control layer of modern security" — and the firm now has a demonstrated playbook for realizing that thesis through intra-portfolio consolidation.

Linx raised a $50M Series B in March 2026 led by Insight Partners at a reported ~$83M total raised, with roughly 100 employees and enterprise contracts in banking, healthcare, and the Fortune 500. It sits in IGA and agent governance — adjacent to, but not identical with, what Oasis brought to Cyera. Insight leading the B rather than an existing investor is a meaningful difference from the Oasis pattern, and it argues for Linx building independently for a while.

Our read: a near-term Linx acquisition by Cyera specifically seems unlikely — the capability overlap with Oasis is too high to pay twice. But Linx as an acquisition target generally, inside the next 18–24 months, looks entirely plausible given how aggressively Cisco, CrowdStrike, Palo Alto, and Check Point are buying in this exact space. If you're evaluating Linx, that's not a reason to walk away — it is a reason to negotiate change-of-control protections and get roadmap commitments in writing. We said the same thing in Issue 10, and this week made the point louder.

SOURCING: Deal terms per Calcalist, TechCrunch, SecurityWeek, Globes, and WSJ reporting, Jul 28–29 2026; Cyera confirmed the ~$1B figure to SecurityWeek. Cash/stock split (~$700M cash) per Calcalist. Oasis funding history (~$195M total, $120M Series B led by Craft Ventures with Cyberstarts, Sequoia, Accel participating) per company and press reports. ARR estimate for Oasis ($10–20M) and the 50–100x multiple comparison per Virtru's published analysis; Cyera's $200M+ ARR is an estimate, as the company is private and does not disclose financials. The "who's next" section is explicitly labeled speculation and represents The Perimeter's opinion, not reporting. No vendor or investor reviewed this analysis before publication.
03

Deep Dive II

Saviynt's big week — $300M ARR, a new platform, and some awkward arithmetic

Momentum, measured
Impressive numbers. Now check the denominator.

Saviynt announced $300M+ ARR, 80%+ bookings growth, 96% retention, and launched Zuma — a full AI identity security platform. All genuinely notable. But the valuation math is tighter than the press release suggests, and Zuma's positioning bears a resemblance to a competitor's May launch that is difficult to unsee.

ARR announced
$300M+Jul 28, 2026
Bookings growth
80%+company-reported
Last valuation
~$3BDec 2025, KKR-led
Implied multiple
~10xon current ARR
First, a correction worth making

Several outlets and a good deal of LinkedIn chatter this week framed the $300M as new capital. It isn't. The $300M is an annual recurring revenue milestone. The capital event was in December 2025: a $700M Series B growth equity round led by KKR, with Sixth Street Growth, TenEleven, and Carrick Capital participating, at a valuation of approximately $3 billion.

The distinction matters enormously for how you read the announcement. "We raised $300M" is a statement about investor conviction today. "We crossed $300M ARR" is a statement about customer conviction — arguably the better signal, and to Saviynt's credit, the harder one to manufacture. Crossing $300M ARR in this category is a real accomplishment and deserves to be reported as one.

The arithmetic nobody put in the press release

Now put the two numbers together. A ~$3B valuation on ~$300M ARR is roughly a 10x ARR multiple. Is that supportable in the current market? It depends entirely on one variable, and the answer is genuinely uncertain.

Per Jamin Ball's Clouded Judgement data as of July 31, 2026, here is where public SaaS actually trades:

Overall median EV / NTM revenue3.8x
Low growth (<15% NTM)3.0x
Mid growth (15–22% NTM)5.2x
High growth (>22% NTM)19.5x
Median NTM growth rate, all comps12%
Source: Clouded Judgement, Jul 31 2026. Multiples are EV / next-twelve-months revenue for public cloud software companies. Private companies typically trade at a discount to public comps for illiquidity, though strategic and scarcity premiums can offset this.

So the question becomes: which bucket is Saviynt in?

If mid-growth (5.2x × $300M)≈ $1.56B
If overall-median (3.8x × $300M)≈ $1.14B
If high-growth (19.5x × $300M)≈ $5.85B
Dec 2025 round priced at≈ $3.0B

This is where we part company with the simpler version of this argument circulating this week. If Saviynt's 80%+ bookings growth converts into sustained high revenue growth, a $3B valuation is not aggressive — it's conservative against a 19.5x high-growth median. KKR is not a naive buyer; they priced this round with access to the data room.

But if growth normalizes into the mid-tier — and bookings growth is a leading indicator that does not always convert cleanly into recognized revenue growth, particularly when it includes multi-year prepaid deals or heavy discounting — the same $300M ARR supports something closer to $1.5B. That would make the December round the high-water mark, and any subsequent primary raise a down round with the dilution and preference-stack consequences that follow.

Why a CIO should care about a private company's cap table

Because down rounds change vendor behavior. They trigger structure — liquidation preferences, ratchets — that pressures management toward short-horizon revenue. That shows up in your world as harder-edged renewal negotiations, more aggressive upsell motions, and occasionally a thinner product-investment budget. You are not investing in Saviynt, but you are underwriting a multi-year dependency on them. The financial trajectory is legitimately part of your diligence.

Zuma vs. Agentic Fabric — a side-by-side

Saviynt launched Zuma on July 28. SailPoint launched Agentic Fabric on May 11 — ten weeks earlier. Both companies announced from Nasdaq. Both structured the launch around a free discovery trial that upgrades into paid tiers. We put the public positioning of the two side by side, and we'll let you form your own view.

DimensionSailPoint Agentic Fabric — May 11Saviynt Zuma — Jul 28
Problem framing AI agents act at machine speed, "often without clear ownership, oversight, or consistent controls" AI agents are autonomous and dynamic, and "exist outside established governance processes"
Signature line "You cannot secure what you cannot see" "You can't secure what you can't see"
Structural triad Discover · Govern · Protect Discover · Protect · Manage (Insights · Access · Governance)
Identity treatment Treat AI agents as "first-class identities" alongside humans Govern AI agents as "first-class, non-human identities"
Discovery layer Complete inventory + identity graph; surfaces shadow AI Zuma Insights: continuous inventory, access map, shadow-AI discovery
Ownership model Map every agent to a human owner + lifecycle controls Ownership management, succession, lifecycle from registration to retirement
Runtime layer Real-time authorization, threat detection, automated response, least privilege Zuma Access + "Intent-Aware Runtime Authorization" evaluating intent, context, risk
Packaging Free Discovery Tool trial → Agentic Business / Business Plus tiers Free ISPM-for-AI/NHI trial → extend into Access + Governance
Platform claim "Delivered by our core SailPoint Platform" "Built on the same Saviynt Identity Security Data Fabric"
Category claim "New era" of identity for the agentic enterprise "Industry's first comprehensive enterprise AI Identity Security Platform"
Venue Nasdaq Nasdaq

To be scrupulously fair: there is a legitimate defense here, and it deserves airtime. Categories converge on shared vocabulary. "Discover, govern, protect" is close to an industry-standard triad. Every vendor in this space is solving a genuinely similar problem, reading the same analyst notes, and hearing the same objections from the same CISOs. Convergent positioning is not evidence of copying — it is often just evidence that the market has settled on how to describe a problem. Saviynt would presumably say exactly this, and it would not be an unreasonable answer.

And there are real differences. Zuma's "Intent-Aware Runtime Authorization" is a distinct framing — evaluating an agent's intent per action, not just its entitlements — and if the implementation matches the ambition, it's a genuine idea rather than a repackaged one. Saviynt also brings a real ISPM heritage that predates this launch.

But the accumulation is what makes this hard to wave away. One shared phrase is coincidence. A near-verbatim signature line, a mirrored structural triad, the identical "first-class identities" framing, the same free-trial-to-tiers packaging motion, the same platform-foundation claim, and the same launch venue — ten weeks apart — is a pattern. Reasonable people can disagree about what the pattern means. Our view is simply that a buyer should notice it, and should ask Saviynt directly what in Zuma is architecturally new versus newly named.

The demo, and the "momentum release" pattern

Zuma is described as "available now." Screenshots circulating from the launch show a clean, modern dashboard — identities discovered, AI agents and non-human counts, a "Risk at a glance" severity breakdown. It looks good. It also looks, to more than a few practitioners who've mentioned it to us, like a great many other modern security dashboards: the visual language of a rapidly-assembled contemporary web app rather than something with years of enterprise iteration behind it.

That observation lands differently for Saviynt than it would for most vendors, because of a pattern we documented in Issue 07. Practitioners have repeatedly described a gap between Saviynt's announcement cadence and its delivered reality — the Glassdoor reviews describing a culture that prioritizes "speed over quality," where "product releases sometimes feel more like early-stage iterations than mature enterprise solutions," and the r/IdentityManagement threads describing failed jobs and instability under load. Saviynt is genuinely well known for announcing well. The recurring practitioner question is whether the shipped product matches the launch deck.

Connecting the thread from Issue 07

We scored Saviynt "CAPABLE ON PAPER — DO YOUR HOMEWORK" three issues ago, and marked its product score down to 7.0 on exactly this basis. Nothing this week changes that verdict; if anything it sharpens it. A vendor with an unresolved trade-secrets suit from Delinea over allegedly misappropriated PAM product information — allegations, not findings, and Saviynt has moved to dismiss — announcing a platform whose positioning closely tracks a competitor's from ten weeks earlier is, at minimum, an unfortunate juxtaposition. We are not connecting those two things causally. We are noting that a company in active IP litigation has a stronger-than-usual interest in demonstrating originality, and that this launch does not obviously do that.

The practical advice is unchanged and unglamorous: ask for a proof-of-concept against your own environment at your own scale, ask which Zuma components are generally available versus in preview, ask for reference customers running it in production rather than in pilot, and ask what specifically is new engineering versus new packaging on the existing Identity Security Data Fabric. Those questions are fair to ask of any vendor. They're just more load-bearing here.

SOURCING: ARR, bookings growth, retention figures, and Zuma product structure per Saviynt's press release, Jul 28 2026 (GlobeNewswire) — all company-reported and not independently audited. December 2025 round ($700M Series B, ~$3B valuation, KKR-led with Sixth Street Growth, TenEleven, Carrick) per Reuters, SecurityWeek, and Cooley. SaaS multiples per Jamin Ball, Clouded Judgement, Jul 31 2026. SailPoint Agentic Fabric positioning per SailPoint's May 11 2026 press release and launch materials. The side-by-side comparison presents publicly available marketing language from both companies; the inference a reader draws from it is their own. Delinea v. Saviynt allegations remain unproven and are the subject of a pending motion to dismiss. Practitioner sentiment per sources documented in Issue 07. Valuation scenarios are illustrative arithmetic, not a company valuation, and The Perimeter holds no position in any company mentioned.
04

Vendor Spotlight

the pitch vs. the reality, synthesized from the people who run it

Microsoft Entra
NASDAQ: MSFT · Entra ID (formerly Azure AD) + ID Governance + Privileged Identity Management · The default you already own
VERDICT: UNBEATABLE CORE, INCOMPLETE GOVERNANCE
Core Auth / Access
8.8/10
Governance Depth
5.5/10
Vendor Stability
9.6/10
Licensing Clarity
4.2/10

Recent News — last 90 days

Attack surface Jul 2026
ShinyHunters breached Abbott through a compromised Entra SSO account

A voice-phishing campaign against employees yielded a corporate Microsoft Entra single sign-on account tied to Abbott's Cancer Diagnostics business. Attackers reportedly persisted for weeks, stealing credential files and deleting logs before detection. This is not an Entra product vulnerability — it's social engineering against the human in front of it — but it illustrates the concentration risk of the identity everything runs through.

Read: when Entra is your front door, an Entra account compromise is a full-estate compromise. Phishing-resistant credentials for privileged and IT staff aren't optional at this concentration of risk.
Platform ongoing 2026
Entra keeps expanding — Governance, PIM, Workload ID, Internet Access

Microsoft has continued pushing Entra well past directory services: ID Governance for lifecycle and access reviews, Privileged Identity Management for just-in-time elevation, Workload Identities for service principals, Verified ID, and the Global Secure Access line. The strategic pitch is that identity, endpoint, and security operations converge inside one Microsoft estate.

Read: the breadth is real and the roadmap is well-funded. Whether each individual module is competitive with a specialist is a separate question, and the answer varies enormously by module — see the governance reviews below.
Buyer friction persistent
The licensing matrix remains the most-cited complaint

Entra's capability tiers span P1, P2, ID Governance add-ons, and M365 E3/E5 bundles, with meaningful security features gated across them. G2's negative tag cloud for Entra ID is led by "Complexity," "Expensive," "Complex Administration," and "Difficult Learning." One Gartner Peer Insights reviewer of ID Governance put the cost structure bluntly: powerful basics are in E5 or P2, "but for the full IGA solution, additional licenses are needed" — so the real price is E5 plus the add-ons on top.

Read: the "it's free, we already have it" assumption is where Entra budgets go to die. Price the tier you actually need for the controls you actually want, not the tier you already own.
SOURCING: Product line and capability descriptions per Microsoft documentation and public product materials. Review sentiment per G2 (Entra ID, 892+ reviews) and Gartner Peer Insights (Entra ID, ID Governance, ID Protection, External ID) as of Jul 2026. Abbott incident per SWK Technologies and contemporaneous reporting; the compromise was of a customer's SSO account via voice phishing, not a defect in Microsoft's product. Microsoft did not review this assessment before publication.

The Pitch vs. The Reality

What Microsoft says
  • One identity platform across cloud, endpoint, and SaaS — already integrated with what you own
  • Conditional Access as a unified policy engine spanning users, devices, and workloads
  • Governance, PIM, and workload identity built in — no third-party IGA required
  • Best economics in the market when bundled into your existing M365 agreement
What practitioners report
  • Core auth, SSO, MFA, and Conditional Access are genuinely excellent — G2 4.5 across 892+ reviews
  • Governance is the weak module: "cannot be used as the only IGA today… the front-end is missing"
  • Reporting in ID Governance described as "very poor"; custom reports effectively unavailable
  • Licensing complexity is the single most consistent complaint across every review platform
  • Non-Microsoft app integration is thinner than the Microsoft-estate experience suggests

Community Pulse — synthesized signal

G2 · Microsoft Entra ID 4.5/5 · 892+ reviews
"Centralized identity management with strong security features and seamless integration with Microsoft services."
— synthesized from G2's review summary. Top positive tags: Ease of Use (129), Security (122), Single Sign-On (90), Identity Management (89), Integrations (80). The core product is genuinely well-regarded and that shouldn't be understated
strongly positive
G2 · the negative tag cloud complexity & cost
"Licensing is a frustration — genuinely useful features are locked behind higher-tier plans, and there isn't clear in-product guidance about what's included versus what you're missing."
— verified reviewer · negative tags led by Complexity (56), Expensive (53), Complex Administration (42), Difficult Learning (38), Complex Setup (37). Reviewers also flag frequent renames and deprecations that slow troubleshooting
real friction
Gartner Peer Insights · ID Governance the weak module
"The biggest problem is that the solution cannot be used as the only IGA today. It just doesn't have a front-end. It has a great back-end with many functions, API integration, etc, but the front-end is missing… Reporting capabilities are very poor."
— verified enterprise reviewer · another notes Microsoft is "still immature compared to some other well established vendors" in this category, and that much functionality is assembled via Logic Apps rather than built-in integrations. This is the clearest gap in the platform story
back-end strong, front-end missing
Gartner Peer Insights · ID Protection effective, opaque
"Entra ID Protection allowed our organization to identify identity-related threats and detect compromised users in time… but the black box of the risk engine sometimes detects multiple false-positive alerts that aren't always clear for our SOC analysts."
— verified reviewer · other flagged limits: 30-day log retention, limited integration with non-Microsoft apps, and the P2 licensing requirement (ID Protection is not included in P1 or M365 E3)
works, but opaque
Structural Position · the bundle qualitative · decisive
"Nobody gets fired for using what's already in the E5 agreement. That's the whole competitive dynamic, and every other identity vendor knows it."
— representative of the practitioner consensus. Entra's real advantage isn't feature superiority in any single category; it's that the buying decision is frequently pre-made by a Microsoft enterprise agreement signed elsewhere in the org. Specialists must clear a much higher bar to justify incremental spend
structurally dominant
METHOD: Synthesized from G2 (Entra ID, 892+ reviews) and Gartner Peer Insights (Entra ID, ID Governance, ID Protection, External ID) as of Jul 2026. A note on the axes: we've deviated from our standard four for this assessment because a single blended "product" score would actively mislead. Entra is not one product — it is a strong core authentication platform with a materially weaker governance layer attached, sold through a licensing structure that is itself a significant part of the buying experience. So we scored Core Auth / Access and Governance Depth separately (8.8 vs 5.5), and replaced sentiment with Licensing Clarity (4.2), because that is what reviewers complain about most and what most affects the actual cost of ownership. Vendor Stability (9.6) is close to definitional — this is Microsoft. Composite scoring across such different axes is less meaningful here than in our other assessments; read the axes, not the average.

The Signal Read

Trajectory: structurally dominant, functionally uneven. Microsoft Entra is the most consequential identity product in the enterprise market, and mostly not because it wins feature bake-offs. It wins because it is already in the agreement. Core authentication, SSO, MFA, and Conditional Access are genuinely excellent — 4.5 on G2 across nearly 900 reviews, with ease of use and security leading the praise. If your estate is Microsoft-centric and your requirement is strong, well-integrated workforce authentication, Entra is not merely adequate; it is a very good answer.

The governance story is where the platform claim strains. The most useful review we found this cycle described Entra ID Governance as having "a great back-end" while "the front-end is missing" — you either invest heavily in user education or integrate a real IGA on top. Reporting is described as "very poor." A separate reviewer called Microsoft "still immature compared to some other well established vendors" in this category. That is a meaningfully different product maturity from the auth layer, and the single bundled brand name obscures it.

And then there's the licensing. It is genuinely the most consistent complaint across every platform we checked — P1 versus P2 versus ID Governance add-ons versus E3 versus E5, with security features distributed across tiers and, per reviewers, little in-product clarity about what you're missing. The practical consequence is that organizations routinely believe they have controls they have not licensed. That is a security problem dressed as a procurement problem.

Net for a CISO: use Entra for what it's genuinely best at, and be honest with yourself about the governance gap rather than assuming the bundle closes it. The most common expensive mistake we see is not choosing Entra — it's choosing Entra, assuming governance is covered, and discovering at audit time that it isn't.

Lean in if…
  • Your estate is Microsoft-centric and workforce auth/SSO/MFA is the core requirement
  • You want Conditional Access as a unified policy engine across users and devices
  • You already hold E5 and the P2-tier controls genuinely meet your risk requirements
  • Vendor longevity is a hard constraint — this is as low as counterparty risk goes
Do your homework on…
  • Governance: pilot ID Governance against your real access-review and reporting requirements before assuming it replaces a specialist IGA
  • Licensing: map every control you're counting on to the specific SKU that includes it — in writing
  • Non-Microsoft apps: test your actual third-party estate, not the Microsoft-native happy path
  • Log retention: 30 days in ID Protection may not meet your investigation or compliance needs
  • Concentration risk: if Entra is the front door to everything, model what an Entra account compromise actually costs you
05

The Stack

a category, tool, or idea worth knowing this week

Contract clause to add

Change-of-control protection is now a standard ask

230 security deals this year, and the identity cluster is the densest. There is a real probability that a vendor you sign this quarter is owned by someone else before your first renewal. Ask for: continuity of support terms through an acquisition, roadmap commitments that survive a change of control, and a termination-for-convenience right if the product is materially deprecated. Vendors resist these. Ask anyway — the ones confident in their independence will negotiate.

Diligence technique

Read the launch, then read the competitor's launch from last quarter

This week's Zuma/Agentic Fabric side-by-side is a useful reminder: category vocabulary converges fast, and marketing language is the cheapest thing a vendor produces. Before you're impressed by a launch, pull the last two quarters of competitor announcements in the same category. If the positioning is near-identical, the differentiation — if it exists — is in the architecture, not the deck. Ask what's engineered differently, and make them answer in specifics.

Financial literacy

Learn to read your vendor's valuation like a risk signal

You're not an investor, but you are underwriting a multi-year dependency. A private vendor priced well above current public comps has to either grow into that number or reprice down — and down rounds bring liquidation preferences, structure, and short-horizon revenue pressure that eventually shows up in your renewal. Jamin Ball's Clouded Judgement publishes the public multiples free every week. Ten minutes a quarter is enough to know whether your vendor's last round looks reasonable or heroic.

06

Boardroom

one line to sound three moves ahead in your next exec meeting

Say this

Get ahead of the consolidation question before procurement asks it

Your board and your CFO are reading the same headlines about billion-dollar security acquisitions. The instinct that follows is "shouldn't we consolidate vendors and save money?" — a reasonable question with a genuinely nuanced answer. Get there first, and frame it as portfolio risk management rather than a spend debate. The strongest position is knowing which of your vendors are acquisition candidates before someone else raises it.

"Three of our security vendors are plausible acquisition targets in the next two years. I'm not worried about that — I'm making sure our contracts survive it. Change-of-control terms are cheaper to negotiate before the deal than after."
07

Overheard

a spicy anonymized take from the community this week

"I sat through two agentic identity launches this quarter. Same problem statement, same three pillars, same free discovery trial, same Nasdaq backdrop. At some point the category stops having competitors and just has one deck with different logos on it."
— identity program lead, Fortune 200 · overheard in a peer Slack, lightly paraphrased