IAM delivery and operations

IAM Obsolescence

IAM obsolescence is the point at which an identity component still runs but becomes progressively hard to maintain, secure or evolve.

Synonym
end of lifetechnical ageing

Definition

Several forms of obsolescence are worth distinguishing in an IAM estate: product obsolescence, when a vendor retires a line; version obsolescence, when support ends; technical obsolescence, when underlying components are no longer sustainable; protocol obsolescence, when an authentication or federation mechanism no longer provides the expected security level; skills obsolescence, when nobody left can work on it; and functional obsolescence, when the platform no longer matches how the organisation actually works. A platform can combine several of these while remaining perfectly available.

Why it matters

Anticipating obsolescence lets an organisation choose when to migrate instead of being forced into it.

The Ariovis perspective

"It still works" is not a lifecycle strategy. But "it is old" is not a sufficient reason to migrate either. Obsolescence should be assessed through its real impact: security, support, skills, compatibility, evolvability, cost and business risk.

Common pitfalls

  • A common mistake is tracking product obsolescence only, and overlooking skills obsolescence, which is often the most constraining.

These concepts matter most inside a real project.

The first conversation helps establish your context, the systems involved and the next useful decision.