Symantec IGA Features
User on/off Boarding (13)
-
Self Service Access requests
Users can request access to an application and be automatically provisioned if they meet policy requirements
-
Smart/Automated Provisioning
Automates account/access rights creation, changes and removals for on-premise and cloud apps
-
Role Management
Establish roles that create a set of authentication rights for each user in the role
-
Policy Management
Enables administrators to create access policies and applies policy controls throughout request and provisioning processes
-
Access Termination
Terminate access to multiple applications based on dates
Approval Workflows
Allow business stake-holders/managers to approve or reject requested changes to access via a defined workflow
Compliance Management
Track and manage adherence to policies for any service, product, process, or supplier
Audit Management
Plan, schedule, and execute organization's accounts and assets to ensure compliance with policies and laws
Workflow Management
Create, design and manage workflows for repetitive tasks
Template Management
Create, save, and re-purpose templates for emails, forms, etc.
Application Management
Track, manage and store the applications of potential future members, customers or candidates
Password Management
Generate and store passwords in an encrypted database and assist in retrieving lost or forgotten passwords
Access Management
Control and manage access to company resources
User Maintenance (3)
-
Self Service Password Reset
Enables users to reset passwords without administrator interaction. Enforces password policies when resetting.
Bulk Changes
Change users and permissions in bulk
-
Bi-directional Identity Synchronization
Keep identity attributes consistent across applications whether the change is made in the provisioning system or the application
Governance (2)
Identifies and Alerts for Threats
Alerts administrators when inappropriate access occurs
Compliance Audits
Proactively audits access rights against policies
Administration (12)
Reporting
Standard and customized report creation to ensure appropriate access rights have been assigned
Mobile App
Provides mobile application that alerts administrators of potential issues and allows administrators manage access rights
-
Ease of set up for target systems
Support for wide variety of cloud and on premise apps to automate provisioning for existing and new applications procured
APIs
Provides appropriate application interfaces to enable custom integrations for unique business requirements
Bi-Directional Identity Synchronization
Keep identity attributes consistent across applications whether the change is made in the provisioning system or the application.
Policy Management
Enables administrators to create access policies and applies policy controls throughout request and provisioning processes.
Cloud Directory
Provides or integrates with a cloud based directory option that contains all user names and attributes.
Application Integrations
Integrates with common applications such as service desk tools.
Password Synchronization
Securely access passwords from any device
Password Management
Generate and store passwords in an encrypted database and assist in retrieving lost or forgotten passwords
Credential Management
Manage usernames, account numbers, passwords, biometric data, public access keys, and other documentation
Password Policies
Set and enforce password security requirements such as length, character sets, and regular password changes
User Experience (4)
Self-Service Experience
Allows users to set, change passwords easily without interaction from IT staff.
Mobile App Usability
Integrates with your mobile device for use on mobile apps.
Multilingual Support
Accommodates multiple languages.
Remote Support
Provide support to your customers and employees remotely over a shared network
Authentication (4)
Multi-Factor Authentication
Provides support for Multi-Factor authentication, so users are required to provide multiple factors to authenticate. For example, something they know, Something they have or something they are.
Biometric Authentication
Uses biometric trait or characteristic to authenticate. Additional hardware may be required to support this type.
Other Authentication Methods
Provides authentication capabilities outside standard authentication methods such as MFA and biometric .
Role-Specific Authentication
Able to assign authentication requirements for different levels of users, such as more robust authentication for senior level executives.
Functionality (13)
Self-registration and self-service
Enables a seamless customer experience with self-registration and self-service functions, including account creation and preference management.
Authentication
Verifies user identity with authentication, which may include multiple multi-factor authentication methods.
Scalability
Scales to support growing a customer base.
Customer data linking
Integrates with directories or other data stores that house customer data to create a complete view of a customer.
Access Management
Control and manage access to company resources
Two-Factor Authentication
Extra layer of security that requires not only a password and username but also something specific to that user
User provisioning
Simplifies or automates user provisioning, deprovisioning, and other user role changes.
Password manager
Offers password management tools to end users.
Single Sign-on
Offers single sign-on functionalities to end users, allowing them to authenticate once and be given access to all of their company accounts.
Enforces policies
Enforces user-access policies based on individual, role type, group membership or other factors to prevent unauthorized access to company systems and data.
Authentication
Authenticates users prior to granting access to company systems.
Multi-factor authentication
Offers multi-factor authentication methods to verify a user's identity.
Two-Factor Authentication
Extra layer of security that requires not only a password and username but also something specific to that user
Type (2)
On-premises solution
Provides an IAM solution for on-prem systems.
Cloud-solution
Provides an IAM solution for cloud-based systems.
Reporting (7)
Activity Tracking
Track and document all activities across devices, networks, and other systems
Reporting
Provides reporting functionality.
Access & Permission Change Reporting
Log and report all modifications to user roles and access rights.
Compliance & Audit Trail Export
Provide standardized reports for regulatory compliance and audits.
Ad hoc Reporting
Generate one-off reports that meet information requirements
Role-Based Permissions
Set & manage permission levels based on user roles and restrict access to only authorized individuals
Real-Time Reporting
Active reporting of data and metrics
Authentication & Authorization - Identity and Access Management (IAM) (1)
Adaptive & Contextual Access Control
Grant access based on user attributes, location, device posture or risk.
Administration & Governance - Identity and Access Management (IAM) (5)
Identity Lifecycle Management
Automate onboarding, offboarding, and access reviews throughout user lifecycles.
Self‑Service Account Management
Enable users to reset passwords and update profiles without admin support.
Member Accounts
Accounts held by members of an organization
User Management
Manage user accounts, profiles, roles, permissions, and other details across applications, devices or networks
Multiple User Accounts
Allow multiple users with individual logins and varying permissions to use the same account, software, portal, or service
Generative AI - Identity and Access Management (IAM) (3)
AI‑Driven Access Anomaly Detection
Identify unusual access patterns using machine learning models.
Automated Policy Tuning
Dynamically adjust access policies based on risk and AI-generated insights.
Predictive Role Recommendations
Suggest appropriate user roles based on usage patterns and peer behavior.
AI Authentication Risk Management - Customer Identity and Access Management (CIAM) (5)
Adaptive MFA
Possesses AI-driven triggers to determine when to require MFA or stronger authentication rather than always requiring it.
Anomaly Detection
Builds profiles of known devices/environments per user and flags deviations such as new devices, new networks, and/or suspicious locations as higher risk.
Fraudulent Login Detection
Spot fraudulent behavior, such as account takeover attempts, credential stuffing, bots, and brute force attacks through the use of AI.
Adaptive Authentication Policies
Uses machine learning to analyze past authentication events and suggest optimizations to security policies (e.g. thresholds, triggers) or to adjust rules over time.
Risk-Based Authentication
Leverages AI to assign a risk score to a login attempt based on context, device, IP, historical patterns to dynamically decide whether to prompt for MFA, additional challenges, or allow seamless login.
AI Biometric & Behavioral Analysis - Customer Identity and Access Management (CIAM) (2)
Behavioral Biometric Analysis
Monitors behavioral signals including typing patterns, mouse movement, and/or touch/swipe dynamics to verify user identity either at login or continuously after login.
Liveness Detection
Uses computer vision, facial recognition, or other biometrics during onboarding or at risk events, with AI-based liveness checks to prevent spoofing or replay attacks.
AI Context-Aware Security Controls - Customer Identity and Access Management (CIAM) (2)
Account Recovery Assistants
Generates dynamic prompts to guide users through account recovery workflows.
Constraint Enforcement
Implements artificial intelligence to filter, rewrite, or block prompts that attempt to access unauthorized data, escalate privileges improperly, exploit system weaknesses, or otherwise re-provision customer access permissions.
Additional Functionality (85)
Secure Data Storage
Securely stores data to prevent data loss or breaches
User Defined Attributes
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Audit Trail
A record of all activities within the system, including user access, changes made, etc.
Automated Scheduling
Automatically create schedules based on business needs or employee availability and qualifications
Active Directory Integration
Integrates with Active Directory
Secure Login
At least a username and password is required to access the system
Real-Time Notifications
Notifications that are delivered to users as soon as an event occurs
Event Logs
A chronological record of actions or occurrences within a network, software, or process
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Risk Assessment
Initiate collection and analysis of known risks
Self Service Portal
Online portal through which end users can access the system, manage tasks, or obtain information
Data Verification
Process of checking different types of data for accuracy to avoid errors or inconsistencies
Customizable Templates
Pre-designed layouts that can be customized to match preferences and requirements
Biometrics
Identify or authenticate a person's identity through biological data such as fingerprints or facial patterns.
Security Auditing
Systematic evaluation of the security of a company's overall security system and situation
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Real-Time Data
Receive data and information in real time
Reporting & Statistics
Collection, analysis, and representation of numerical data and generation of reports to understand various patterns
Monitoring
Observe and track the demand, usage, progress or quality of a system, product, or user
HIPAA Compliant
Compliant with HIPAA, which sets standards for sensitive patient data protection
Real-Time Monitoring
Active monitoring of systems, applications, or networks
Customizable Reports
Alter the layout and content of reports
Risk Analysis
Analyze potential risks across the organization
Secure Data Storage
Securely stores data to prevent data loss or breaches
User Defined Attributes
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Audit Trail
A record of all activities within the system, including user access, changes made, etc.
Automated Scheduling
Automatically create schedules based on business needs or employee availability and qualifications
Active Directory Integration
Integrates with Active Directory
Secure Login
At least a username and password is required to access the system
Real-Time Notifications
Notifications that are delivered to users as soon as an event occurs
Event Logs
A chronological record of actions or occurrences within a network, software, or process
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Risk Assessment
Initiate collection and analysis of known risks
Self Service Portal
Online portal through which end users can access the system, manage tasks, or obtain information
Data Verification
Process of checking different types of data for accuracy to avoid errors or inconsistencies
Customizable Templates
Pre-designed layouts that can be customized to match preferences and requirements
Biometrics
Identify or authenticate a person's identity through biological data such as fingerprints or facial patterns.
Security Auditing
Systematic evaluation of the security of a company's overall security system and situation
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Real-Time Data
Receive data and information in real time
Reporting & Statistics
Collection, analysis, and representation of numerical data and generation of reports to understand various patterns
Monitoring
Observe and track the demand, usage, progress or quality of a system, product, or user
HIPAA Compliant
Compliant with HIPAA, which sets standards for sensitive patient data protection
Real-Time Monitoring
Active monitoring of systems, applications, or networks
Customizable Reports
Alter the layout and content of reports
Risk Analysis
Analyze potential risks across the organization
Real-Time Notifications
Notifications that are delivered to users as soon as an event occurs
Access Certification
Verify user access rights within systems to confirm each user has appropriate and authorized access to resources
Behavioral Analytics
Track and analyse user behavior within a system or network
Self Service Portal
Online portal through which end users can access the system, manage tasks, or obtain information
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Multiple Authentication Methods
Authenticate user identities through different methods such as ID cards, PINs, passwords, RFID, and biometrics
User Provisioning
Create, modify, disable, or delete user accounts and their profiles across IT infrastructures
Data Security
Protect sensitive data for digital privacy
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Single Sign On
Allow users to access multiple services after entering their login credentials once
Automatic User/Device Recognition
The system can automatically recognize a user and/or device
Unified Directory
Store, modify, and track user accounts and access in a centralized directory
Self-Service Access Request
Enable end users to request access or request changes to their account privileges
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Mobile Access
Access software remotely via mobile devices
Employee Portal
Online portal where employees can access and track their own information
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Employee Database
Electronic storage of staff/employee contact information and job status in a centralized repository
Secure Password Sharing
Securely share encrypted passwords with colleagues
Single Sign On
Allow users to access multiple services after entering their login credentials once
Group Passwords
Create and edit passwords that can be accessed by a group of people
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Self-Service Access Request
Enable end users to request access or request changes to their account privileges
Alerts/Notifications
Alerts or notifications of various types such as pop-up messages, sounds, banners, or badges
Remote Access/Control
Access work applications remotely, for when working away from the office and/or traveling
Self Service Portal
Online portal through which end users can access the system, manage tasks, or obtain information
Password Database
A database of passwords to flag for reuse
Remote Access & Monitoring
Control system behavior and appearance, and access and report on system status/health from a distant location
Application Security
Identify and respond to security threats to developed applications
Password Protection
Protect passwords from security threats
Password Generator
Generates strong, unique passwords with customizable parameters
Reminders
Timed notification for any upcoming task, deadline, appointment, or activity
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Identity Lifecycle Management - Identity Governance and Administration (IGA) (3)
Identity & Entitlement Repository
Centralizes and reconciles identity, account, role, and entitlement data from connected applications, directories, and systems.
Access Provisioning & Deprovisioning
Creates, modifies, and removes accounts and entitlements across connected applications and systems based on approved access and lifecycle events.
Joiner-Mover-Leaver Automation
Automates provisioning, access changes, and deprovisioning as employees, contractors, and other users join, change roles, or leave the organization.
Access Governance and Compliance - Identity Governance and Administration (IGA) (4)
Access Certifications
Conducts scheduled or ad hoc reviews of user accounts and entitlements to validate that access remains appropriate.
Audit Trails & Compliance Reporting
Records identity and access decisions and generates reports that provide evidence for audits and regulatory compliance.
Segregation of Duties
Detects or prevents conflicting combinations of roles and entitlements based on defined segregation of duties policies.
Role Management & Role Mining
Creates, maintains, analyzes, and optimizes roles to standardize access based on job functions and access patterns.
AI-Powered Governance - Identity Governance and Administration (IGA) (3)
AI Access Recommendations
Uses AI or machine learning to recommend appropriate access and assist reviewers with approval, revocation, and certification decisions.
AI Access Risk Detection
Uses AI or machine learning to identify anomalous, excessive, or high-risk access based on identity attributes, peer groups, and entitlement patterns.
AI Role Discovery & Optimization
Uses AI or machine learning to discover access patterns and recommend new or modified roles based on users, entitlements, and organizational attributes.