Between the first edition of this Wave and the second, Forrester added exactly one word to the title: Security.
In March 2024 the evaluation was called The Forrester Wave: Workforce Identity Platforms. In May 2026 it came back as The Forrester Wave: Workforce Identity Security Platforms, published May 20, 2026 and announced the following day by Geoff Cairns, the Principal Analyst who has owned this research stream since the 2024 edition. Nothing else in the title moved. One word, inserted in the middle, and the whole evaluation changed meaning.
A workforce identity platform used to be where users signed in. Workforce identity security is where an organization decides who and what may act, watches that decision being used, and moves to reverse it when it is misused. Not an SSO project anymore. A control plane.
The word Forrester inserted
Forrester's own announcement is blunt about what the rename records. Between the 2024 and 2026 evaluations, two capabilities became core: identity security posture management (ISPM) and identity threat detection and response (ITDR). They joined phishing-resistant multifactor authentication, just-in-time privileged access, and contextual access controls as the table stakes of the category.
Read that as a repricing of the market. In 2024, Forrester's first stated trend was adaptive identity security, framed as uniting Zero Trust principles with user productivity. The 2024 scorecard cared about friction. The 2026 announcement barely mentions user experience at all. Its three buyer themes are fundamentals first (lifecycle management, phishing-resistant MFA, least-privilege governance), then identity intelligence that ends in enforcement (automated remediation, adaptive access, real-time policy), then agentic AI. The 2024 report spent a paragraph on friction; the 2026 announcement spends its paragraphs on enforcement.
The inserted word is the verdict. The category stopped selling convenience and started selling containment. Identity is no longer the friendly front door of the enterprise stack. It is the layer where the attack chain is expected to break, from the phish through the hijacked session to lateral movement. Forrester says the platform must now address that full chain, and scores vendors on whether it can.
The scorecard this one replaces
The predecessor edition is worth reading closely, because it defined the field the 2026 report re-scored.
The Forrester Wave: Workforce Identity Platforms, Q1 2024, published March 20, 2024, evaluated twelve vendors across twenty four criteria. It replaced Forrester's 2021 Wave for Identity as a Service, and it carried one of the sharpest historical details in the category: OneLogin, a Leader in 2021, was acquired by One Identity and fell out of the Leader group before the next scorecard. User experience had become central to the evaluation, and the merger candidate's momentum did not survive it.
The 2024 tiers read as follows. Leaders: Okta, Microsoft, and CyberArk. Strong Performers: Ping Identity, Saviynt, SailPoint, and IBM. Contenders: JumpCloud and One Identity. Challengers: OpenText, Entrust, and Broadcom.
Okta led on current offering and took the maximum possible score in market presence. Microsoft placed second overall and took the top strategy score. CyberArk placed third, tied with Okta for the second-highest strategy score, and collected the highest possible scores in six criteria: vision, innovation, access management, platform security, endpoint device trust, and identity threat detection. Two of its details aged especially well. It was one of only two vendors to earn the top score in platform security, and it was the only company named a Leader in both this Wave and The Forrester Wave: Privileged Identity Management, Q4 2023. In 2024, CyberArk was the vendor whose scorecard already looked like a security evaluation.
SailPoint sat in the Strong Performer group, tied with Saviynt for the fourth-highest strategy score. The 2024 field was twelve names. The 2026 field is ten.
The May 2026 scorecard: The Forrester Wave: Workforce Identity Security Platforms, Q2 2026
The new evaluation scores ten providers. Forrester's announcement calls them "the ten providers that matter most" in the category, and the criteria set now spans the renamed category's full scope: phishing-resistant MFA, just-in-time privileged access, contextual access controls, ISPM, ITDR, and the planning dimensions of vision and roadmap alongside the usual current-offering and market-presence categories.
Two Leader placements are publicly confirmed.
Microsoft, through its Entra portfolio, was recognized as a Leader with the highest scores in both current offering and strategy. Forrester's cited strengths are identity threat detection and response with real-time analytics that surface anomalous sign-ins and trigger remediation, phishing-resistant authentication (FIDO2, Windows Hello for Business), identity verification, AI-enabled policy enforcement through Conditional Access pulling device health, location, and AI-agent activity signals, and unified governance across Azure, Microsoft 365, on-premises Active Directory, and third-party SaaS from a single policy engine.
Okta was named a Leader for the second consecutive time, with the highest possible score of five out of five in nine criteria: vision, roadmap, adoption, community, administration, identity data sources, identity lifecycle management, identity security posture management, and availability and resiliency. Forrester credits Okta with "a clear vision for identity as the cornerstone of enterprise security," anchored in what it calls a neutral identity security fabric and leadership in open identity standards such as Cross App Access. On capability, the report notes "superior depth in IAM administration, authentication, and identity security posture management." Okta's 2025 acquisition of Axiom Security gets a nod for strengthening privileged access management, and the report flags identity threat detection driven by device trust and single logout, enabling near-real-time enforcement.
The remaining eight placements sit behind Forrester's paywall, and no public vendor announcements confirm them at the time of writing. The stop-loss here is deliberate: a scorecard reported from memory of the 2024 edition is not the 2026 scorecard. What is verifiable is the two Leaders, the ten-vendor field size, and the criteria shift. That is what the rest of this article is built on.
The fork inside the Leader tier
Here is the part a vendor would never write about its own placement. The two confirmed Leaders are not interchangeable. They are the two ends of the market's central argument.
Microsoft Entra is the integrated answer. Identity security arrives as part of a security and cloud estate, one policy engine across Azure, Microsoft 365, on-premises Active Directory, and SaaS. The strength list Forrester published for Entra is a control-plane list: ITDR, Conditional Access, unified governance.
Okta is the independent answer. A neutral fabric, open standards, no cloud platform or security suite attached. Forrester wrote the fork into the citation itself: Okta is "a strong fit for medium and large enterprises operating diverse, multicloud environments" that want "an independent, full-scope workforce IAM platform rather than one tightly coupled to a broader security or single cloud provider."
That sentence is the buying guide, buried in a vendor citation. Forrester is saying the decision between these two Leaders is not a score comparison. It is a business-model question the buyer must answer first: bundle or independence. The tier cannot answer it. The tier only tells you both answers are executed well.
For European buyers the fork runs steeper still, where bundling pressure and sovereignty constraints pull in opposite directions. A scorecard cannot price that tension. It can only name the two vendors who sit on opposite sides of it.
The users who are not people
The third theme of the 2026 announcement is the one that will define the next edition: agentic AI. The report now expects platforms to govern machine and AI agent identities with fine-grained dynamic authorization, short-lived credentials, and continuous monitoring of agent actions.
The scoring reflects it. Okta's maximum Roadmap score is explicitly tied to AI agent governance and just-in-time privilege capabilities. Microsoft's cited strengths include Conditional Access evaluating AI-agent activity signals. This is a remarkable place for a workforce category to be. A market built around managing people is being scored on its ability to manage software that acts on behalf of people, at machine scale, with credentials of its own.
Forrester had already made this move before the Wave. The Workforce Identity Security Platforms Landscape, Q4 2025, published in December 2025, covers thirty two vendors across the broader market and names machine and AI agent identity management as one of its extended use cases. Specialist entrants appear there that never made the old Wave's shortlist. Linx Security is listed across three extended use cases: identity governance, machine and AI agent identity management, and identity security posture management. Veza appears as a notable vendor in identity governance, ISPM, and machine and AI identity management. ManageEngine is among the thirty two names.
The Landscape used the new word six months before the Wave did. The rename did not come out of nowhere. Forrester had already recategorized this market as security, and the Wave simply caught up to the Landscape.
Why the field is bigger than the scorecard
Ten providers get scored. Thirty two get named. The gap is the honest limitation of this report, and it is worth being precise about which part is which.
First, the Wave is a shortlist, not a census. The Landscape of Q4 2025 is the census, and it shows a market where identity governance specialists, posture management startups, and platform giants coexist. A buyer who reads only the Wave reads a tenth of the market. That is fine for a shortlist. It is a problem if the tier column gets mistaken for the field.
Second, the new core criteria are first-edition criteria. ISPM and ITDR became core between 2024 and 2026, which means every score on them in this Wave is a first score. A criterion added this year has no track record. It cannot yet tell you who sustains a posture over time; it can only tell you who looks strongest on the day of evaluation.
Third, the full roster is gated, and only the two Leaders have confirmed their placements publicly. Any buyer drafting a shortlist from this report should treat unconfirmed tier claims found online with suspicion. The report is out, but the public record of it is thin.
That thinness is itself evidence of how young the renamed category is. The 2024 edition replaced the 2021 Identity as a Service Wave and scored twelve vendors. The 2026 edition renames the category, shrinks the field to ten, and adds criteria that did not exist in 2021. Three scorecards, three different products. The market has not settled. It has only changed its name to match what it now does.
Three questions the rename forces
Buyers do not get to skip these by buying the top score. The rename made each of them urgent.
One: which side of the fork are you on? If your estate is Microsoft-centric and your security stack is a bundle, Entra's unified governance is the model the scorecard rewards. If you run diverse, multicloud environments and value independence from any single vendor, Forrester's own language points to Okta. Decide the business model before you read the tier, because both confirmed Leaders score well and neither converts cleanly into the other's architecture.
Two: show evidence for the new criteria, not just the scores. ISPM and ITDR are the reason this report is called what it is called, and every score on them is a first score. Ask the vendor for deployments, detection histories, and reference customers on exactly those capabilities. A five out of five on a first-edition criterion is a claim. The second edition will be the receipt.
Three: who are your users in 2029? If agents and machine identities outnumber people, the platform's agent identity governance must be working product today, not roadmap. Okta's top Roadmap score is for agent governance that is, by definition, not fully shipped. The next edition will score what exists. Your contract will be live before that edition publishes.
The detection side of this same identity signal is scored separately in Security Analytics Platforms, where Forrester frames the buying decision as a bet on which AI "horse" reshapes the security team around it.
Analyst Source
Forrester Research
This article draws on Forrester's coverage of workforce identity security: The Forrester Wave: Workforce Identity Security Platforms, Q2 2026, published May 20, 2026, evaluating ten providers across criteria spanning phishing-resistant MFA, just-in-time privileged access, contextual access controls, ISPM, ITDR, vision, roadmap, and market presence, announced by Principal Analyst Geoff Cairns. It renames and succeeds The Forrester Wave: Workforce Identity Platforms, Q1 2024 (twelve vendors, twenty four criteria), which itself replaced the 2021 Identity as a Service Wave. The Q4 2025 Landscape of the same category (thirty two vendors) preceded the renamed Wave and defines workforce identity security platforms as unified platforms that govern, administer, and enforce identity security across human and nonhuman workforce identities, combining SSO, MFA, access management, identity governance, and AI-driven identity intelligence. Related but separate Forrester coverage includes The Forrester Wave: Privileged Identity Management, Q4 2023.
Source research
- The Forrester Wave: Workforce Identity Security Platforms, Q2 2026
- Announcing The Forrester Wave: Workforce Identity Security Platforms, Q2 2026 (Forrester blog, Geoff Cairns)
- The Forrester Wave: Workforce Identity Platforms, Q1 2024
- The Workforce Identity Security Platforms Landscape, Q4 2025
- Okta press release: Okta Named a Leader in The 2026 Forrester Wave: Workforce Identity Security Platforms
- Microsoft Security Blog: Microsoft recognized as a Leader in The Forrester Wave for Workforce Identity Security Platforms
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.