CIOPages
All RFP packages

RFP Package · Cybersecurity & Identity

Identity & Access Management (IAM) RFP questions and template

122 questions, 10 demo scenarios and a five-vendor scorecard for choosing Identity & Access Management (IAM) software, in one Excel workbook.

What this package is for

Use it to run a Identity & Access Management (IAM) software selection, from the first long list to the final scorecard.

What the category covers. Software that signs the workforce in, governs who has access to what, and runs the joiner, mover and leaver lifecycle: passkeys and phishing-resistant authentication, enrollment and recovery, adaptive access policy, single sign-on, provisioning, hybrid directory, identity threat detection and machine identities. Bought by identity, security and IT infrastructure leaders replacing an identity provider or retiring passwords.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 24 questions screen out products that lack something you need.
  • RFP, to the shortlist. 63 questions ask how each product does the work.
  • Deep dive, to the finalists. 35 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 90 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Provide your published support matrix listing the operating systems, browsers and platform authenticators on which a user can sign in with a passkey created through W3C Web Authentication Level 3, with no password.

Why it matters. Users whose devices cannot complete passkey sign-in stay on passwords, and those users remain open to phishing. A matrix that is missing or vague leaves the buyer unable to size that group before rollout.

Good answer
  • The matrix is a public or customer-portal document with named operating system and browser versions and a last-updated date
  • Known gaps and limitations are listed per platform, not only supported combinations
  • The matrix covers desktop and mobile platform authenticators separately
Red flags
  • The answer says "all modern browsers" without naming versions
  • The matrix exists only in a sales presentation
  • No limitations or unsupported combinations are listed

2. List each recovery path your product offers to a user who has no remaining registered authenticator, stating for each whether an administrator can disable it.

Why it matters. Recovery is an alternate way into the account, so the weakest path that cannot be turned off sets the real strength of sign-in, whatever share of users hold passkeys.

3. Which scopes can an administrator use to turn off SMS, voice and email one-time codes: the whole tenant, chosen groups, or account recovery only?

Why it matters. If these codes cannot be removed, they remain a phishable route into accounts even after users enroll passkeys.

Capability areas

Phishing-resistant authentication and passkeys (14)

In: passkey sign-in on platform authenticators, roaming security keys (USB, NFC, Bluetooth), synced versus device-bound passkey controls, cross-device sign-in, user verification, conditional mediation, smart card certificate sign-in, desktop OS login, shared and kiosk devices, relying party ID design, attestation and authenticator allow/block lists, server certification status, and alternatives for users who cannot use biometrics or lack a supported authenticator. Out: enrollment and recovery flows, which are covered under ENR, and policy rules that decide when a method is required, which are covered under POL.

Enrollment and account recovery (13)

In: passwordless first enrollment, enrollment prompts for existing users, multiple named authenticators, administrator pre-registration of keys, identity proofing before enrollment, single-use expiring enrollment links, new-device enrollment rules, lost-device self-recovery, helpdesk-assisted recovery with caller verification, temporary access passes, recovery codes, revocation of lost authenticators, and user notifications. Out: general helpdesk staffing and support SLAs.

Adaptive access policy and session control (12)

In: policy per application and group, allowed authenticator types and assurance levels, step-up for sensitive apps and actions, risk signals (location, IP reputation, impossible travel), device trust from endpoint tools, disabling SMS, voice and email codes, enforcing phishing-resistant-only groups, rate limiting of failed sign-in and recovery attempts, session lifetime, reauthentication, continuous session evaluation, and behavior when the service is degraded so it does not fall back to weaker methods. Out: post-authentication threat detection, which is covered under ITD.

Single sign-on and application federation (11)

In: acting as identity provider over SAML 2.0, OpenID Connect and WS-Federation, acting as the passwordless step for an existing identity provider, header-based and agent-based access to legacy and home-grown apps, VPN and RADIUS sign-in, verified prebuilt integrations for the buyer's named apps, interoperability testing, and token signing key rotation. Out: the vendor's own product SSO for its admin console, which is covered in the security module.

Joiner-mover-leaver lifecycle and provisioning (13)

In: the HR system as authoritative source, joiner, mover and leaver automation, SCIM 2.0 and LDAP provisioning, provisioning to apps without SCIM, deprovisioning that blocks sign-in and ends sessions, contractor, partner and seasonal populations with sponsors and end dates, self-service access requests, handling of dirty or duplicate HR data, and integration points to identity governance and privileged access tools. Out: full certification campaigns and privileged session vaulting, which belong to separate governance and PAM evaluations.

Directory and hybrid architecture (10)

In: the cloud or universal directory, coexistence with on-premises Active Directory and LDAP, hybrid agents and their failure behavior, write-back, multi-domain and multi-forest support, groups populated by user attributes, and the blast radius and failure isolation of the directory and authentication service as a dependency. Out: generic hosting regions and DR commitments, which are covered by the deployment-hosting and business-continuity-dr modules.

Identity threat detection and response (11)

In: post-authentication risk evaluation, session and token theft detection, anomaly signals, identity security posture (dormant accounts, over-privilege, MFA and passkey coverage gaps), automated response such as session and token revocation, and two-way signal exchange with the SIEM and XDR including event delivery latency. Out: the vendor's own SOC and vulnerability management, which are covered in the security module.

Machine, workload and AI-agent identity (10)

In: OAuth client-credentials and workload identity federation for services and APIs, scoped short-lived credential issuance, discovery and inventory of service accounts and other non-human identities, ownership assignment, secrets handling, rotation, revocation, and identities for AI agents acting on a user's behalf with delegated, limited scope. Out: controls over AI agents inside the vendor's own product, which are covered by the ai-agentic-autonomy module.

Migration, coexistence and password retirement (9)

In: running the new platform in parallel with the incumbent identity provider, cutover by application tranche, coexistence of password and passkey users, removal of passwords by user or group once a passkey is held, import of existing WebAuthn public-key credentials, account linking without duplicate users, and migration tooling for app configurations and policies. Out: contract-end data export, which is covered by the migration-exit module.

Administration, delegation and audit (11)

In: the admin console, scoped roles such as a helpdesk role that can recover users but cannot change policy, delegated administration by business unit, phishing-resistant sign-in for administrators, configuration export and change control, non-production tenants and promotion to production, authentication and admin event logs with before and after values, tamper protection for logs, and reporting on enrollment, method use, failures and recovery. Out: generic log retention commitments and vendor staff access, which are covered in the security module.

Sign-in experience and developer tooling (8)

In: no-code configuration of registration, sign-in, recovery and step-up flows with versioning and preview, editable flow templates, hosted sign-in pages branded and served on the buyer's domain, web, iOS and Android SDKs that handle WebAuthn and passkey prompts, the API for users, authenticators and policies, and lifecycle and authentication webhooks. Out: generic API availability, rate limits and deprecation policy, which are covered by the integration module.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. New hire's first day, no password
  2. Lost phone recovered while traveling
  3. Social-engineering call to the help desk
  4. Termination effective immediately
  5. Stolen session token replayed
  6. Our hardest applications
  7. Hybrid coexistence and tranche cutover
  8. Contractor engaged for six weeks
  9. AI agent acting on a user's behalf
  10. Policy change under change control

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Identity & Access Management (IAM) RFP questions are there?

122 solution questions in 11 capability areas: 24 for the RFI, 63 for the RFP and 35 deep-dive questions for the finalists. The workbook adds 90 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Identity & Access Management (IAM)

For the business side of the same change: