Whitepaper
The 2025 Identity Automation Gap Report

The gap between the identity tools enterprises deploy and the critical tasks still run by hand: MFA enforcement, provisioning, offboarding, and credential rotation, especially for the apps that don't connect to your identity systems.
The identity automation gap is the distance between the identity policies organizations write and the identity work they actually automate. Most enterprises assume tasks like enforcing MFA, rotating credentials, provisioning access, and offboarding users are automated. In practice the execution still runs on people, especially for disconnected applications: the tools that don't support identity standards like SAML, SCIM, or OIDC and so can't be governed through a central identity provider.
Cerby's 2025 Identity Automation Gap Report, based on a survey of more than 500 US IT and security leaders, quantifies how wide that gap is:
-
Fewer than 4% of organizations have fully automated their core identity tasks. For the other 96%, execution still depends on manual, human-centric workflows.
-
89% do not automatically enforce MFA or passkeys, leaving enrollment up to individual users.
-
59% still provision access, offboard users, or both by hand, through ticketing systems or follow-up emails.
-
72% distribute user entitlement data manually or through flat files like Excel and CSV.
-
58% describe their identity approach as fragmented or highly fragmented.
-
58% say former employees have retained access to systems after leaving.
-
46% have already had a security, compliance, or operational issue caused directly by manual execution.
-
78% do not trust AI agents to perform core identity tasks autonomously, while 45% are open to a collaborative, human-in-the-loop approach.
The report closes with a five-question self-assessment IT and security teams can use to find their own last-mile automation gaps.
Read the full 2025 Identity Automation Gap Report
Download
To download the PDF, please click the button below.