Opens in a new tab
vmblog logo 2024 wht (updated)

Lastwall 2026 Predictions: Identity and Access Management at the Edge – What Comes Next for Digital Security

Share: 

David Marshall | Published: December 12, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Shawn Moorhead, Vice President of Sales, Lastwall 

As organizations reflect on another year of rapidly accelerating digital transformation, it’s clear that identity remains the defining security control of the modern enterprise. Every IT modernization initiative and Zero Trust Architecture plan starts at the user (identity) layer, before covering networks, devices, or applications. Yet the predictions many of us made in 2024 and 2025, from decentralized identity to adaptive authentication, still haven’t reached mainstream adoption. That doesn’t mean the predictions were wrong; rather, the supporting infrastructure, regulatory frameworks, and operational realities needed more time than expected. In 2026, the pressure to secure distributed workforces, critical infrastructure, cloud resources, and emerging edge environments will fundamentally reshape how identity systems are built and deployed. The result will be a year that pushes identity security into new operational domains and elevates identity architectures to the center of Zero Trust strategies across government and industry. 

1. Decentralized and User-Controlled Identity Moves from Concept to Early Adoption 

Decentralized identity systems, sometimes referred to as Self-Sovereign Identity (SSI), decentralized identifiers (DIDs), or verifiable credentials, have been “the future” for years. In 2026, I predict that they will shift from speculative conversation to structured adoption. Not widespread adoption, but early, meaningful adoption in controlled environments. 

Regulated industries such as finance, healthcare, and critical infrastructure will begin deploying pilot programs that empower users to store and manage identity attributes within secure digital wallets rather than in large centralized repositories. The motivators will include value propositions like reducing compliance burdens, limiting concentrated data risk, and increasing user privacy. Early deployments will likely involve high-value workflows such as patient identity verification, remote workforce onboarding, and secure cross-organization collaboration, where minimizing sensitive data exposure offers immediate benefit. 

Challenges will remain significant, especially those related to user experience, interoperability standards, and education/behavior. However, the shift toward user-controlled, portable identity will press on and adapt. Organizations that treat decentralized identity as an evolutionary path, not a wholesale replacement, will be best positioned to capture the benefits without destabilizing existing systems. 

2. AI-Driven Adaptive Authentication Enters Its “Second Wave” 

Adaptive authentication has existed for years, with identity providers using contextual signals such as device, location, and behavior to adjust authentication requirements. But the explosion of AI technologies and machine learning capabilities is ushering in a second wave of sophistication. 

In 2026, adaptive authentication systems will expand beyond risk scoring based on isolated signals. Instead, they will build behavioral baselines that continuously learn from user interactions across applications, devices, and environments. Rather than challenging users based on simple anomalies, AI systems will predictively identify subtle deviations that correlate with credential abuse, session hijacking, or synthetic identity activity. 

This does not mean blanket surveillance. Organizations will need to adopt transparent data usage policies and explicitly define what behavioral telemetry is collected and why. But privacy-respecting behavioral models using differential privacy, homomorphic encryption, and federated learning will make it possible to detect identity-based attacks earlier and with far fewer false positives. 

The result will be authentication systems that feel more seamless to legitimate users while becoming far more hostile to attackers and bots. 

3. Identity at the Edge: The Era of Disconnected and Intermittently Connected Environments 

In 2026, one of the most impactful shifts will be the emergence of identity systems capable of operating reliably in disconnected, degraded, intermittent, and limited (DDIL) environments. This is especially critical as organizations increasingly rely on mobile workforces, IoT deployments, operational technology, and distributed edge computing architectures. 

Traditional identity systems assume consistent, reliable connectivity with central directories or cloud-based identity providers. But in real-world environments such as those on manufacturing floors, remote field operations, critical infrastructure facilities, defense missions, and emergency response situations, connectivity is essential and anything but guaranteed. 

The next generation of identity platforms will: 

  • Perform strong authentication locally, without requiring constant connectivity
  • Enforce policy at the edge and sync securely with enterprise systems when connections restore
  • Cache cryptographic material, tokens, and permissions with strict expiration and tamper-resistant protections
  • Support local adjudication of access decisions based on pre-distributed policies
  • Enable secure identity operations even when cloud resources are unavailable 

Organizations deploying IoT, containerized workloads, service mesh architectures, or remote operational systems will increasingly prioritize identity technologies that function autonomously. This will mark a significant departure from identity’s historical dependence on real-time cloud connectivity. 

4. Zero Trust Matures Toward Identity-First Infrastructure Automation 

In 2026, Zero Trust continues its shift from abstract principle driven by policy requirement to practical implementation and operational value-add. The most important evolution will be the expansion of identity-first automation, or the idea that identity policies should be treated as code, version-controlled, continuously validated, and automatically enforced across distributed systems. 

Identity-as-Code will move beyond early adopters and begin reshaping how organizations manage privileges, enforce segmentation, and validate trust. Infrastructure teams will standardize identity controls the same way they standardize network configurations, Kubernetes manifests, or infrastructure-as-code templates. 

This will accelerate several related trends: 

  • Fine-grained, context-aware access rules bound to users, workloads, and devices
  • Automated rotation and issuance of credentials, certificates, and tokens
  • Identity-centric microsegmentation in virtualized, containerized, and edge environments
  • Unified policy engines capable of operating across cloud, data center, and hybrid architectures 

The most successful organizations will treat identity as an operational discipline, not just a security capability. 

Looking Ahead 

2026 will not be the year where every identity innovation becomes mainstream, but it will be the year that foundational shifts take hold. Decentralized identity will begin real deployments, AI-driven authentication will become dramatically more intelligent, and identity will finally extend into environments where connectivity cannot be assumed. As identity continues its evolution toward becoming the backbone of Zero Trust, organizations that modernize their identity architectures now will be best positioned to navigate the increasingly complex digital landscape of the years ahead. 

## 

ABOUT THE AUTHOR 

Shawn Moorhead 

Shawn Moorhead is the Vice President of Sales at Lastwall, where he leads the company’s efforts to deliver cutting-edge identity and access management solutions to US federal agencies, the Department of Defense, and critical infrastructure organizations. With deep experience bridging emerging technologies and mission critical needs, Shawn helps ensure that Lastwall’s platform aligns with the operational realities and defensive cybersecurity requirements of government and defense environments. 

Prior to joining Lastwall, Shawn worked closely with over 100 early-stage startups, guiding them through growth, fundraising, and strategic partnerships-often within highly regulated sectors. His past roles have included building a global partner program to connect innovative technologies with infrastructure and defense partners, raising investment funds, and advising public and private stakeholders on innovation adoption. Shawn’s work has consistently focused on enabling secure, scalable solutions that meet the complex challenges facing government and national security sectors.