Auth0 World 2022 brought together identity security practitioners, architects, and vendors for two days of sessions, workshops, and discussions centered on the evolving state of authentication and authorization. The event drew over 400 attendees from across the identity and security ecosystem, with representation from enterprise IT, financial services, healthcare, government, and technology companies.
Here is a recap of the event highlights, keynote themes, standout sessions, and the key takeaways that shaped conversations throughout the conference.
Keynote Themes: Identity as the Primary Attack Surface
The opening keynote set the tone for the entire event with a straightforward assertion: identity has become the primary attack surface for enterprise security, and the industry is not keeping pace with the threat.
Data presented during the keynote reinforced this claim. Over 80% of breaches in 2021 and 2022 involved compromised credentials, misconfigured access controls, or identity-related vectors. Phishing attacks targeting authentication workflows increased 61% year-over-year. And the rise of adversary-in-the-middle (AiTM) attacks demonstrated that even MFA-protected accounts are vulnerable when the MFA mechanism is not phishing-resistant.
The keynote argued that the identity security problem is structural, not tactical. Organizations invested heavily in network security, endpoint protection, and SIEM over the past decade. Investment in identity security - beyond basic SSO and MFA - lagged behind. The result is an environment where attackers consistently find identity to be the easiest path into enterprise environments.
Top Sessions
The Machine Identity Problem was the most attended session of the conference. The presentation covered the 45:1 ratio of non-human to human identities in enterprise environments and the governance gap that ratio creates. Attendees reported that machine identity was the topic they discussed most in hallway conversations after the session.
Enterprise Passkey Deployment: Lessons from Early Adopters drew a standing-room audience. A panel of three organizations that had deployed passkeys in production shared their experiences, including adoption rates, user friction points, and the account recovery challenge that every deployment faces. The honest discussion of what did not work was as valuable as the success stories.
OAuth 2.0 Security BCP Deep Dive walked through the practical implications of BCP 212 for implementers. The speaker broke down each recommendation with code examples and migration strategies. This session generated the most post-event requests for slide decks.
Zero Trust Identity in Practice featured a case study from a Fortune 500 financial services company that had spent 18 months implementing identity-centric zero trust. The session covered their conditional access policy framework, their approach to just-in-time provisioning, and the organizational challenges they encountered when removing standing privileges from engineering teams.
Decentralized Identity: Promise and Reality offered a balanced assessment of verifiable credentials, decentralized identifiers, and the practical challenges of making decentralized identity work in enterprise environments. The speaker argued that decentralized identity will find its niche in specific use cases rather than replacing centralized identity providers entirely.
Attendee Demographics
The Auth0 World 2022 audience reflected the cross-functional nature of identity security.
- Identity architects and engineers made up 38% of attendees, the largest single group.
- Security professionals (CISOs, security engineers, analysts) accounted for 27%.
- IT operations and infrastructure represented 18%.
- Product managers and developers building identity-related features comprised 12%.
- Vendor representatives and analysts made up the remaining 5%.
Organizationally, attendees came from a mix of enterprise sizes. Approximately 45% worked at organizations with over 10,000 employees, 30% at mid-market companies (1,000 to 10,000), and 25% at smaller organizations or consultancies.
The geographic distribution was predominantly North American (68%), with European attendees representing 22% and the remaining 10% from Asia-Pacific, Latin America, and the Middle East.
Key Takeaways
Five themes emerged consistently across sessions, workshops, and informal discussions:
Identity security investment is catching up to its importance. Multiple attendees reported that their organizations had increased identity security budgets for 2023, driven by breach trends and board-level awareness. The gap between identity’s importance as an attack surface and the investment it receives is narrowing, though it has not closed.
Phishing-resistant authentication is no longer optional. The AiTM attack demonstrations and real-world breach examples made a convincing case that SMS and TOTP-based MFA are insufficient against sophisticated attackers. FIDO2 passkeys and hardware security keys are the direction of travel for organizations that take phishing seriously.
Machine identity governance is years behind human identity governance. The gap was a recurring theme. Organizations that have mature human identity programs - with lifecycle management, access reviews, and automated provisioning - often have no equivalent processes for service accounts, API keys, and certificates.
Zero trust is a journey with no clear finish line. Every session on zero trust acknowledged that full implementation across an enterprise application portfolio takes years. The practical advice was to start with high-value applications, measure progress with concrete metrics, and accept that zero trust is an ongoing program rather than a project with a completion date.
The identity vendor landscape is consolidating rapidly. Acquisitions and mergers throughout 2021 and 2022 reshaped the market. Attendees expressed both optimism (integrated platforms reduce complexity) and concern (vendor lock-in increases when fewer options exist).
Looking Ahead
Auth0 World 2022 captured an industry at an inflection point. Identity has moved from a back-office IT function to a primary security control, and the tools, practices, and organizational structures are still adapting to that shift. The conference provided a forum for practitioners to share what is working, what is not, and what comes next - which is exactly what this community needs as the stakes continue to rise.