How come more Fortune 100 enterprises aren demanding that their enterprise application vendors implement XACML?
Probably for the same reason why they are not demanding application vendors to accept SAML as additional token for authentication as opposed to proprietary implementation or always requires a db or ldap for authentication. With wide spread adoption of web access management/ Federation organizations are still customizing their COTS products to implement SSO. Its probably true organizations havent realized the painful in defining and implementing authorization policies across the enterprise. Hopefully the implementations by Oracle, Sun, BEA, etc would change this soon.