Identity & Access Management
Identity and access management (IAM) controls how people, devices, workloads, and services prove who they are and what they may do. Strong IAM reduces friction for legitimate users while limiting the reach of mistakes and compromised accounts.
TL;DR
- Identity answers who or what; authorization answers what may it do.
- Joiner, mover, and leaver workflows are core security controls.
- Centralize authentication with SSO and strengthen it with MFA.
- Prefer roles and policy to one-off permissions.
- Protect privileged and non-human identities more strictly than ordinary accounts.
Learning Tracks
Identity Lifecycle
Cover authoritative sources, provisioning, role changes, suspension, deprovisioning, account recovery, and periodic access certification.
Authentication & Federation
Learn passwords, passkeys, MFA, session management, SAML, OpenID Connect, and federation boundaries. See WebAuthn and OAuth.
Authorization
Compare role-, attribute-, and policy-based access models. Design for least privilege, separation of duties, explicit ownership, and time-limited elevation.
Privileged & Workload Access
Manage administrators, break-glass accounts, service accounts, API credentials, secrets, certificates, and machine identities. Continue with Secrets Management.
Start Here
- Identify the authoritative source for workforce identities.
- Map high-risk applications and privileged roles.
- Automate account creation, role change, and termination.
- Require phishing-resistant authentication where impact is highest.
- Review privileged, stale, and non-human accounts on a schedule.
Control Model
An identity architecture typically includes an authoritative source, identity provider, provisioning engine, application directories, policy decision points, privileged-access controls, and audit logs. Tie birthright access to stable attributes, sensitive access to approval and review, and exceptional elevation to a short-lived, recorded workflow.
Useful Measures & Pitfalls
Track provisioning and termination time, MFA and phishing-resistant coverage, dormant accounts, orphaned access, privileged-role age, review completion, and failed deprovisioning. Watch for role explosion, shared accounts, long-lived service credentials, shadow directories, and access reviews that ask approvers to certify permissions they cannot interpret.
Featured Topics
Authentication
- Authentication Strategies — Sessions, tokens, and passwordless login
- Password Security — Hashing, policies, breach checks, and recovery
- Multi-Factor Authentication (MFA) — Second factors and phishing resistance
- Passkeys & WebAuthn — Phishing-resistant, passwordless credentials
Federation & Tokens
- Single Sign-On (SSO) — SAML, OIDC, and enterprise federation
- OAuth 2.0 & OpenID Connect — Delegated authorization and identity
- JSON Web Tokens (JWT) — Stateless tokens, claims, and validation
Identity Governance
- Identity Lifecycle Management — Joiner, mover, and leaver workflows
- Privileged Access Management — Protecting high-impact human and workload access
Which Mechanism for Which Job
Related Hubs
- Application Security — Vulnerabilities and defenses around identity
- Systems Administration & Infrastructure — Directory services and server access
- Enterprise Technology — SaaS portfolios that IAM must govern
- IT Operations — Endpoint and service desk processes that touch identity
- Compliance & Privacy — Access reviews and audit evidence