Identity & Access Management

Identity and access management (IAM) controls how people, devices, workloads, and services prove who they are and what they may do. Strong IAM reduces friction for legitimate users while limiting the reach of mistakes and compromised accounts.

TL;DR

Learning Tracks

Identity Lifecycle

Cover authoritative sources, provisioning, role changes, suspension, deprovisioning, account recovery, and periodic access certification.

Authentication & Federation

Learn passwords, passkeys, MFA, session management, SAML, OpenID Connect, and federation boundaries. See WebAuthn and OAuth.

Authorization

Compare role-, attribute-, and policy-based access models. Design for least privilege, separation of duties, explicit ownership, and time-limited elevation.

Privileged & Workload Access

Manage administrators, break-glass accounts, service accounts, API credentials, secrets, certificates, and machine identities. Continue with Secrets Management.

Start Here

  1. Identify the authoritative source for workforce identities.
  2. Map high-risk applications and privileged roles.
  3. Automate account creation, role change, and termination.
  4. Require phishing-resistant authentication where impact is highest.
  5. Review privileged, stale, and non-human accounts on a schedule.

Control Model

An identity architecture typically includes an authoritative source, identity provider, provisioning engine, application directories, policy decision points, privileged-access controls, and audit logs. Tie birthright access to stable attributes, sensitive access to approval and review, and exceptional elevation to a short-lived, recorded workflow.

Useful Measures & Pitfalls

Track provisioning and termination time, MFA and phishing-resistant coverage, dormant accounts, orphaned access, privileged-role age, review completion, and failed deprovisioning. Watch for role explosion, shared accounts, long-lived service credentials, shadow directories, and access reviews that ask approvers to certify permissions they cannot interpret.

Featured Topics

Authentication

Federation & Tokens

Identity Governance

Which Mechanism for Which Job

Related Hubs

References