
Identify who you are and what you can access with identity and access management. IAM automates creating, updating, and deactivating user access to protect resources and ensure compliance.
Explore the triple a of identity and access management—authentication, authorization, and accounting—clarifying the difference between authentication and authorization and introducing accounting with monitoring and auditing within the zero trust model.
Explore zero trust, a security framework that never trusts and always verifies every user, device, and application, using strong authentication, least privilege, and constant monitoring to minimize attack surfaces.
Apply the principle of least privilege within the Zero Trust framework, showing how Jane's access shifts from teller to loan officer, revoking old rights and granting only what she needs.
Continuously monitor and audit systems to detect insider threats and slow attacks, tracking every session and action to flag unusual hours, locations, and access and prevent breaches.
Track identity lifecycle management from joiners to movers and leavers, showing how aggregation creates a digital birth and how access rights are granted, adjusted, and revoked.
Explore authentication methods, including knowledge-based, possession-based, and biometric factors, and learn how secondary factors like location and behavior strengthen identity verification.
Explore MFA and 2FA, using something you know, something you have, and OTP checks to reduce unauthorized access and protect data, while GPS location and IP address checks provide safeguards.
Dynamic MFA adapts factors to login risk, balancing security and convenience. Normally a password and OTP suffice; high-risk logins trigger extra verifications like push notifications, security questions, or location checks.
Master single sign on to access multiple applications with one login. SSO uses a central authentication server to generate authentication token shared with apps via Saml, AU, or OpenID connect.
Compare customer identity and access management with workforce identity to show external user focus, self-service and privacy versus internal security, single sign on, multi-factor authentication, and lifecycle management.
Explore rbac and abac: role-based access control and attribute-based access control illustrated by a new hire's birthright access and attribute-driven permissions, with a comparison of their strengths and weaknesses.
Policy based access management enforces dynamic access using predefined rules on location, ip address, time, and device.
Empower resource owners with discretionary access management (DAC) to decide who can access files and folders. Grant or restrict read and write rights for individual users.
In mandatory access management, system level security policies enforce label-based access with clearance levels; for Muhammad, a confidential clearance allows access to A and B but not C.
Define and manage roles and entitlements using RBAC and ABAC, apply identity lifecycle management to maintain least privilege, and map entitlements to business functions with role hierarchies.
Explore how access request systems like Ares manage birthright access and on-demand approvals through a manager and application owner workflow, with automatic provisioning through the identity system.
Explore five approval workflows, including delegated approver, default approver, serial approval, series approval, parallel approval, and escalation after time out, to route access requests efficiently.
Apply segregation of duties to prevent toxic combinations of entitlements, analyze roles, establish SOD rules, and enforce checks in IAM systems with monitoring and temporary access when justified.
Explore policies and compliance in identity and access management through governance, risk, and compliance (GRC), and learn how insider threats and unauthorized access combinations drive proactive risk protection.
Identity governance defines and enforces policies to control access to data, applications, and resources, protecting information and reducing risk through RBAC, ABAC, and segregation of duties.
Learn how compliance enforces governance through auditing, reporting, and continuous monitoring, and how frameworks like GDPR, HIPAA, PCI DSS, and NIST guide IAM to reduce non-compliance risk.
Introduce certifications within identity and access management and explain how periodic access rights checks enforce least privilege, revoke unused permissions, and support governance, audit readiness, and regulatory compliance.
Discover how certification campaigns assign owners to review access across teams, applications, roles, and high risk entitlements, ensuring appropriate permissions and removing unnecessary privileges.
Launch periodic certification campaigns that vary by risk level, with monthly reviews for high-risk roles, quarterly checks for sensitive apps, and annual reviews for low-risk entitlements.
Manage proactive IAM through regular certifications to remove outdated permissions, reduce attack surfaces, and boost security, efficiency, and compliance with GDPR, HIPAA, PCI DSS, and NIST.
Explore SaaS IAM connectors and how HR data from CSV or SQL feeds the IAM hub, provisions directory accounts, and extends access to devices and apps via REST APIs.
Explore moving to the cloud with hybrid IAM setups, bridging on-premises assets with a cloud-based solution through a specialized connector to maintain visibility and control across environments.
Explore SailPoint and Saviynt SaaS connectors, virtual appliance, and SC 2.0, enabling secure, outbound-only hybrid IAM links between cloud IAM and on-prem resources like Active Directory and databases.
Step into the world of Identity & Access Management (IAM) and learn how it protects modern organizations from security threats. Whether you’re an IT professional looking to specialize in IAM, a beginner exploring cybersecurity, or someone transitioning into identity management, this vendor-neutral course will give you the skills you need to succeed.
You’ll gain a clear, practical understanding of IAM fundamentals, including identity lifecycle management, access controls, authentication methods, Single Sign-On (SSO), Multi-Factor Authentication (MFA), and governance policies. Learn how organizations use IAM solutions like SailPoint, Okta, and Saviynt to secure user access, prevent breaches, and ensure regulatory compliance across industries.
This course takes a vendor-neutral approach, ensuring you understand IAM concepts that apply across various platforms and environments. However, we also include a dedicated lecture comparing leading IAM tools, giving you insight into their differences and helping you choose the right solution for different business needs.
Through real-world scenarios, you’ll see IAM in action, learning how businesses protect sensitive data, enforce security policies, automate user provisioning, and implement role-based access control (RBAC) effectively. You’ll also explore emerging trends in IAM, such as Zero Trust security and cloud-based identity solutions, making you industry-ready.
By the end of this course, you’ll have a strong foundation in IAM concepts, allowing you to understand identity security, enforce access controls, and navigate IAM tools used in modern IT environments. Whether you're aiming to transition into IAM or strengthen your cybersecurity skills, this course will give you the knowledge and confidence to take the next step in your career.