
Brief agenda of the training session
Explore the course introduction outlining the structure, simple definitions, and concrete examples. Engage in labs with identity and access governance solutions and take notes, ask questions, and share topics.
Meet your instructor, Geoffroy Andrieu, an expert in identity and access management with over ten years of cybersecurity experience, and begin the introduction to identity and access management.
Short definition and main differences between IAM and CIAM
IAM pillars and solutions
Example of a macro IAM architecture
Explore how identity and access governance blends business processes, information, and technology to manage digital identities and access rights. Integrate standard processes and native functionalities where possible.
Identify the main end users of an identity and access governance solution, including standard end users, managers, assistants, cybersecurity teams, application owners, and auditors.
Main stakeholders in IAG processes and implementation projects
IAG capabilities that support IAM processes
Main Identity management functionalities
Identity objectifs and characteristics
Explore SailPoint IdentityIQ to discover the identity model, including identities, attributes, roles, and rights, and examine how application accounts and authorizations define access in an IAM framework.
In SailPoint IIQ, identify identity types in the identity warehouse by authoritative source, distinguishing employees from contractors. Job title appears for employees; contractors may have empty attributes.
Learn to modify identity information via authoritative sources in SailPoint IIQ, using csv data, aggregation tasks, and optional edit mode to manage location and region attributes.
Explore the identity lifecycle from creation to deletion, covering states like active, deactivated, locked, disabled, and archiving, and how IAG solutions consolidate updates across IT systems.
Explore identity lifecycle examples, including contract expiration and extensions, 30-day deactivation delays, and advance notifications to anticipate extensions and keep identities active.
Identify how robust and effective unique identifiers in identity and access governance distinguish users, link authoritative source identifiers with logins, and support secure access via technical identifiers.
Identity certification verifies identity legitimacy in the information system and removes illegitimate accounts via an IAG solution, with compliance managers launching campaigns and deletions to reduce security risks.
Discover eight access rights management capabilities within identity and access governance. Learn to define access rights objects, manage roles, and apply entertainment aggregation, provisioning, and role mining.
Discover RBAC, the most widely used identity and access management model, where roles bundle permissions and provisioning grants access to target systems through a source, with access profiles.
Examine RBAC by modeling a senior data analyst with Splunk admin and Click user profiles, plus VPN and Notepad Plus Plus access, and discuss the model's advantages and trade-offs.
Examine how access rights are modeled within an identity and access governance solution, linking a digital identity to rights that create Windows accounts and grant access to services.
Explain attribute based access control (abac), where login-time rules use identity, environment, and resource attributes to grant rights in applications like Splunk and Workday, highlighting scalability and centralization challenges.
Compare RBAC, ABAC, and RBAC-A in IAG solutions, showing how dynamic rules and centralized management assign roles and access profiles to users based on job titles and attributes.
Define and manage roles through their life cycle with unique names and descriptions, owner oversight, mandatory and optional access profiles, criticality levels, approval workflows, authorized populations, and separation of duties.
Explore top-down and data-driven role composition in identity and access management, and the life cycle from creation to decommissioning.
Explore how to raise access requests for resources, specify permissions, navigate validation workflows with managers, assistants, or colleagues, and manage approvals, start and end dates, and temporary or permanent rights.
Explore SailPoint IIQ lab on application configuration and request workflows in identity and access management, adding a new entertainment, 'reporting', to the time tracking app and processing manager approvals.
Create an automatic role assignment using identity attributes to grant the time tracking reporting capability to executive management, and automatically revoke it when they move to a different department.
Explore role mining within identity and access governance to identify permission patterns, group users into roles, and simplify onboarding through automated provisioning.
Explore SailPoint IIQ role mining to build and activate roles from grouped entitlements, using role mining campaigns across selected applications, and validate ownership through identity cube refresh.
Learn to manage access certification by reviewing permissions and privileges, with managers or application owners certifying access, prioritizing critical rights and scheduling campaigns aligned with role changes.
Learn to configure and run a SailPoint IIQ access certification campaign, including identity selection, scope filtering, certifier roles, scheduling, and manager-based approvals.
In today's interconnected world, safeguarding sensitive data and ensuring proper access control are paramount. That is why Identity and Access Management (IAM) has become the primary cornerstone of enterprise cybersecurity.
Enhance your cybersecurity knowledge by mastering the fundamentals of the IAM's most crucial and complex area: Identity and Access Governance (IAG), also called Identity Governance and Administration (IGA).
This comprehensive course delves deep into the vital realm of Identity and Access Governance (IAG). Explore the essentials of IAM and IAG, covering both organizational and technical aspects. Discover why this field of cybersecurity encompasses not only cybersecurity challenges but also user experience concepts.
Acquire expertise in the main capabilities of IAG solutions: identity classification and lifecycle management, integration with authoritative sources, access rights management and modeling (RBAC, ABAC...), access certification, segregation of duties, and more.
Immerse yourself in hands-on labs featuring SailPoint IIQ, the market-leading solution for IAG. Visualize and solidify your understanding of the theoretical concepts discussed in the course through immersive lab experiences. Concrete examples will be provided to enhance comprehension, ensuring a practical grasp of the material to finally gain practical experience through real-world scenarios and challenges faced by organizations.
Equip yourself with the knowledge and skills needed to navigate the complex realm of Identity and Access Governance confidently. Prepare for a rewarding career in securing digital identities and protecting valuable assets from cyber threats.