
Identity and Access Management (IAM) Introduction Video
In this video you will learn about domain 1 (IAAA) topics and objectives.
In this video you will learn about the fundamental security principles or CIA triad.
You will learn Identification, Authentication, Authorization and Accounting.
In this video you will learn about important security concepts like job rotation, least privileges, and separation of duty.
Kerberos is one of the most widely used authentication and authorization protocols. In this video, you will learn about Kerberos components and operation.
Identity federation is used to allow users utilize the same credentials across multiple platforms. In this video you will learn about federation and how it works.
Discover WS-Fed, a web services federation protocol similar to SAML with enhanced security, and OAuth, enabling apps to access data without passwords.
Strong authentication is a fundamental to security. You will learn about authentication factors and how you can design a secure authentication platform.
Biometrics can be used as a very strong authentication and verification mechanism. In this video you will learn about different type of biometrics.
Build a lab environment with a Windows server and Windows 10 workstation on the same network, configure a static IP and DNS, and set up Active Directory domain services for cyber.local.
Note - I am not providing the details about how to install Windows and AD or join a pc to domain, as those information are not part of this course. There are lots of Youtube videos that can help with that if you have not done it before.
Note - You do not have to build the lab. This is optional. You can watch the videos to understand the operation.
Steps to build the lab:
Download and install a Windows 10 and Windows server (2016/2019), on Virtual box.
Make sure they are both on the same network, and can ping each other.
Install Active directory roles on the Window server using server manager. You can name the domain "IAM.Local".
Join Windows 10 to the domain (IAM.Local)
Install remote administration tool on your Windows 10 machine.
Customize your goals in Okta to guide the integration path for developers and admins, then add applications, enable single sign-on and provisioning, and monitor security in the dashboard.
Enable self-service in Okta by letting users request apps like Zendesk, optionally with approvals, and publish these apps to the service catalog for portal access.
Secure privileged sessions with certificate-based verification and encryption to prevent hijacking and man-in-the-middle attacks, while logging, monitoring, auditing, and alerting on privileged activity for compliant incident response.
Explores privileged access management solutions, outlining credential storage with strong encryption, multi-factor authentication, secure session management, auditing, anomaly monitoring, and reporting to minimize malicious use of privileged accounts.
Apply application whitelisting as a top essential control identified by the Australian Signals Directorate to prevent malicious code execution. On Windows, SRP and Applocker enforce which programs may run.
learn how to rename the windows default administrator account to iamadmin and enable auditing for privileged activities, then review event viewer logs to monitor privileged changes.
Information Security Access Controls, Centralized, Decentralized, and Role based access controls
Develop and sustain identity governance through ongoing monthly access validation and certification, reviewing and adjusting user permissions to ensure the right access and remove excessive privileges.
Develop and manage identity lifecycles with ILM, from onboarding and provisioning to access maintenance and termination. Leverage self-service, password and biometrics maintenance, and audit-ready security, compliance, and governance.
Practice configuring an IIS web server on Windows 10 to manage identities by enabling basic authentication, disabling anonymous access, denying a specific user, and testing connectivity to localhost.
Learn how a manager reviews employee access in the identity and access management system, including entitlements, master data, risk scores, passcode self-service, and attestations.
Use the self-service portal to request access to apps or hardware from a configurable service catalog, and route approvals through compliance rules and a manager.
Configure the service catalog in the one identity manager, create a marketing read-only Active Directory group, and add it to the IT shop to enable access requests.
Protecting intellectual property drives success for innovator companies, and this lecture maps trademarks, trade secrets, licensing, patents, and copyrights, with WIPO protecting patents and trademarks.
identify notifiable data breaches in australia by recognizing incidents involving personal data where unauthorized access or disclosure could cause serious harm, triggering reporting under the ndb scheme.
Learn to manage data access and permissions in a Windows environment by creating C drive folders, assigning group-based security settings, and testing access for finance, HR, IT, and public data.
Grant the IT group read and execute access across folders and deny write access; verify with an IT login that read is allowed in public, HR, and finance.
Create a lab with a Windows 11 client and a Server 2019 controller to install and test ManageEngine AD Audit Plus for auditing Active Directory and file access in lab.local.
Connect to ADAudit Plus remotely, monitor active directory and authentication events, and review user log on activity and failures through comprehensive reports, supporting identity governance and brute force detection.
Explore monitoring active directory and file activity with ManageEngine ADAudit Plus, configure file integrity monitoring on domain controllers, and use analytics and alerts to detect login and access events.
OpenIAM installation can be challenging if you don't use the right version of OS or software, or miss one of the steps. I suggest you read the materials carefully and follow the steps, and use the right version of OS. You might give this a coupe of tries, using CentOS or Ubuntu, don't get disappointed if one doesn't work for you, try the other one.
https://docs.openiam.com/docs-4.2.1.2/installation/2-docker-installation
Install OpenIAM on a CentOS server using Docker and Docker Compose, with swarm, Bitbucket community edition, environment file and port configurations.
Install and initiate open IAM with Docker on Linux, verify containers, then access the web console, create the default content provider, and enable http or https.
Learn how IAM connectors and managed systems enable provisioning to external systems like LDAP and Active Directory, configure connectors, and set up provisioning and deprovisioning workflows.
Explore the reporting functionality in identity and access management with open IAM, generating and emailing out-of-the-box and custom reports on users, entitlements, access requests, and last login.
Discover how to obtain a 30-day trial of the PingOne identity platform by registering with a business email, selecting a data center, and creating your initial environment.
Enable seamless Active Directory integration with PingOne by creating a gateway and provisioning connections, synchronizing AD users, and mapping AD attributes to enrich user metadata on the PingOne identity platform.
Learn to integrate applications with the PingOne platform using SAML SSO. Create a custom app, import metadata, enable it, and map attributes like user id, email, and last name.
Learn how to integrate Zendesk with PingOne using the application catalog, configure saml settings, certificate fingerprint, and external authentication to enable single sign-on for Zendesk users.
Configure the Ping Identity environment to manage the directory, create users, groups, and populations, and define attributes and roles for secure access.
Join identity and access management training, celebrate your progress, and stay secure; share a review or feedback to help others and improve the course.
Identity and Access Management is a fundamental and critical cybersecurity capability, to ensure the right people and things have the right access to the right resources at the right time.
In this course, you will learn about different components of Identity and Access Management, security considerations and some labs and examples.