
Identity and Access Management (IAM) Introduction Video
In this video you will learn about domain 1 (IAAA) topics and objectives.
In this video you will learn about the fundamental security principles or CIA triad.
You will learn Identification, Authentication, Authorization and Accounting.
In this video you will learn about important security concepts like job rotation, least privileges, and separation of duty.
Kerberos is one of the most widely used authentication and authorization protocols. In this video, you will learn about Kerberos components and operation.
Identity federation is used to allow users utilize the same credentials across multiple platforms. In this video you will learn about federation and how it works.
Discover WS-Fed, a web services federation protocol similar to SAML with enhanced security, and OAuth, enabling apps to access data without passwords.
Strong authentication is a fundamental to security. You will learn about authentication factors and how you can design a secure authentication platform.
Biometrics can be used as a very strong authentication and verification mechanism. In this video you will learn about different type of biometrics.
Build a lab environment with a Windows server and Windows 10 workstation on the same network, configure a static IP and DNS, and set up Active Directory domain services for cyber.local.
Note - I am not providing the details about how to install Windows and AD or join a pc to domain, as those information are not part of this course. There are lots of Youtube videos that can help with that if you have not done it before.
Note - You do not have to build the lab. This is optional. You can watch the videos to understand the operation.
Steps to build the lab:
Download and install a Windows 10 and Windows server (2016/2019), on Virtual box.
Make sure they are both on the same network, and can ping each other.
Install Active directory roles on the Window server using server manager. You can name the domain "IAM.Local".
Join Windows 10 to the domain (IAM.Local)
Install remote administration tool on your Windows 10 machine.
Create a standard user in the IAM lab, add them to the local remote desktop users group on Windows 10, then log in to compare admin versus standard permissions.
Customize your goals in Okta to guide the integration path for developers and admins, then add applications, enable single sign-on and provisioning, and monitor security in the dashboard.
Create and manage users and groups in the directory, assign them to applications, and review configuration. Integrate Active Directory with Okta to synchronize identities and control access to apps.
Configure a custom domain, branding, and sign-in experiences in Okta, including logos, images, fonts, and tailored email and text templates for organization-wide identity and access management.
Integrate external applications with Okta as the identity provider by browsing the app catalog, selecting apps such as Zendesk, configuring SSO, provisioning, and lifecycle management where available.
Create a web application in Okta, select authentication such as OpenID Connect or SAML, obtain the SDK, and configure tokens and client IDs for your custom app.
Enable self-service in Okta by letting users request apps like Zendesk, optionally with approvals, and publish these apps to the service catalog for portal access.
Review and strengthen your Okta identity platform by configuring captcha, notifications, health insights, and anomaly detection; enable multi-factor authentication and tailor authentication policies for applications.
Explore Okta system logs and reporting to track activity, changes, and logins, integrate with central logging and email reports to admins for auditing.
Master privileged account and session management by using password managers, enforcing unique accounts, encrypting credentials, and monitoring sessions to defend against man-in-the-middle attacks.
Secure privileged sessions with certificate-based verification and encryption to prevent hijacking and man-in-the-middle attacks, while logging, monitoring, auditing, and alerting on privileged activity for compliant incident response.
Explores privileged access management solutions, outlining credential storage with strong encryption, multi-factor authentication, secure session management, auditing, anomaly monitoring, and reporting to minimize malicious use of privileged accounts.
Apply application whitelisting as a top essential control identified by the Australian Signals Directorate to prevent malicious code execution. On Windows, SRP and Applocker enforce which programs may run.
learn how to rename the windows default administrator account to iamadmin and enable auditing for privileged activities, then review event viewer logs to monitor privileged changes.
Discover identity governance and administration in IAM, covering onboarding, termination, access requests, role changes, role-based controls, certifications, segregation of duties, audits, lifecycle management, with Windows Active Directory audit demos.
Learn how to terminate user accounts promptly, revoke access to all systems, and collect assets when a contract ends, while managing role changes to prevent permission inheritance.
Information Security Access Controls, Centralized, Decentralized, and Role based access controls
Develop and sustain identity governance through ongoing monthly access validation and certification, reviewing and adjusting user permissions to ensure the right access and remove excessive privileges.
Explore segregation of duties as a governance and security control to prevent fraud, with auditing and reporting requirements, tamperproof access logs, and compliance under SOX and ASX.
Develop and manage identity lifecycles with ILM, from onboarding and provisioning to access maintenance and termination. Leverage self-service, password and biometrics maintenance, and audit-ready security, compliance, and governance.
Practice configuring an IIS web server on Windows 10 to manage identities by enabling basic authentication, disabling anonymous access, denying a specific user, and testing connectivity to localhost.
Explore One Identity Manager's virtual lab for identity and access governance and administration, showing automated provisioning, HRM integration, and Active Directory workflow in a ready-made test environment.
Learn how a manager reviews employee access in the identity and access management system, including entitlements, master data, risk scores, passcode self-service, and attestations.
Use the self-service portal to request access to apps or hardware from a configurable service catalog, and route approvals through compliance rules and a manager.
Configure the service catalog in the one identity manager, create a marketing read-only Active Directory group, and add it to the IT shop to enable access requests.
Sandra, the owner of business and system rules, uses role owners web access to view and update rules, manage entitlements and membership, and request Active Directory groups and system roles.
Explore data types and the value of sensitive information for different organizations, including PII and PHI, financial data, intellectual property, and government sensitive data.
Protecting intellectual property drives success for innovator companies, and this lecture maps trademarks, trade secrets, licensing, patents, and copyrights, with WIPO protecting patents and trademarks.
Identify and implement a structured incident response by preparing resources, detecting incidents, containing malware, remediating root causes, recovering operations, documenting lessons learned, and notifying authorities when data is lost.
identify notifiable data breaches in australia by recognizing incidents involving personal data where unauthorized access or disclosure could cause serious harm, triggering reporting under the ndb scheme.
Learn to manage data access and permissions in a Windows environment by creating C drive folders, assigning group-based security settings, and testing access for finance, HR, IT, and public data.
Grant the IT group read and execute access across folders and deny write access; verify with an IT login that read is allowed in public, HR, and finance.
Create a lab with a Windows 11 client and a Server 2019 controller to install and test ManageEngine AD Audit Plus for auditing Active Directory and file access in lab.local.
Install and configure ManageEngine AD Audit Plus on a Windows Server domain controller to monitor file access and permissions across DataSec folders in Lab.Local.
Connect to ADAudit Plus remotely, monitor active directory and authentication events, and review user log on activity and failures through comprehensive reports, supporting identity governance and brute force detection.
Track AD users and groups changes with ADAudit Plus, including creation, modification, and disablement, in detailed reports. Monitor administrator activity and alerts to detect suspicious access events.
Monitor Active Directory activity with ADAudit Plus, including OU creation, GPO monitoring, and policy changes, with visibility into recently created OUs, computers, and GPO setting changes.
Explore monitoring active directory and file activity with ManageEngine ADAudit Plus, configure file integrity monitoring on domain controllers, and use analytics and alerts to detect login and access events.
Explore Open IAM, an open source identity governance and administration platform with identity store, authentication manager, policy engine, and access manager, enabling lifecycle, RBAC, self-service, and compliant access.
Discover the OpenIAM community edition, a free open source entry point with features like identity lifecycle management and access controls; the commercial edition adds enterprise grade integrations and dedicated support.
OpenIAM installation can be challenging if you don't use the right version of OS or software, or miss one of the steps. I suggest you read the materials carefully and follow the steps, and use the right version of OS. You might give this a coupe of tries, using CentOS or Ubuntu, don't get disappointed if one doesn't work for you, try the other one.
https://docs.openiam.com/docs-4.2.1.2/installation/2-docker-installation
Install OpenIAM on a CentOS server using Docker and Docker Compose, with swarm, Bitbucket community edition, environment file and port configurations.
Learn how to initialize Open IAM after Docker installation, configure SELinux to permissive, open required ports (8080, 443, 5432, 9200, 9092, 6379), and start the Open IAM startup process.
Install and initiate open IAM with Docker on Linux, verify containers, then access the web console, create the default content provider, and enable http or https.
Integrate open IAM with an smtp relay to enable emails for onboarding, offboarding, and certification campaigns. Configure mailbox templates like SendGrid, test the connection, and verify delivery.
Open IAM centers identity governance, provisioning and deprovisioning users and groups across directories and applications, enabling source-of-truth governance and access review campaigns.
Discover how to define and manage access with resources, organizations, roles, and groups in Open IAM, enabling granular provisioning and policy-based access for services, databases, and data objects.
Link resources, groups, roles, and organizations to individual users to assign entitlements and establish supervisor hierarchies, then test with multiple users to enforce access controls.
Learn how IAM connectors and managed systems enable provisioning to external systems like LDAP and Active Directory, configure connectors, and set up provisioning and deprovisioning workflows.
Explore the AD managed system template in identity and access management, using Open IAM's standard templates, default connectors, and policy mappings to provision accounts to Active Directory.
Learn how authentication providers link external services with IAM, configure app ID and secret for Google or other providers, and manage these links via access control and content providers.
Explore identity and access management by defining and provisioning access rights for the ADP application, including admin and user roles, through requests, approvals, and automated provisioning.
Discover how open IAM's synchronization automates bidirectional attribute updates with Active Directory, SAP, Workday, Salesforce, and other apps, enabling seamless onboarding and offboarding.
Explore the reporting functionality in identity and access management with open IAM, generating and emailing out-of-the-box and custom reports on users, entitlements, access requests, and last login.
Explore Ping identity and the PingOne cloud platform to manage digital identities and access across apps, featuring user provisioning, identity federation, customizable workflows, and single sign-on with multi-factor authentication.
Discover how to obtain a 30-day trial of the PingOne identity platform by registering with a business email, selecting a data center, and creating your initial environment.
Manage administrators and access in identity and access management via the administrator section, and use the environment to set dev, test, prod configurations with policies and app integrations.
Learn to integrate PingOne with Active Directory using an LDAP gateway, including environment setup, directory selection, hostname and credentials, and preparing the gateway for installation.
Deploy a gateway, connect LDAP to PingOne, and verify the integration is running. Create a connection and a provisioning rule, map AD attributes to PingOne, and enable synchronization.
Enable seamless Active Directory integration with PingOne by creating a gateway and provisioning connections, synchronizing AD users, and mapping AD attributes to enrich user metadata on the PingOne identity platform.
Learn to integrate applications with the PingOne platform using SAML SSO. Create a custom app, import metadata, enable it, and map attributes like user id, email, and last name.
Learn how to integrate Zendesk with PingOne using the application catalog, configure saml settings, certificate fingerprint, and external authentication to enable single sign-on for Zendesk users.
Configure the Ping Identity environment to manage the directory, create users, groups, and populations, and define attributes and roles for secure access.
Implement threat protection with risk based authentication on the ping one platform, using predictors and risk scores to enforce multi-factor authentication when risk thresholds exceed.
Join identity and access management training, celebrate your progress, and stay secure; share a review or feedback to help others and improve the course.
Identity and Access Management is a fundamental and critical cybersecurity capability, to ensure the right people and things have the right access to the right resources at the right time.
In this course, you will learn about different components of Identity and Access Management, security considerations and some labs and examples.