Identity and Access Management Foundations: From Sign-In to Accountable Access
About this course
This intermediate course teaches security practitioners, IT administrators, application owners, and technical managers how to make access decisions that are both secure and usable. Rather than treating identity as a sign-in screen, learners follow the entire access lifecycle: establishing an accountable identity, verifying an authenticator, evaluating authorization, managing federated trust, limiting session risk, protecting administrative access, and reviewing whether access remains justified.
The course uses vendor-neutral patterns and realistic decision points. It does not prescribe a particular identity platform. By the end, learners can map an access path, identify its weak trust assumptions, select proportionate controls, and assemble an improvement plan with clear owners, evidence, and review points.
What you'll learn
- ✓ Map an end-to-end access path and distinguish identity proofing, authentication, authorization, session management, and governance responsibilities.
- ✓ Select authentication and authorization controls that fit an asset's impact, user population, operational constraints, and credible threats.
- ✓ Explain how federation, tokens, sessions, and recovery flows create trust dependencies that require explicit safeguards.
- ✓ Produce a prioritized access-improvement plan with accountable owners, measurable evidence, and a review cadence.
Before you begin
You will get more from this course if these foundations are already familiar.
- Basic cybersecurity concepts — Learners should understand accounts, networks, applications, common threats, and the difference between confidentiality, integrity, and availability.
Course content
Module 1: 1. Establishing Identity and Trust
Build the vocabulary and lifecycle model needed to reason about who receives access, what is being verified, and how authentication choices change account-takeover risk.
Accountable Identities and the Access Lifecycle
Learn why an account must have an owner, a purpose, a lifecycle, and a revocation path before it can be trusted.
Authentication, Assurance, and Phishing Resistance
Compare authenticator choices by what they prove, how attackers target them, and what recovery can undo.
Module 2: 2. Making and Delegating Access Decisions
Learn how applications should decide what an authenticated identity may do, and how federation extends that decision across trust boundaries.
Authorization, Least Privilege, and Policy Design
Translate business permissions into explicit decisions about who can perform which action on which resource under which conditions.
Federation, OAuth, and Delegated Trust
Understand how an application relies on an identity provider and how tokens, redirect flows, scopes, and validation rules shape that trust.
Module 3: 3. Containing Sessions and Privilege
Focus on the trust that continues after sign-in: session boundaries, recovery, administration, elevation, and emergency access.
Sessions, Tokens, and Continuous Access Decisions
Treat an authenticated session as time-bounded authority that must be protected, limited, observed, and revoked when risk changes.
Privileged Access, Elevation, and Emergency Paths
Protect the identities that can change security controls, administer platforms, approve high-impact actions, or access broad datasets.
Module 4: 4. Governing Access and Improving It
Turn identity and access design into an operating practice through reviews, evidence, monitoring, and a prioritized improvement plan.
Access Reviews, Evidence, and Detection
Keep access justified over time by reviewing meaningful entitlements, recording evidence, and monitoring the events that change trust.
Build a Risk-Based Identity Improvement Plan
Synthesize the course by turning an access-path assessment into a sequenced plan with owners, evidence, dependencies, and success measures.