Course

Identity and Access Management Foundations: From Sign-In to Accountable Access

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Intermediate
Modules 4
Lessons 8
Time 5 hr 25 min
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
A complete identity and access pathFive connected stages show identity, authentication, authorization, session control, and governance. IDENTITY AND ACCESS MANAGEMENTFrom sign-in to accountable access IDENTITYaccountable subjectVERIFYauthenticatorDECIDEleast privilegeSESSIONbounded trustGOVERNreview and evidence A sound sign-in is necessary, but it is only one decision in the access lifecycle.

About this course

This intermediate course teaches security practitioners, IT administrators, application owners, and technical managers how to make access decisions that are both secure and usable. Rather than treating identity as a sign-in screen, learners follow the entire access lifecycle: establishing an accountable identity, verifying an authenticator, evaluating authorization, managing federated trust, limiting session risk, protecting administrative access, and reviewing whether access remains justified.

The course uses vendor-neutral patterns and realistic decision points. It does not prescribe a particular identity platform. By the end, learners can map an access path, identify its weak trust assumptions, select proportionate controls, and assemble an improvement plan with clear owners, evidence, and review points.

What you'll learn

  • Map an end-to-end access path and distinguish identity proofing, authentication, authorization, session management, and governance responsibilities.
  • Select authentication and authorization controls that fit an asset's impact, user population, operational constraints, and credible threats.
  • Explain how federation, tokens, sessions, and recovery flows create trust dependencies that require explicit safeguards.
  • Produce a prioritized access-improvement plan with accountable owners, measurable evidence, and a review cadence.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Basic cybersecurity concepts — Learners should understand accounts, networks, applications, common threats, and the difference between confidentiality, integrity, and availability.

Course content