Learning path · Intermediate
Identity and Access Management
Learn the identity control plane: directories, protocols, policy and privileged access.
What you will be able to do
- Explain Kerberos, SAML, OAuth and OIDC and when each applies
- Design Conditional Access policy with break glass and rollback
- Remove standing privilege using tiering and just in time activation
The path
Work through these in order.
- 01Identity Fundamentals
Authentication versus authorization.
Authentication proves who you are; authorization decides what you may do; identity management maintains both over time.
- 02Active Directory
Forests, Group Policy and Tier 0 thinking.
Microsoft's on premises directory service, providing authentication, authorisation, policy and object management for Windows environments.
- 03Kerberos
Tickets, SPNs and the attacks that target them.
A ticket based authentication protocol that proves identity to services without sending the password across the network.
- 04Microsoft Entra ID
Cloud identity, tokens and hybrid synchronisation.
Microsoft's cloud identity and access management service, the identity control plane for Microsoft 365, Azure and thousands of federated applications.
- 05SAML & OpenID Connect
Federated SSO patterns and their pitfalls.
One authentication event, evaluated by a central identity provider, granting access to many applications through issued tokens or assertions.
- 06MFA & Passwordless
Method strength and phishing resistance.
Requiring two or more independent factors, something you know, have or are, before granting access.
- 07Conditional Access
Signals, controls and safe rollout.
Policy that evaluates signals about the user, device, application, location and risk at sign in, then grants, blocks or constrains access.
- 08Privileged Access Management
Tiering, JIT, vaulting and PAWs.
Controlling, brokering, recording and time limiting administrative access to the systems that can change everything else.
- 09Identity Governance
Lifecycle, reviews and separation of duties.
The lifecycle and oversight side of identity: joiner mover leaver automation, entitlement management, access reviews and separation of duties.
