TechKnowSurge
NIST 800-53 AC-2 NIST CSF PR.AA-01 ISC2 CC 3.1 CompTIA Cloud+ 1.2 NIST 800-53 IA-2 Cisco CCNA 5.8 CompTIA Tech+ 6.4 Cisco CCST Cybersecurity 1.3
VideoSecurityFree

Identity and Access Management (IAM)

Identity and access management (IAM) is a framework of policies, technologies, and controls that governs how organizations verify who users are and what resources they can access. It also covers the full account lifecycle, from provisioning new users to deprovisioning accounts when employees leave.

Complete this video to capture a CTF flag worth 1 point.

About this video

Identity and access management (IAM) is a broad organizational framework that defines how a company establishes user identities, verifies those identities, and controls what resources authenticated users are permitted to access. Rather than a single product or tool, IAM encompasses policies, standards, procedures, guidelines, controls, technologies, services, and protocols — and its specific implementation varies from organization to organization based on their structure and security requirements. The identity side of IAM focuses on authentication: confirming that users are who they claim to be. Identity can be established through usernames and passwords, digital certificates, biometrics, smart cards, or one-time passcodes delivered via email or SMS. Numerous protocols support the authentication process, including PAP, CHAP, and EAP for point-to-point connections; Kerberos, TACACS+, RADIUS, DIAMETER, and LDAP for network-level authentication; and SAML, OAuth, and OpenID for modern web application environments. Successfully authenticating to a system does not automatically grant access to all of its resources — that is governed separately by authorization controls, which define which systems, networks, servers, data sets, and documents a given user is permitted to interact with. IAM also extends into account lifecycle management, treating the entire span of a user's relationship with organizational systems as part of the framework. When a new employee joins, an account provisioning process grants them access to the specific resources their role requires. As their responsibilities change, access permissions must be reviewed and updated to ensure they reflect current needs — a principle of ongoing access governance. When an employee departs, a formal deprovisioning process terminates the account and revokes associated access, ensuring that former users retain no foothold within organizational systems. Taken together, these technical and administrative dimensions make IAM one of the foundational disciplines of enterprise security.

What you'll learn

What's covered

Identity and Access Management

Aligned to

NIST 800-53
AC-2 Account Management
IA-2 Identification and Authentication (Organizational Users)
NIST CSF
PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization.
ISC2 CC
3.1 Understand identity life cycle management
CompTIA Cloud+
1.2 Given a scenario, configure identity and access management (IAM) for a cloud environment.
Cisco CCNA
5.8 Compare authentication, authorization, and accounting concepts
CompTIA Tech+
6.4 Compare and contrast authentication, authorization, accounting, and non-repudiation concepts
Cisco CCST Cybersecurity
1.3 Explain access management principles

Key terms

Identity and Access Management
IAM
A framework of policies and technologies that ensures the right users have appropriate access to resources.
Authentication
The process of verifying the identity of a user, device, or system.
Authorization
The process of determining what actions or resources an authenticated user is permitted to access.
Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Single Sign-On
SSO
An authentication process that allows a user to access multiple applications with one set of credentials.
Biometrics
Authentication methods that use unique physical or behavioral characteristics such as fingerprints or retinal scans.
Role-Based Access Control
RBAC
An access control model that assigns permissions based on a user's role within an organization.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Active Directory
AD
Microsoft's directory service used to manage users, computers, and resources in a network.
Account Lifecycle Management
The process of provisioning, maintaining, and deprovisioning user accounts throughout their existence within an organization.

Topics

Identity And Access Management Authentication Authorization Account Lifecycle Management Access Control Cybersecurity

Transcript

We'll start out by just defining what IAM is, get into identity and access management and the two components of it, and then finish off by talking about account lifecycle.

What IAM Is

The name really does say it all: identity, which is who you are, proving who you are; and then access management, what do you have access to. These tickets do represent some systems — not all systems, but some systems — where once you prove your identity you're given certain tokens, and you're allowed to log into certain resources from those tokens.

But really, what is it? IAM is a framework. It consists of policies, standards, procedures, guidelines, controls, technology, services, protocols. It's really how you implement this idea of identity and access management. Each company is going to have a little bit different view into this and a little different setup into this, but it's the overall picture of how your company and organization approaches identifying people and the access that they have.

Identity and Authentication

Identity can come in lots of different forms. A lot of times we use usernames to identify people, but it could come in the form of a certificate, it could come in the form of biometrics, it could come in the form of some sort of smart card, it could come in as a one-time password — something sent to you through email or through SMS or through some other means, some sort of code for you to log into that system.

Anything that will identify who you are, we call that authentication. When you take who you are, your ID, and some sort of verification, then you become authenticated, and so that is authentication.

There's quite a few authentication protocols that help with this process. PAP, CHAP and EAP are examples of those, and EAP is one of the most prevalent ones that are out there. These are really more associated with point-to-point protocols, although something like EAP gets incorporated with a lot of other types of protocols — we take this protocol and we incorporate it into other protocols, and so it really gets used a lot.

Then there's Kerberos, TACACS, RADIUS, Diameter and LDAP. These are more protocols that you would use within your network. And then we have SAML, OAuth and OpenID, which are some more recent protocols that we use with web applications.

Authorization and Access Management

Once you are authenticated with the system and are allowed onto a system, that doesn't mean that you have access to all the resources of that system. So there's an authorization part that happens to this as well — there's an access management part of this. What do you have access to once you're on the system? It could be certain computers that you have access to, it could be certain networks, it could be certain servers, certain data, certain keys, certain types of documents. So what are you authorized to view once you're on that network, once you're within the system?

Account Lifecycle

Identity and access management is really this holistic view, though. It's not just the systems you're logging on to and how you're managing it, but it also takes this broader scope of even how do you manage your accounts.

When somebody starts at your company, you have this provisioning process where they are provisioned an account and they're given access to certain things. Once they are given access to it, there's this maintenance that happens, and you have to do some change management if they change positions. So we sit there and manage those accounts as things change, so that way we make sure that we don't give them access to systems that they don't necessarily need access to at any given time. And then we go through a de-provisioning process when that person leaves — then we have to terminate the account and bring it down, so we go through this process of decommissioning or de-provisioning resources from that account.

I like to think of IAM, identity and access management, as this big umbrella of how you approach things and how you implement things from a company- or organization-wide view. So it really has to do with that identity part and what you have access to. But there are parts of it that are not just a technical way of looking at things — there are things like account lifecycle, and how you provision and de-provision those accounts.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →