TechKnowSurge
NIST NICE K0742 NIST CSF PR.AA-01 CompTIA Security+ 4.6 ISC2 CISSP 5.2 NIST 800-53 AC-2 ISC2 CISSP 5.5 NIST NICE K0829 NIST CSF PR.AA-05
VideoSecurityFree

Identity and Access Management (IAM)

Identity and Access Management (IAM) is a framework of policies, technologies, and controls that governs how organizations verify who users are and what resources they can access. It spans authentication protocols, authorization systems, and the full account lifecycle from provisioning to deprovisioning.

Complete this video to capture a CTF flag worth 1 point.

About this video

Identity and Access Management (IAM) is a comprehensive organizational framework built from policies, standards, procedures, guidelines, controls, technologies, and protocols. Its purpose is to define and enforce how an organization identifies users and manages what those users are permitted to access. While every organization implements IAM differently based on its structure and needs, the underlying principles remain consistent: confirm identity, control access, and manage accounts throughout their entire lifecycle. Authentication is the process of verifying identity, combining something that identifies a user, such as a username, certificate, biometric, smart card, or one-time passcode, with a verification step to confirm that the person is who they claim to be. A range of authentication protocols supports this process across different environments. PAP, CHAP, and EAP are commonly associated with point-to-point connections, while Kerberos, TACACS+, RADIUS, Diameter, and LDAP are widely used within enterprise networks. SAML, OAuth, and OpenID have become standard for web application authentication. Authorization is a separate but equally important function that determines which specific resources an authenticated user may access, whether that means particular computers, networks, servers, data sets, encryption keys, or document types. Being authenticated does not automatically grant access to everything within a system, and IAM frameworks define those boundaries explicitly. IAM also governs the full account lifecycle, starting with provisioning when a user joins an organization, continuing through ongoing maintenance and role-based access adjustments as responsibilities change, and concluding with deprovisioning when the user departs and their access is formally terminated. This lifecycle management ensures that access rights remain accurate and appropriate at every stage of a user's relationship with the organization.

What you'll learn

What's covered

Identity & Access Management

Aligned to

NIST NICE
K0742 Knowledge of identity and access management (IAM) principles and practices
K0829 Knowledge of account creation policies and procedures
NIST CSF
PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization.
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.
CompTIA Security+
4.6 Given a scenario, implement and maintain identity and access management.
ISC2 CISSP
5.2 Design identification and authentication strategy
5.5 Manage the identity and access provisioning lifecycle
NIST 800-53
AC-2 Account Management

Key terms

Identity and Access Management
IAM
A framework of policies and technologies that ensures the right users have appropriate access to resources.
Authentication
The process of verifying the identity of a user, device, or system.
Authorization
The process of determining what actions or resources an authenticated user is permitted to access.
Provisioning
The process of creating and configuring user accounts and granting appropriate access rights when a user joins or changes roles in an organization.
De-provisioning
The process of revoking and removing a user's access rights and accounts when they leave an organization or no longer require access.
Account Lifecycle
The end-to-end management of a user account from initial provisioning through ongoing maintenance to final de-provisioning.

Topics

Identity And Access Management Authentication Access Control Account Lifecycle Authorization Cybersecurity

Transcript

What identity and access management is

The name really does say it all. Identity, which is who you are, proving that who you are. And then access management, what do you have access to. These tickets do represent some systems — not all systems, but some systems — where, once you prove your identity, you're given certain tokens that you're allowed to log into certain resources from.

But really, what is it? IAM is a framework. It consists of policies, standards, procedures, guidelines, controls, technology, services and protocols. It's really how you implement this idea of identity and access management. Each company is going to have a little bit different view into this and a little different setup into this, but it's the overall picture of how your company and organization approaches identifying people and the access that they have.

Identity and authentication

Identity can come in lots of different forms. A lot of times we use usernames to identify people, but it could come in the form of a certificate, it could come in the form of biometrics, it could come in the form of some sort of smart card, it could come in as a one-time password — something, when you're trying to log into a system, that you are sent through email or through SMS or through some other means, some sort of code for you to log into that system.

So, anything that will identify who you are, we call that authentication. When you take who you are, your ID, and some sort of verification, then you become authenticated. That is authentication.

There are quite a few authentication protocols that help with this process. PAP, CHAP and EAP are examples of those, and EAP is one of the most prevalent ones that are out there. These are really more associated with point-to-point protocols, although something like EAP gets incorporated with a lot of other types of protocols. So we take this protocol and we incorporate it into other protocols, and so it really gets used a lot.

Then there's Kerberos, TACACS, RADIUS, Diameter and LDAP. These are more protocols that you would use within your network. And then we have SAML, OAuth and OpenID, which are some more recent protocols that we use with web applications.

Access management and authorization

Once you are authenticated with a system and are allowed onto a system, that doesn't mean that you have access to all the resources of that system. So there's an authorization part that happens to this as well. There's an access management part of this.

So what do you have access to once you're on the system? It could be certain computers that you have access to, it could be certain networks, it could be certain servers, certain data, certain keys, certain types of documents. So, what are you authorized to view once you're on that network, once you're within the system?

Account life cycle

Identity and access management is really this holistic view though. It's not just the systems you're logging onto and how you're managing it, but it also takes this broader scope of even how do you manage your accounts.

When somebody starts at your company, you have this provisioning process where they are provisioned an account and they're given access to certain things. Once they are given access to it, there's this maintenance that happens, and you have to do some change management if they change positions. So we sit there and manage those accounts as things change, so that way we make sure that we don't give them access to systems that they don't necessarily need access to at any given time. And then we go through a de-provisioning process when that person leaves. Then we have to terminate the account and bring it down, so we go through this process of decommissioning or de-provisioning resources from that account.

I like to think of IAM, identity and access management, as this big umbrella of how you approach things and how you implement things from a company or organization wide standpoint. So it really has to do with that identity part and what you have access to, but there are parts of it that are not just a technical way of looking at things — there are things like account life cycle and how you provision and de-provision those accounts.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →