openskills.info
Course Preview

Identity and Access Management Fundamentals

Identity and access management (IAM) is the set of people, processes, and technology that manages digital identities and controls their access to systems and data. It connects account lifecycles, sign-in checks, access policies, enforcement, and audit records.

itIdentity, access, and cryptography

Identity and access management as a control system

Identity and access management (IAM) manages digital identities and controls how those identities use resources. A digital identity is a system's representation of a person, workload, device, or other subject. IAM connects that representation to accounts, authenticators, attributes, permissions, policies, sessions, and audit records.

IAM is not one login screen or one directory. It is a control system spread across the identity lifecycle and the access path. It answers several distinct questions:

  • Which subject does an account represent?
  • How does the subject prove control of that account?
  • Which action may the subject perform on a particular resource?
  • Where is that decision enforced?
  • How does access change when the subject's relationship with the organization changes?
  • Which records explain who requested, approved, received, used, and lost access?

Keeping these questions separate prevents a common mistake: treating successful authentication as permission to do anything.

The identity lifecycle

An identity record usually begins from an authoritative source. A workforce system may supply a person's employment status, manager, and department. A cloud platform may create a workload identity for a service. A partner organization may provide identity information through federation.

Provisioning creates or updates accounts and access from that source. Administration binds attributes, group membership, roles, and authenticators to the account. During use, authentication establishes identity context and authorization evaluates a requested action. Reviews and monitoring look for inappropriate or unused access. Deprovisioning disables accounts, revokes credentials and sessions, and removes grants when the relationship ends.

This lifecycle is often summarized as joiner, mover, and leaver:

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources