Identity and Access Management
Identity vocabulary every security practitioner shares — authentication factors + MFA, federation (SAML/OAuth/OIDC), authorization models, Zero Trust, PIM, identity governance. Five hands-on labs including three on a real Entra P2 tenant.
View badge details
About This Course
Build the identity vocabulary every modern security practitioner shares. Over eight AI-led teaching lessons and five hands-on labs including read-only audit labs on a real Entra P2 tenant you will learn authentication factors and the modern phishing-resistant MFA ladder, federation protocols (SAML, OAuth 2.0, OIDC), authorization models (ACL, RBAC, ABAC, PBAC, ReBAC), the Zero Trust architecture that replaced perimeter trust, privileged-access-management via PIM, and the full identity-governance lifecycle. By the end you will be able to decode a SAML assertion and an OIDC id_token by hand, audit a Conditional Access configuration, read a PIM eligibility set, and triage Identity Protection risk events the way a real IAM analyst does.
Course Curriculum
10 Lessons
Authentication factors and password security
Learn the five authentication factor categories and the specific reasons password-based authentication has become the single highest-risk identity surface. By the end of this lesson you will be able to name all five factor categories and explain why combining them across categories (not within) is the modern MFA baseline, explain why fast cryptographic hashes make password storage with SHA-256 alone insufficient, and distinguish credential-stuffing from password-spraying attacks on Beacon Harbor's login surfaces.
MFA deep-dive — phishable, phishing-resistant, and risk-based
Build on Lesson 1's factor-category foundation to understand which specific second factors are phishable (SMS, voice call, security questions), which are phishing-resistant (FIDO2 keys, platform authenticators, certificate-based auth), and how modern identity platforms use risk signals to require stronger factors only when the sign-in context demands it. By the end you will be able to rank the common second-factor choices by resistance to AITM phishing, explain what makes FIDO2/WebAuthn cryptographically phishing-resistant, and describe when conditional access risk-based policies belong in the authentication flow.
SAML and OIDC decode - Lab Exercises
Note: This lab pre-provisions an Azure Linux VM at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Decode real SAML assertions and OIDC id_tokens from the command line to see exactly what information passes through each stage of federated authentication. You will capture a sample SAML response, base64-decode and XML-parse it to inspect the Subject, Issuer, Conditions, and AttributeStatement; capture a sample OIDC id_token, split and base64-decode its three JWT segments, and verify its signature against the issuer's public JWKS. By the end you will be able to read a federation trace and tell Priya at the SOC which fields a reviewer must verify in any identity-related investigation.
Federation protocols — SAML, OAuth 2, OIDC in depth
Build on Lab 1's hands-on decode and understand WHEN each federation protocol belongs in Beacon Harbor's identity architecture. By the end you will be able to draw the SAML browser-POST flow and identify what travels at each hop, draw the OIDC Authorization Code with PKCE flow and name the three token types (access, id, refresh), explain the authentication-vs-authorization distinction that OAuth 2 alone does not solve, and tell a developer why OIDC on top of OAuth 2 is the modern baseline instead of SAML for new applications.
OAuth 2.0 and OIDC walkthrough - Lab Exercises
Walk through a real OIDC Authorization Code flow against a public identity provider sandbox, capture the authorization code and id_token, and decode them to see exactly which values pass between the parties. You will use the public OIDC playground at openidconnect.net to observe the full round trip without needing a Beacon Harbor tenant, then decode the returned id_token at jwt.io to inspect each claim. By the end you will have seen every HTTP exchange in a working OIDC flow and can describe what breaks if any single parameter is missing.
Authorization models — RBAC, ABAC, and ReBAC
Learn the three dominant authorization models used in modern enterprise systems — Role-Based (RBAC), Attribute-Based (ABAC), and Relationship-Based (ReBAC) — and when each is correct. By the end you will be able to design the authorization model for a new Beacon Harbor application given its data model and access requirements, explain the "role explosion" problem that drives teams from RBAC to ABAC or ReBAC, and name specific signals in a system's requirements that call for ABAC over RBAC.
Zero Trust architecture
Learn the Zero Trust architectural stance — "never trust, always verify" — and how its three principles (verify explicitly, use least privilege, assume breach) replace the legacy perimeter-based security model. By the end you will be able to describe how Zero Trust Network Access (ZTNA) replaces the legacy VPN, explain microsegmentation at the application level, and audit a Beacon Harbor sign-in flow against the three Zero Trust principles.
Audit Beacon Harbor Conditional Access on opsgilitylabs69 - Lab Exercises
Note: This lab pre-provisions an Entra P2 user in the shared opsgilitylabs69 tenant at start — allow up to 5 minutes for the environment to become ready before beginning the exercises.
Audit Beacon Harbor's Conditional Access policies on the real shared opsgilitylabs69 tenant using a lab-provisioned Global Reader account. You will inventory every active CA policy, identify which policies cover which user groups and applications, spot gaps in sign-in-risk coverage, and brief Camila on three specific improvements. By the end you will have practiced the exact audit workflow that an SC-300 candidate or a working Beacon Harbor identity engineer performs quarterly.
Privileged access and identity governance
Learn Privileged Access Management (PAM) and identity governance — the two specialized disciplines around high-value accounts and ongoing access control. By the end you will be able to design a PAM strategy using just-in-time elevation (PIM) with break-glass fallback, explain why standing privileged access is the single biggest internal risk, and run an access review that produces an actionable outcome rather than rubber-stamp noise.
Audit PIM and Identity Protection on opsgilitylabs69 - Lab Exercises
Note: This lab pre-provisions an Entra P2 user in the shared opsgilitylabs69 tenant at start — allow up to 5 minutes for the environment to become ready before beginning the exercises.
Audit Beacon Harbor's Privileged Identity Management (PIM) + Identity Protection posture on the real shared opsgilitylabs69 tenant using a lab-provisioned Global Reader account. You will inventory all PIM-eligible and PIM-active role assignments, verify break-glass accounts match the standard pattern, review Identity Protection sign-in and user-risk policies, cross-reference the user-risk and sign-in-risk reports for the past 30 days, and brief Camila on the top four improvements. By the end you will have practiced the full IAM capstone workflow combining PAM, access reviews, and Identity Protection into one coherent audit.