This course is currently under maintenance. We're updating content and labs. Enrollment is paused; check back soon.
AI Instructor Live Labs Included

Identity and Access Management

Identity vocabulary every security practitioner shares — authentication factors + MFA, federation (SAML/OAuth/OIDC), authorization models, Zero Trust, PIM, identity governance. Five hands-on labs including three on a real Entra P2 tenant.

Beginner
11h 30m
10 Lessons
CYBER-200
Identity and Access Management Badge

View badge details

About This Course

Build the identity vocabulary every modern security practitioner shares. Over eight AI-led teaching lessons and five hands-on labs including read-only audit labs on a real Entra P2 tenant you will learn authentication factors and the modern phishing-resistant MFA ladder, federation protocols (SAML, OAuth 2.0, OIDC), authorization models (ACL, RBAC, ABAC, PBAC, ReBAC), the Zero Trust architecture that replaced perimeter trust, privileged-access-management via PIM, and the full identity-governance lifecycle. By the end you will be able to decode a SAML assertion and an OIDC id_token by hand, audit a Conditional Access configuration, read a PIM eligibility set, and triage Identity Protection risk events the way a real IAM analyst does.

Course Curriculum

10 Lessons
01
AI Lesson
AI Lesson

Authentication factors and password security

1h 30m

Learn the five authentication factor categories and the specific reasons password-based authentication has become the single highest-risk identity surface. By the end of this lesson you will be able to name all five factor categories and explain why combining them across categories (not within) is the modern MFA baseline, explain why fast cryptographic hashes make password storage with SHA-256 alone insufficient, and distinguish credential-stuffing from password-spraying attacks on Beacon Harbor's login surfaces.

02
AI Lesson
AI Lesson

MFA deep-dive — phishable, phishing-resistant, and risk-based

1h 0m

Build on Lesson 1's factor-category foundation to understand which specific second factors are phishable (SMS, voice call, security questions), which are phishing-resistant (FIDO2 keys, platform authenticators, certificate-based auth), and how modern identity platforms use risk signals to require stronger factors only when the sign-in context demands it. By the end you will be able to rank the common second-factor choices by resistance to AITM phishing, explain what makes FIDO2/WebAuthn cryptographically phishing-resistant, and describe when conditional access risk-based policies belong in the authentication flow.

03
Lab Exercise
Lab Exercise

SAML and OIDC decode - Lab Exercises

1h 0m 4 Exercises

Note: This lab pre-provisions an Azure Linux VM at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Decode real SAML assertions and OIDC id_tokens from the command line to see exactly what information passes through each stage of federated authentication. You will capture a sample SAML response, base64-decode and XML-parse it to inspect the Subject, Issuer, Conditions, and AttributeStatement; capture a sample OIDC id_token, split and base64-decode its three JWT segments, and verify its signature against the issuer's public JWKS. By the end you will be able to read a federation trace and tell Priya at the SOC which fields a reviewer must verify in any identity-related investigation.

04
AI Lesson
AI Lesson

Federation protocols — SAML, OAuth 2, OIDC in depth

1h 15m

Build on Lab 1's hands-on decode and understand WHEN each federation protocol belongs in Beacon Harbor's identity architecture. By the end you will be able to draw the SAML browser-POST flow and identify what travels at each hop, draw the OIDC Authorization Code with PKCE flow and name the three token types (access, id, refresh), explain the authentication-vs-authorization distinction that OAuth 2 alone does not solve, and tell a developer why OIDC on top of OAuth 2 is the modern baseline instead of SAML for new applications.

05
Lab Exercise
Lab Exercise

OAuth 2.0 and OIDC walkthrough - Lab Exercises

45m 3 Exercises

Walk through a real OIDC Authorization Code flow against a public identity provider sandbox, capture the authorization code and id_token, and decode them to see exactly which values pass between the parties. You will use the public OIDC playground at openidconnect.net to observe the full round trip without needing a Beacon Harbor tenant, then decode the returned id_token at jwt.io to inspect each claim. By the end you will have seen every HTTP exchange in a working OIDC flow and can describe what breaks if any single parameter is missing.

06
AI Lesson
AI Lesson

Authorization models — RBAC, ABAC, and ReBAC

1h 15m

Learn the three dominant authorization models used in modern enterprise systems — Role-Based (RBAC), Attribute-Based (ABAC), and Relationship-Based (ReBAC) — and when each is correct. By the end you will be able to design the authorization model for a new Beacon Harbor application given its data model and access requirements, explain the "role explosion" problem that drives teams from RBAC to ABAC or ReBAC, and name specific signals in a system's requirements that call for ABAC over RBAC.

07
AI Lesson
AI Lesson

Zero Trust architecture

1h 0m

Learn the Zero Trust architectural stance — "never trust, always verify" — and how its three principles (verify explicitly, use least privilege, assume breach) replace the legacy perimeter-based security model. By the end you will be able to describe how Zero Trust Network Access (ZTNA) replaces the legacy VPN, explain microsegmentation at the application level, and audit a Beacon Harbor sign-in flow against the three Zero Trust principles.

08
Lab Exercise
Lab Exercise

Audit Beacon Harbor Conditional Access on opsgilitylabs69 - Lab Exercises

1h 0m 4 Exercises

Note: This lab pre-provisions an Entra P2 user in the shared opsgilitylabs69 tenant at start — allow up to 5 minutes for the environment to become ready before beginning the exercises.

Audit Beacon Harbor's Conditional Access policies on the real shared opsgilitylabs69 tenant using a lab-provisioned Global Reader account. You will inventory every active CA policy, identify which policies cover which user groups and applications, spot gaps in sign-in-risk coverage, and brief Camila on three specific improvements. By the end you will have practiced the exact audit workflow that an SC-300 candidate or a working Beacon Harbor identity engineer performs quarterly.

09
AI Lesson
AI Lesson

Privileged access and identity governance

1h 15m

Learn Privileged Access Management (PAM) and identity governance — the two specialized disciplines around high-value accounts and ongoing access control. By the end you will be able to design a PAM strategy using just-in-time elevation (PIM) with break-glass fallback, explain why standing privileged access is the single biggest internal risk, and run an access review that produces an actionable outcome rather than rubber-stamp noise.

10
Lab Exercise
Lab Exercise

Audit PIM and Identity Protection on opsgilitylabs69 - Lab Exercises

1h 30m 5 Exercises

Note: This lab pre-provisions an Entra P2 user in the shared opsgilitylabs69 tenant at start — allow up to 5 minutes for the environment to become ready before beginning the exercises.

Audit Beacon Harbor's Privileged Identity Management (PIM) + Identity Protection posture on the real shared opsgilitylabs69 tenant using a lab-provisioned Global Reader account. You will inventory all PIM-eligible and PIM-active role assignments, verify break-glass accounts match the standard pattern, review Identity Protection sign-in and user-risk policies, cross-reference the user-risk and sign-in-risk reports for the past 30 days, and brief Camila on the top four improvements. By the end you will have practiced the full IAM capstone workflow combining PAM, access reviews, and Identity Protection into one coherent audit.

Under Maintenance

This course is currently being updated. Check back soon!

This course includes:

  • 24/7 AI Instructor Support
  • Live Lab Environments
  • 4 Hands-on Lessons
  • Completion Badge
Identity and Access Management Badge

Earn Your Badge

Complete all lessons to unlock the Identity and Access Management achievement badge.

Skill Level Beginner
Total Duration 11h 30m
Identity and Access Management Badge
Achievement Badge

Identity and Access Management

Awarded for completing Identity and Access Management. Signals demonstrated competence in authentication factors + MFA strength, federation protocols (SAML/OAuth/OIDC), authorization models, Zero Trust architecture, PIM, and identity governance including hands-on audit of a real Entra P2 tenant configuration.

Course Identity and Access Management
Criteria Complete all 8 teaching lessons with ≥80% assessment scores + all 5 hands-on labs (SAML/OIDC decode, OAuth walkthrough, Conditional Access audit, PIM review, Identity Protection triage) within the 12-month skill-path window.

Skills You'll Earn

Authentication factors + MFA Password security Federation (SAML + OAuth 2.0 + OIDC) Authorization models (ACL + RBAC + ABAC + PBAC + ReBAC) Zero Trust architecture Privileged Access Management (PIM) Identity governance (JML + access reviews)

Complete all lessons in this course to earn this badge