Identity Access Management (IAM)
IAM
IAM (Identity and Access Management) is a cybersecurity framework that ensures the right people have the right access to the right resources at the right time.
IAM controls:
Who a user is (Identity)
How they prove they are who they claim to be (Authentication)
What they are allowed to access (Authorization)
Simple Example
Imagine a company office:
Plain Text
Employee
|
v
Login
|
v
IAM System
|
v
Applications and Data
The IAM system verifies:
Who the employee is
Whether they are allowed access
What actions they can perform
Identity
An identity is a digital representation of a user, device, or application.
Examples:
Plain Text
John Smith
jsmith@company.com
Laptop-001
App-Service-Account
Each identity has:
Username
Password
Permissions
Roles
Authentication
Authentication answers:
Plain Text
"Who are you?"
`
A user proves their identity.
Examples:
Something You Know
Plain Text
Password
PIN
Something You Have
Plain Text
Smartphone
Security Token
Smart Card
Something You Are
Plain Text
Fingerprint
Face Scan
Iris Scan
Authorization
Authorization answers:
Plain Text
"What are you allowed to do?"
Example:
Plain Text
HR Employee
|
Can access HR Files
Sales Employee
|
Cannot access HR Files
Authorization occurs after authentication.
Core IAM Components
User Accounts
Each user receives an account.
Example:
Plain Text
Username:
jsmith
The IAM system manages the account lifecycle.
Multifactor Authentication (MFA)
Requires more than one authentication factor.
Example:
Plain Text
Password
+
Phone Verification Code
Benefits:
✅ Stronger security
✅ Reduces account compromise
Single Sign-On (SSO)
Allows users to log in once and access multiple applications.
Without SSO:
Plain Text
Email Login
VPN Login
HR Login
Payroll Login
``
With SSO:
Plain Text
One Login
|
Multiple Applications
Examples:
Microsoft Entra ID (formerly Azure AD)
Okta
Ping Identity
Role-Based Access Control (RBAC)
Permissions are assigned based on job roles.
Example:
Plain Text
HR Role
|
Access HR Data
Sales Role
|
Access Sales Data
Benefits:
✅ Easier administration
✅ Consistent permissions
✅ Improved security
Principle of Least Privilege
Users receive only the permissions necessary to perform their jobs.
Example:
Plain Text
Accountant
Gets access to:
Plain Text
Accounting Systems
Not:
Plain Text
Server Administrator Tools
Identity Lifecycle Management
IAM manages accounts through their entire lifecycle.
Joiner
New employee is hired.
Plain Text
Create Account
Assign Role
Grant Access
`
Mover
Employee changes jobs.
Plain Text
Update Permissions
Remove Old Access
Add New Access
Leaver
Employee leaves company.
Plain Text
Disable Account
Remove Access
Privileged Access Management (PAM)
PAM is a specialized IAM function for highly privileged accounts.
Examples:
Plain Text
Domain Admin
Database Admin
Cloud Administrator
These accounts are high-value targets and require additional protection.
Common IAM Solutions
Microsoft
Microsoft Entra ID
Active Directory
Other Vendors
Okta
Ping Identity
CyberArk
SailPoint
OneLogin
IAM in Cloud Computing
Cloud environments rely heavily on IAM.
Example:
Plain Text
Microsoft Azure
AWS
Google Cloud
IAM controls:
User accounts
Administrator access
Application permissions
API access
Resource access
Benefits of IAM
✅ Centralized user management
✅ Better security
✅ Supports MFA
✅ Simplifies audits
✅ Improves compliance
✅ Reduces insider threats
✅ Enables SSO
✅ Enforces least privilege
IAM vs Authentication vs Authorization
Term MeaningIdentity Who the user is
Authentication Verify identity
Authorization Determine access
IAM Manages all three
Security+ Exam Tips
Remember
Plain Text
Identity = Who Are You?
Authentication = Prove It
Authorization = What Can You Access?
Key Technologies
MFA
SSO
RBAC
PAM
Least Privilege
Quick Memory Trick
Plain Text
IAM =
Identity
Authentication
Authorization
Management
Simple Definition
IAM (Identity and Access Management) is the process of managing digital identities and controlling access to systems, applications, and data through authentication, authorization, multifactor authentication, single sign-on, and role-based access controls to ensure that only authorized users can access specific resources.
AllPeoplePeopleFilesFilesMeetingsMeetings
Subscribe to our newsletter
Sign up with your email address to receive news and updates.