Entry level · 8 articles
IAM Basics
The concepts every other path assumes: what identity and access management is for, how authentication differs from authorization, where directories fit, and the handful of controls (MFA, SSO, least privilege, lifecycle) that every IAM program is built from.
People new to identity: students, sysadmins and developers moving into IAM, and managers who need the vocabulary.
You can explain how a user gets access to an application in a modern organization, name the controls involved, and read the rest of this site without a glossary open.
Before you start: IAM in five ideas
- Identity is the record, not the person. An identity is an entry in a directory with attributes (name, department, manager, status) and credentials. People, devices, services and now AI agents all have them, and the non-human ones outnumber the human ones.
- Authentication asks "is it you?"; authorization asks "may you?". Passwords, passkeys and MFA are authentication. Roles, groups, policies and entitlements are authorization. Most incidents involve the second being too generous.
- Applications trust an identity provider instead of keeping passwords. Single sign-on works because the application (service provider or relying party) accepts a signed statement from the identity provider, carried by SAML or OpenID Connect.
- Access should follow the job, and end with it. The joiner-mover-leaver lifecycle, driven from HR, is where access is granted and removed. Governance tools exist to automate it and to prove to auditors that it happened.
- Privilege is the prize. Administrative access is what attackers want and what least privilege, privileged access management and zero trust are designed to limit.
Terms you do not recognize are in the IAM glossary. When you finish this path, the Identity Protocols path is the usual next step for engineers, and Identity Governance for analysts.
Reading order
- 1
IAM Career Path Guide: From Entry Level to Expert
Start with the map of roles and skills so the rest of the path has a destination.
- 2
Mastering LDAP & Active Directory for IAM: A Deep Dive Guide
Directories are where identities live; most organizations still run on this one.
- 3
Multi-Factor Authentication (MFA) Deep Dive: A Complete Guide
Authentication, and the single control with the best return in IAM.
- 4
SSO Implementation Best Practices
How one login reaches many applications, and what can go wrong.
- 5
RBAC vs ABAC: Your IAM Access Control Decision Guide
Authorization: the two models you will meet in every product.
- 6
Implementing Least Privilege: Boost Your IAM Security
The principle behind PAM, governance and zero trust.
- 7
Secure & Efficient IAM: Identity Lifecycle Management Best Practices
Joiners, movers and leavers: where most access problems begin.
- 8
How to Choose an Identity Provider: Enterprise Selection Guide
Finish by seeing how the concepts turn into a buying decision.
Each article shows its place in this path with links to the previous and next step, so you can read straight through.