Glossary
IAM Glossary
67 terms, defined the way practitioners use them. Each links to the guide or tool that goes deeper.
A
- Access Management (AM)
- The part of IAM that decides, at the moment of a request, whether an authenticated identity may reach an application or resource. Covers single sign-on, multi-factor authentication, session management and access policy.
- Access Management solutions
- Access Review (Access Certification)
- A periodic check in which a manager or resource owner confirms or revokes each person's access. The control auditors ask about first; it only counts when the results are applied.
- Effective Access Reviews
- Access Token
- A credential issued by an authorization server that a client presents to an API to prove it is allowed to call it. In OAuth 2.0 it is meant for the API, not for identifying the user; that is the ID token's job.
- JWT DecoderOAuth 2.0 Deep Dive
- Active Directory (AD)
- Microsoft's on-premises directory service: the database of users, computers and groups that Windows domains authenticate against, using Kerberos and LDAP. Still the source of truth in most hybrid organizations.
- LDAP & Active Directory deep dive
- Adaptive (Risk-Based) Authentication
- Varying the authentication requirement by risk signals such as device, location, network and behaviour: a known laptop on the office network gets a password, an unknown device abroad gets a step-up challenge.
- Assertion (SAML)
- The signed XML statement an identity provider sends to a service provider saying who the user is, how they authenticated and which attributes they carry. The service provider must verify its signature, audience, issuer and validity window.
- SAML DecoderSAML 2.0 Explained
- Attribute-Based Access Control (ABAC)
- Authorization decided by evaluating attributes of the user, the resource, the action and the environment against policy, rather than by role membership alone. More expressive than RBAC, harder to audit.
- RBAC vs ABAC
- Authentication (AuthN)
- Establishing that a principal is who it claims to be, using something it knows (password), has (security key, phone) or is (biometric). Comes before authorization.
B
- B2B Identity (Partner Identity)
- Giving people from other organizations access to your applications without creating full employee accounts for them: guest accounts, federation with their identity provider, and partner-specific governance.
- Partner identity solutions
- Break-Glass Account
- An emergency administrative account excluded from the usual access policy so that administrators can still get in when the identity provider, MFA or Conditional Access is misconfigured. Stored offline, monitored, and tested on a schedule.
C
- Claims
- Name-value statements about a subject carried in a token or assertion: subject identifier, email, groups, authentication time. Applications should rely on the claims they validated, not on anything else in the token.
- Claims Mapper
- Cloud Infrastructure Entitlement Management (CIEM)
- Tooling that discovers and right-sizes permissions across cloud providers, where a single identity may hold thousands of granular entitlements that no human reviews.
- CIEM Deep Dive
- Conditional Access
- Policy that grants, blocks or adds requirements to a sign-in based on conditions: user, application, device state, location, risk. Microsoft's name for it; other vendors call it sign-on policy or adaptive access.
- Designing Conditional Access policies
- Customer Identity and Access Management (CIAM)
- IAM for customers and consumers rather than employees: self-registration, social login, consent and privacy, and scale to millions of users with a user experience that does not drive them away.
- Customer identity solutions
D
- Deprovisioning
- Removing accounts and access when a person leaves or changes role. The step most often missed, and the reason leavers still have access months later.
- Directory Service
- A database optimized for reading identity data: users, groups, devices and their attributes. LDAP directories and Active Directory on premises; Entra ID, Okta Universal Directory and Google Cloud Identity in the cloud.
- Directory services solutions
- DPoP (Demonstrating Proof of Possession)
- An OAuth extension that binds an access token to a key held by the client, so a stolen token cannot be replayed from elsewhere. One of the sender-constraining mechanisms, alongside mutual TLS.
- DPoP ToolOAuth 2.1 and DPoP
E
- Entitlement
- A specific permission in a specific system: a group membership, a role in an application, a share on a file server. Governance works at this level; roles bundle entitlements.
- Entitlement Management
- Request-and-approval workflows that grant bundles of access (access packages) with an approver, a duration and a review. The self-service front door of identity governance.
F
- Federation
- Trusting another organization's or system's identity provider to authenticate users, so they sign in once at home and are accepted elsewhere. SAML and OpenID Connect are federation protocols.
- SAML vs OIDC
- FIDO2 / WebAuthn
- The standards behind passkeys and security keys: a public-key credential created per site, used by the browser to sign a challenge. Phishing-resistant because the credential is bound to the origin.
- WebAuthn DebuggerFIDO2 WebAuthn Internals
I
- ID Token
- The OpenID Connect token that tells the client who signed in: a signed JWT with subject, issuer, audience, expiry and nonce. It is for the client, not for calling APIs.
- OIDC Deep Dive
- Identity Fabric
- An architecture in which an organization's existing identity services are connected under consistent policy, orchestrated flows, standard interfaces and shared observability, rather than replaced by one product.
- Identity Fabric Solutions
- Identity Governance and Administration (IGA)
- The discipline and product category covering identity lifecycle, access requests, access reviews, role management and separation of duties, with the audit trail that proves it. SailPoint, Saviynt, Microsoft Entra ID Governance and others.
- Identity governance solutionsIGA learning path
- Identity Lifecycle (Joiner, Mover, Leaver)
- The events that should drive access: someone joins and gets a baseline, changes role and has access adjusted, leaves and has everything removed. Usually driven from the HR system.
- Lifecycle management best practices
- Identity Orchestration
- Composing sign-in, registration and step-up journeys from separate services through configuration, so a change to the MFA provider or the risk engine changes every flow at once.
- Identity Provider (IdP)
- The system that authenticates users and issues assertions or tokens to applications: Entra ID, Okta, Ping, Keycloak and others. Applications that trust it are relying parties or service providers.
- Choosing an identity provider
- Identity Threat Detection and Response (ITDR)
- Detecting and responding to attacks on the identity layer itself: credential theft, token replay, privilege escalation, rogue MFA enrolment. Sits between IAM and the security operations centre.
- Identity threat detection solutions
J
- JSON Web Key Set (JWKS)
- A published document of the public keys an issuer signs tokens with, found via the discovery document's jwks_uri. Clients fetch and cache it to validate signatures and pick up key rotation.
- JWK ToolOIDC Discovery
- JSON Web Token (JWT)
- A compact token format: a header, a JSON payload of claims and a signature, each base64url-encoded and joined by dots. Validation means checking the signature against the issuer's keys and the standard claims, never trusting the header's algorithm blindly.
- JWT DecoderJWT Security Deep Dive
- Just-in-Time (JIT) Access
- Granting privilege only for the duration of a task, with approval and a time limit, instead of leaving it assigned permanently. The practical form of zero standing privilege.
- Just-in-Time Access Simplified
K
- Kerberos
- The ticket-based authentication protocol used inside Active Directory domains. A key distribution centre issues ticket-granting tickets and service tickets; attacks such as Kerberoasting and golden tickets target its trust model.
- Kerberos Deep Dive
L
- LDAP (Lightweight Directory Access Protocol)
- The protocol for querying and modifying directory services. Still how many applications look up users and groups, and the reason LDAP filters and distinguished names remain daily IAM vocabulary.
- LDAP Filter Builder
- Least Privilege
- Granting each identity only the access needed for its task, for only as long as needed. The principle behind PAM, governance, CIEM and zero trust.
- Implementing Least Privilege
M
- Machine Identity
- An identity for a device, workload or service rather than a person: certificates, service accounts, cloud workload identities, SPIFFE IDs. Treated with the same lifecycle and ownership as human identities, in theory.
- Machine identity solutions
- Managed Identity
- A cloud provider's built-in identity for a workload, with credentials the platform issues and rotates so the application never stores a secret. Azure's term; AWS uses IAM roles, GCP uses service accounts attached to resources.
- Multi-Factor Authentication (MFA)
- Requiring two or more independent factors to authenticate. Phishing-resistant methods (passkeys, security keys, certificates) are the goal; push and one-time codes are better than nothing but can be phished.
- MFA Deep DiveOTP Generator
N
- Non-Human Identity (NHI)
- Any identity that is not a person: service accounts, API keys, bots, workloads and AI agents. They outnumber human identities by a wide margin and are usually less governed.
- Non-Human Identity ManagementZero Trust & NHI learning path
O
- OAuth 2.0
- The framework for delegated authorization: a user lets a client application act on their behalf against an API without sharing their password. Defines flows, tokens and endpoints; OpenID Connect adds identity on top.
- OAuth 2.0 Deep Dive
- OpenID Connect (OIDC)
- The identity layer on OAuth 2.0: adds the ID token, the userinfo endpoint and discovery, so a client can learn who signed in. The protocol behind most modern single sign-on.
- OIDC DiscoveryOIDC Deep Dive
P
- Passkey
- A FIDO2 credential synced across a user's devices (or bound to one security key) that replaces the password with a cryptographic challenge, unlocked by the device's biometric or PIN. Phishing-resistant by design.
- Passwordless solutions
- PKCE (Proof Key for Code Exchange)
- An OAuth extension in which the client sends a hashed secret with the authorization request and the original with the token request, so an intercepted authorization code is useless. Required for public clients and recommended for all.
- PKCE Generator
- Principal
- Any entity that can be authenticated and granted access: a user, a group, a service account, a workload. Policies are written about principals.
- Privileged Access Management (PAM)
- Controlling administrative and other high-risk access: vaulting credentials, brokering and recording sessions, rotating secrets and granting elevation just in time. CyberArk, Delinea, BeyondTrust and others.
- PAM solutionsPAM learning path
- Privileged Identity Management (PIM)
- Microsoft Entra's just-in-time elevation feature: users are eligible for roles and activate them for a bounded time with MFA or approval. The same idea other vendors ship as JIT or zero standing privilege.
- Provisioning
- Creating and updating accounts and entitlements in target systems from a source of truth. Done with SCIM for SaaS, connectors for everything else, and by hand where neither exists.
- SCIM Provisioning Explained
R
- Refresh Token
- A long-lived OAuth credential a client exchanges for new access tokens without involving the user again. Rotation (a new refresh token with each use) and revocation are what keep it from becoming a permanent key.
- Relying Party (RP)
- An application that trusts an identity provider to authenticate its users. OpenID Connect's name for the client; SAML calls it the service provider.
- Role-Based Access Control (RBAC)
- Authorization by assigning permissions to roles and roles to people. Simple to reason about and audit; breaks down when roles multiply to match every exception (role explosion).
- RBAC vs ABAC
S
- SAML 2.0
- The XML-based federation standard used for enterprise single sign-on: an identity provider posts a signed assertion to the service provider's assertion consumer service. Older than OIDC, still required by many enterprise applications.
- SAML 2.0 ExplainedSAML Generator
- SCIM (System for Cross-domain Identity Management)
- The REST and JSON standard for provisioning users and groups into applications, so an identity provider can create, update and deactivate accounts automatically.
- SCIM Filter TesterSCIM Provisioning Explained
- Secrets Management
- Storing, distributing and rotating credentials used by software: API keys, database passwords, certificates, tokens. Vaults such as HashiCorp Vault and CyberArk Conjur replace secrets in config files and pipelines.
- Separation of Duties (SoD)
- Rules that keep conflicting permissions apart, so one person cannot both create a vendor and approve its payments. Governance tools detect violations across systems.
- Service Account
- An account used by software rather than a person. Frequently over-privileged, shared, and never rotated; bringing them under ownership and rotation is a core PAM and NHI task.
- Securing service accounts
- Service Provider (SP)
- In SAML, the application that consumes assertions from an identity provider. Equivalent to OIDC's relying party.
- Session
- The state that keeps a user signed in after authentication, usually a cookie bound to server-side state or a signed token. Its lifetime, idle timeout, revocation and binding to the device decide how much a stolen cookie is worth.
- Session Management Deep DiveSession Cookie Analyzer
- Single Sign-On (SSO)
- Authenticating once and reaching many applications without signing in again, by federating them to one identity provider. The user-facing result of SAML or OIDC done well.
- SSO Implementation Guide
- SPIFFE / SPIRE
- An open standard (SPIFFE) and runtime (SPIRE) for giving workloads cryptographic identities, issued automatically from attested properties of where they run, instead of from secrets placed in them.
- Zero Trust Services with SPIFFE and SPIRE
- Step-Up Authentication
- Requiring a stronger factor for a sensitive action within an existing session, such as a passkey before a payment, instead of demanding it for every sign-in.
T
- Token Introspection
- An OAuth endpoint a resource server calls to ask the authorization server whether an opaque token is active and what it carries. The alternative to validating self-contained JWTs locally.
- Introspection Tester
W
- Workforce Identity
- IAM for employees and contractors: directory, SSO, MFA, device trust, lifecycle from HR. Contrast with customer identity, which has different scale and privacy requirements.
- Workforce identity solutions
- Workload Identity Federation
- Letting a workload outside a cloud (a CI pipeline, another cloud) exchange its own token for the cloud's credentials, so no long-lived key has to be stored. OIDC trust between platforms.
Z
- Zero Standing Privilege (ZSP)
- The end state of just-in-time access: no account holds administrative rights permanently; every elevation is requested, bounded and logged.
- Zero standing privilege solutions
- Zero Trust
- A security model that grants access per request based on identity, device and context rather than network location: verify explicitly, use least privilege, assume breach. Identity is its control plane.
- Zero trust solutionsZero Trust & NHI learning path