Skip to main content
IAMRoadmapIAMRoadmap
Learning paths

Read the guides in an order that builds

Each path is a sequence of articles from this site, chosen so that every step uses what the previous one taught. Follow one from the first article to the last; each article shows where you are and what comes next.

Entry level8 articles · roughly 80 min

IAM Basics

The concepts every other path assumes: what identity and access management is for, how authentication differs from authorization, where directories fit, and the handful of controls (MFA, SSO, least privilege, lifecycle) that every IAM program is built from.

For: People new to identity: students, sysadmins and developers moving into IAM, and managers who need the vocabulary.

Start the path
Intermediate10 articles · roughly 100 min

Identity Protocols

SAML, OAuth 2.0, OpenID Connect, JWT, SCIM and WebAuthn, in the order they build on each other, with the security details that integration guides leave out.

For: Developers and engineers who integrate applications, debug federation, or secure APIs.

Start the path
Intermediate9 articles · roughly 90 min

Identity Governance

Identity governance and administration from concepts to deployment: lifecycle automation, access requests, certification campaigns, the product landscape, and the career it leads to.

For: Analysts, engineers and auditors responsible for who has access, whether they should, and proving it.

Start the path
Intermediate8 articles · roughly 80 min

Privileged Access Management

Privileged access from principles to product: least privilege, vaulting and session control, just-in-time elevation, service accounts and secrets, and how the leading platforms differ.

For: Engineers and security staff who own administrative access, secrets, and the accounts attackers want most.

Start the path
Advanced8 articles · roughly 80 min

Zero Trust and Non-Human Identity

Zero trust as an identity architecture, then the identities it has to cover: workloads, service accounts, cloud entitlements and AI agents, and the detection layer that watches all of them.

For: Architects and senior engineers designing access for cloud, workloads and AI agents, where the perimeter is gone and most identities are not people.

Start the path

Reading time assumes about ten minutes per article. New to the vocabulary? Keep the IAM glossary open alongside.