Read the guides in an order that builds
Each path is a sequence of articles from this site, chosen so that every step uses what the previous one taught. Follow one from the first article to the last; each article shows where you are and what comes next.
IAM Basics
The concepts every other path assumes: what identity and access management is for, how authentication differs from authorization, where directories fit, and the handful of controls (MFA, SSO, least privilege, lifecycle) that every IAM program is built from.
For: People new to identity: students, sysadmins and developers moving into IAM, and managers who need the vocabulary.
Start the pathIdentity Protocols
SAML, OAuth 2.0, OpenID Connect, JWT, SCIM and WebAuthn, in the order they build on each other, with the security details that integration guides leave out.
For: Developers and engineers who integrate applications, debug federation, or secure APIs.
Start the pathIdentity Governance
Identity governance and administration from concepts to deployment: lifecycle automation, access requests, certification campaigns, the product landscape, and the career it leads to.
For: Analysts, engineers and auditors responsible for who has access, whether they should, and proving it.
Start the pathPrivileged Access Management
Privileged access from principles to product: least privilege, vaulting and session control, just-in-time elevation, service accounts and secrets, and how the leading platforms differ.
For: Engineers and security staff who own administrative access, secrets, and the accounts attackers want most.
Start the pathZero Trust and Non-Human Identity
Zero trust as an identity architecture, then the identities it has to cover: workloads, service accounts, cloud entitlements and AI agents, and the detection layer that watches all of them.
For: Architects and senior engineers designing access for cloud, workloads and AI agents, where the perimeter is gone and most identities are not people.
Start the pathReading time assumes about ten minutes per article. New to the vocabulary? Keep the IAM glossary open alongside.