High School AdvancedModule A1310 Lessons + Module Test

Advanced Module A13

Identity, Zero Trust, and Access Control

Develop advanced identity strategy across human users, privileged administrators, workloads, applications, external parties, federation, conditional access, least privilege, monitoring, governance, and zero-trust architecture.

The module is defensive and architecture-focused. Every identity record, access decision, log, policy, and scenario is fictional. No real passwords, tokens, accounts, or private identity systems are required.

Module Snapshot

Identity Architecture as a Continuous Security System

Primary purpose

Advanced identity strategy

Core method

Evidence-based access review

Hands-on style

Fictional architecture labs

Portfolio outcome

Enterprise identity and zero-trust review

Main Question

How should an organization decide who or what gets access, under which conditions, for how long, and with what evidence?

Identity security is strongest when the organization can explain the requesting identity, resource, business purpose, privilege, access conditions, approval, lifecycle, owner, monitoring, and review evidence for every important access relationship.

Safety Boundary

Architecture and governance only — no credential attacks or real identity access

This module teaches defensive identity architecture. Do not attempt credential attacks, password guessing, authentication bypass, session hijacking, privilege escalation, token theft, account enumeration, or access to real identity systems. Labs use fictional identities, synthetic policy decisions, safe metadata, and conceptual evidence.

Professional Review Pattern

A Five-Part Module-Level Identity Review

This is a practical review pattern for the module, not a rigid structure every lesson must repeat. Individual lessons will use the models that best fit federation, conditional access, privileged access, monitoring, governance, or usability.

1

Map identities and trust

Identify human, privileged, workload, service, external, and temporary identities plus the resources and trust relationships they depend on.

2

Define access intent

State why access exists, what scope is required, who approves it, what conditions apply, and when the access should end.

3

Evaluate verification and privilege

Review authentication, authorization, federation, contextual policy, least privilege, and privileged-access boundaries.

4

Verify evidence and lifecycle

Check monitoring, source health, access review, ownership, expiration, revocation, and change evidence.

5

Make a governance decision

Classify the design as Confirmed, Conditional, Unknown, Blocked, or Accepted Risk and document the next action.

Learning Outcomes

Six Capabilities You Will Build

1

Explain why identity can function as a security perimeter across humans, workloads, applications, devices, administrators, and external parties.

2

Apply zero-trust principles using explicit verification, least privilege, bounded trust, continuous evidence, and architecture-aware access decisions.

3

Evaluate federation, SSO, conditional access, RBAC, ABAC, privileged access, and service identity designs using purpose, scope, ownership, lifecycle, and evidence.

4

Design identity logging and monitoring that supports authentication, authorization, privileged activity, policy change, lifecycle review, source health, and accountable response.

5

Perform access reviews and governance decisions that distinguish justified access, stale access, exceptions, residual risk, and removal requirements.

6

Produce an Enterprise Identity and Zero-Trust Review that integrates architecture, governance, monitoring, usability, and evidence into one professional portfolio artifact.

Core Architecture Questions

Identity Review Starts With Questions, Not Products

1

Who or what is requesting access?

2

What resource or action is being requested?

3

Why does the access exist?

4

What evidence proves the identity and policy decision are current?

5

How much privilege is actually required?

6

Which conditions should influence the decision?

7

Who owns the identity, resource, and access policy?

8

When should access be reviewed, reduced, revoked, or retired?

Architecture Principles

Eight Ideas That Connect the Whole Module

Identity is more than a username

Identity architecture includes workforce users, administrators, workloads, applications, service identities, external partners, temporary operators, and machine-to-machine trust.

Zero trust is not zero access

Zero trust reduces assumed trust by making access decisions explicit, contextual, least-privileged, observable, and continuously reviewable.

Authentication is not authorization

Proving who or what an identity is does not automatically prove that it should perform a particular action on a particular resource.

Federation shifts trust

Federation can reduce duplicate credentials and improve lifecycle control, but it creates trust relationships that require ownership, evidence, monitoring, and review.

Least privilege is contextual

Appropriate access depends on business purpose, resource, action, environment, time, identity type, and operational responsibility.

Privileged access is exceptional

Administrative capability deserves stronger approval, time limits, monitoring, separation, and post-use evidence.

Evidence must stay current

Access justified months ago may no longer be appropriate after role, service, data, ownership, provider, or architecture changes.

Usability affects security

Controls that are confusing or impractical may create unsafe workarounds, so identity architecture should be strong, understandable, and supportable.

Lesson Roadmap

Ten Advanced Identity Lessons

Each lesson adds one evidence artifact and advances the final Enterprise Identity and Zero-Trust Review.

A13.1Portfolio: Identity Perimeter Map

Identity as a Security Perimeter

Focus

Treat identity as a primary security boundary across users, administrators, workloads, applications, devices, and external parties.

Defensive Lab

Build a fictional identity-perimeter map showing identity types, trust relationships, access paths, resources, owners, lifecycle, and evidence.

Open A13.1
A13.2Portfolio: Zero Trust Principles Assessment

Zero Trust Principles

Focus

Study zero trust as architecture thinking: verify explicitly, minimize assumed trust, apply least privilege, and continuously reassess access.

Defensive Lab

Evaluate a fictional environment against zero-trust principles and identify where trust is assumed instead of supported by current evidence.

Open A13.2
A13.3Portfolio: Federation Trust Register

Federation and Single Sign-On Concepts

Focus

Understand federation, identity providers, relying services, SSO, trust relationships, lifecycle, ownership, and monitoring without handling real credentials.

Defensive Lab

Create a fictional federation trust map with identity providers, relying services, trust purpose, owners, lifecycle, and monitoring evidence.

Open A13.3
A13.4Portfolio: Conditional Access Decision Matrix

Conditional Access and Policy Decisions

Focus

Examine how identity, role, device context, application sensitivity, session context, environment, and business conditions can influence access decisions.

Defensive Lab

Build fictional conditional-access decision records and explain allow, deny, step-up, limited-access, or review outcomes using safe synthetic context.

Open A13.4
A13.5Portfolio: Access Model Comparison

Role-Based and Attribute-Based Access Concepts

Focus

Compare role-based and attribute-based access models through purpose, maintainability, policy complexity, consistency, and least-privilege tradeoffs.

Defensive Lab

Design a fictional access model that combines roles and attributes while keeping authorization decisions understandable and reviewable.

Open A13.5
A13.6Portfolio: Privileged Access Governance Register

Privileged Access Management Concepts

Focus

Study privileged identity separation, approval, time-bounded access, emergency access, monitoring, evidence, and post-use governance.

Defensive Lab

Create a fictional privileged-access register with role purpose, approval, duration, owner, monitoring, evidence, and review status.

Open A13.6
A13.7Portfolio: Identity Monitoring Coverage Matrix

Identity Logging and Monitoring

Focus

Design identity telemetry around authentication, authorization, privileged actions, policy changes, lifecycle events, source health, and alert ownership.

Defensive Lab

Build a fictional identity-monitoring coverage matrix using synthetic events, source-health records, alert ownership, and evidence states.

Open A13.7
A13.8Portfolio: Access Review Decision Register

Access Reviews and Governance

Focus

Evaluate access using purpose, privilege, ownership, lifecycle, evidence freshness, approvals, exceptions, removal decisions, and risk.

Defensive Lab

Run a fictional access-review board using synthetic identity, entitlement, ownership, expiration, and evidence records.

Open A13.8
A13.9Portfolio: Security and Usability Tradeoff Review

Balancing Security and Usability

Focus

Analyze how strong identity controls can remain usable, understandable, supportable, resilient, and proportionate to business risk.

Defensive Lab

Compare fictional access-control designs and recommend the strongest balance between security, usability, supportability, and operational resilience.

Open A13.9
A13.10Portfolio: Enterprise Identity and Zero-Trust Review

Zero Trust Design Lab

Focus

Integrate identity perimeter, zero trust, federation, policy decisions, access models, privileged access, monitoring, governance, and usability.

Defensive Lab

Produce a complete fictional enterprise identity and zero-trust review with evidence, findings, owners, residual risk, and architecture recommendations.

Open A13.10

Fictional Evidence Preview

Northbridge Identity Evidence Package

A13 continues with a fictional Northbridge identity environment. These safe synthetic records provide continuity without using any real identity system or credential.

IDN-01Confirmed

Workforce Identity

Central identity source, named owner, lifecycle review, and current authentication evidence.

IDN-02Conditional

Privileged Administrator

Time-bounded access is active, but one emergency session is awaiting post-use review.

IDN-03Confirmed

Student Portal Workload

Workload identity is scoped to approved application resources and monitored.

IDN-04Conditional

External Support Guest

Sponsor is current, but the next access-review date is approaching.

IDN-05Blocked

Legacy Reporting Account

No current owner, long-lived access, and no acceptable lifecycle evidence.

IDN-06Confirmed

Federated Scheduling Service

Trust purpose, service owner, allowed scope, lifecycle, and monitoring are documented.

Career Connection

Roles That Use These Skills

Identity Security Architect
IAM Engineer
Cloud Security Engineer
Security Operations Analyst
Application Security Engineer
Governance / Risk Analyst

Portfolio Outcome

Enterprise Identity and Zero-Trust Review

By A13.10, you will combine the module evidence into a professional fictional enterprise identity and zero-trust review. The final assessment will explain identity boundaries, trust relationships, policy decisions, privileged access, monitoring, governance, usability, evidence quality, findings, ownership, and recommended architecture decisions.

1.Identity Perimeter Map
2.Zero Trust Principles Assessment
3.Federation Trust Register
4.Conditional Access Decision Matrix
5.Access Model Comparison
6.Privileged Access Governance Register
7.Identity Monitoring Coverage Matrix
8.Access Review Decision Register
9.Security and Usability Tradeoff Review
10.Enterprise Identity and Zero-Trust Review

Module Test

A13 Identity, Zero Trust, and Access Control Test

After all ten lessons, take the 25-question module test covering identity perimeter, zero trust, federation and SSO, conditional access, RBAC and ABAC, privileged access management, identity monitoring, governance, and security-usability tradeoffs.

Module Navigation

Continue the Advanced Track