High School IntermediateModule I68 Lessons + Module Test

Identity and Access Management

Learn how defenders connect identities, accounts, authentication, roles, permissions, sessions, privileged access, lifecycle, monitoring, and business ownership to make safer access decisions.

8

Detailed lessons

1

Integrated lab

25

Module-test questions

1

Portfolio report

Main Question

How can an organization give the right identities the right access for the right reason and duration—while preserving evidence, accountability, privacy, and business function?

Identity and access management is not only about passwords. It combines account ownership, authentication strength, roles, permissions, sessions, device trust, privileged access, lifecycle, monitoring, recertification, and safe remediation.

Safety Boundary

Use Only Fictional, Authorized, Read-Only Identity Evidence

Students do not access real accounts, request credentials, test passwords, bypass MFA, change permissions, create privileged users, inspect private identity data, or use live administrative consoles. Every scenario uses fictional users, devices, applications, sign-ins, roles, groups, tickets, logs, and organizations.

Professional Workflow

Six Steps for Reviewing Identity and Access

1

Identify the subject and resource

Determine which fictional user, service account, device, application, role, group, system, or data resource is involved.

2

Confirm the business need

Record the owner, job or service purpose, requested access, environment, duration, sensitivity, and required outcome.

3

Verify authentication context

Review password, MFA, device, location, session, recovery, conditional-access, and sign-in evidence without overstating identity certainty.

4

Evaluate authorization

Compare roles, groups, permissions, inheritance, exceptions, conflicts, and least-privilege requirements.

5

Validate lifecycle and ownership

Check creation, change, review, inactivity, expiration, transfer, suspension, removal, and accountable ownership.

6

Remediate and monitor

Use narrow approved changes, preserve evidence, prepare rollback, verify business function, monitor, and document residual risk.

Learning Objectives

What You Will Be Able to Do

Objective 1

Explain the difference between identity, account, authentication, authorization, permission, role, session, and access decision.

Objective 2

Evaluate fictional access using business purpose, owner, least privilege, separation of duties, duration, approval, device, and authentication context.

Objective 3

Interpret fictional identity logs without assuming that a successful sign-in proves the physical person, safe intent, or approved later activity.

Objective 4

Identify excessive access, stale accounts, orphaned permissions, risky role combinations, weak recovery, and incomplete monitoring.

Objective 5

Design safe fictional account-lifecycle, privileged-access, access-review, and remediation workflows.

Objective 6

Create a portfolio-ready Identity and Access Review Report supported by traceable evidence and accountable owners.

Module Lessons

Complete All Eight Lessons

I6.1Live

Identity, Authentication, and Authorization

Lesson focus

Build a clear mental model of identity, accounts, authentication, authorization, sessions, trust, and access decisions.

Defensive lab

Analyze fictional sign-in and access evidence to separate who an account claims to be, how access was verified, and what the account was permitted to do.

I6.2Live

Accounts, Roles, and Least Privilege

Lesson focus

Connect users, service accounts, groups, roles, permissions, ownership, business need, and minimum necessary access.

Defensive lab

Review a fictional access matrix and identify excessive, missing, inherited, temporary, and unowned permissions.

I6.3Live

Passwords, MFA, and Authentication Factors

Lesson focus

Understand password controls, MFA, authentication factors, recovery, remembered sessions, device trust, and evidence limitations.

Defensive lab

Compare fictional sign-in sequences and determine which controls were used, which failed, and what remains unknown.

I6.4Live

Access Control Models and Permissions

Lesson focus

Explore role-based, attribute-based, rule-based, discretionary, mandatory, and resource-level access concepts.

Defensive lab

Map fictional access decisions to the correct model and identify where broad permissions or conflicting rules create risk.

I6.5Live

Privileged Access and Administrative Accounts

Lesson focus

Examine administrative identities, privileged roles, elevation, separation of duties, approval, monitoring, and emergency access.

Defensive lab

Evaluate fictional privileged-access requests using owner, purpose, duration, approval, device, MFA, logging, rollback, and review evidence.

I6.6Live

Account Lifecycle and Access Reviews

Lesson focus

Follow accounts through creation, change, transfer, temporary access, inactivity, suspension, removal, and periodic recertification.

Defensive lab

Review a fictional joiner-mover-leaver packet and build an access-remediation plan with owners and due dates.

I6.7Live

Identity Logs and Access Monitoring

Lesson focus

Interpret sign-ins, failures, MFA, lockouts, role changes, group changes, sessions, conditional access, and identity alerts.

Defensive lab

Build a fictional identity timeline and separate expected activity, policy enforcement, suspicious patterns, and evidence gaps.

I6.8Live

Identity and Access Management Lab

Lesson focus

Integrate account, role, authentication, permission, lifecycle, privileged-access, logging, owner, and business evidence.

Defensive lab

Produce a fictional Identity and Access Review Report with confirmed facts, findings, priorities, owners, validation, and residual risk.

Fictional Evidence Preview

Evidence Students Will Learn to Correlate

Identity provider

Fictional sign-in, MFA, session, application, device, location, policy, result, and reason.

Review question

What does the record directly prove, and what does it not prove about the physical user or later activity?

Directory and group membership

Fictional account, role, group, permission, owner, change time, requester, and approver.

Review question

Is the access direct, inherited, role-based, temporary, excessive, missing, or unowned?

Application access

Fictional user, resource, action, result, session, request ID, privilege, and time.

Review question

Was the action permitted, and did the business owner approve that exact level of access?

Lifecycle and ticket records

Fictional joiner, mover, leaver, exception, expiration, recertification, owner, rollback, and validation details.

Review question

Does documented intent match the current technical state?

Portfolio Outcome

Identity and Access Review Report

The final portfolio artifact will evaluate a fictional identity and access environment using traceable evidence, accountable owners, safe recommendations, validation, monitoring, and residual risk.

Executive summary and scope
Identity and account inventory
Authentication and MFA review
Role, group, and permission matrix
Privileged-access review
Lifecycle and access-review findings
Identity monitoring and evidence gaps
Prioritized remediation roadmap
Validation, monitoring, and residual risk
Evidence appendix with traceable fictional records

Module Assessment

I6 Module Test: 25 Questions

The assessment covers identity concepts, authentication, MFA, authorization, roles, permissions, privileged access, account lifecycle, access reviews, identity monitoring, and integrated analysis. Answers remain hidden until revealed.

Open I6 Module Test

Navigation

Begin Module I6