Identity
A fictional user, administrator, service account, application identity, supplier identity, shared process identity, or emergency account represented in an access system.
Review fictional users, suppliers, service accounts, emergency accounts, roles, groups, inherited permissions, approvals, exceptions, business need, activity, and effective access using least privilege and evidence-limited decisions.
Lesson Progress
High School Intermediate • I16: Intermediate Defensive Labs • Lesson 3 of 8
Readiness Check
0/5 ready
Professional Hook
A fictional finance analyst used both invoice-entry and payment-approval permissions during temporary coverage. The activity is real, but the roles remain incompatible. Professional IAM review asks whether the identity is legitimate, whether the current business need supports each entitlement, whether approvals are current, and whether the resulting access creates control conflicts.
Weak access review
Retain access because it was used, review only visible roles, ignore nested groups, renew expired exceptions, and close tickets without validating effective access.
Professional access review
Confirm identity legitimacy, map effective access, validate business need and approvals, identify conflicts, choose a proportionate decision, and verify the final access state.
Objective 1
Define a fictional IAM permission-review scope covering identities, roles, groups, privileged access, service accounts, suppliers, systems, business owners, approvals, exceptions, time windows, and decision authority.
Objective 2
Evaluate fictional access using business need, least privilege, role design, separation of duties, approval history, activity evidence, source health, ownership, expiration, and residual risk.
Objective 3
Distinguish fictional identity status, entitlement status, approval status, activity status, exception status, ownership status, and confirmed misuse.
Objective 4
Choose proportionate fictional access decisions such as retain, reduce, remove, suspend, renew, convert, monitor, investigate, or escalate.
Objective 5
Create a portfolio-safe fictional IAM review package with an identity inventory, entitlement matrix, decision register, exception review, owner communication, validation, metrics, and improvement recommendations.
Why This Matters
Fictional stale access, expired supplier permissions, orphaned identities, excessive roles, shared accounts, service accounts, and emergency accounts can create serious risk even when no misuse is observed. Good IAM review prevents unnecessary capability while preserving valid business and recovery needs.
Core Concept
Identity
Which fictional user, supplier, contractor, service, application, shared, or emergency identity exists, and who owns it?
Need
Which fictional role, task, service, project, supplier agreement, data scope, and time period require access now?
Access
Which fictional direct grants, groups, nested groups, roles, inherited permissions, conditions, and exceptions create effective access?
Control
Which fictional least-privilege, separation-of-duties, approval, expiration, monitoring, session, credential, and review controls apply?
Validation
Which fictional evidence proves the intended access state, service function, owner decision, residual risk, and next review?
Key Vocabulary
A fictional user, administrator, service account, application identity, supplier identity, shared process identity, or emergency account represented in an access system.
A fictional permission, role, group membership, service assignment, data capability, administrative function, or access path granted to an identity.
A fictional bundle of permissions intended for a defined job function or operational responsibility.
A fictional relationship that grants access through a named group rather than through a direct assignment.
Fictional capability that can change security settings, identities, systems, services, data protections, or other high-impact controls.
A fictional nonhuman identity used by an application, automation, scheduled task, integration, or background process.
A fictional documented reason explaining why an identity requires a specific entitlement to perform an approved function.
A fictional principle of granting only the minimum access needed for the approved task and time period.
A fictional control that prevents one identity from controlling incompatible steps such as request, approval, payment, deployment, and review.
The fictional role accountable for deciding who should receive, retain, modify, or lose access to a resource or service.
The fictional role accountable for the identity's lifecycle, employment or supplier status, and continued legitimacy.
A fictional approved deviation from the normal access model with a reason, owner, scope, controls, start time, end time, and review requirement.
A fictional periodic review in which authorized owners confirm, modify, or remove identities and entitlements.
A fictional identity with no valid owner, employment relationship, supplier relationship, application dependency, or documented business need.
A fictional entitlement that is no longer supported by current need, ownership, approval, project status, role, or recent use.
The fictional permissions an identity actually receives after direct assignments, groups, roles, inherited access, conditions, and exceptions are combined.
Identity Inventory
Entitlement
Confidential support-service administrator
Business need
Original support project ended yesterday.
Approval status
Exception expired at 17:00; no renewal is recorded.
Activity evidence
One sign-in and one status-page view after expiration.
Owner
Third-Party Risk Owner and Service Owner
Risk
Unsupported active administrative capability.
Decision
Remove now or replace with a new narrow, time-limited approval if current need is independently confirmed.
Evidence limit
Misuse, configuration change, and data disclosure are not confirmed.
Entitlement
Invoice entry and payment approval
Business need
Invoice entry is required; payment approval belongs to a separate role.
Approval status
Two roles were granted during temporary coverage and never separated.
Activity evidence
Both functions were used during the coverage period.
Owner
Finance Process Owner
Risk
Separation-of-duties conflict.
Decision
Retain invoice entry and remove payment approval after owner confirmation.
Evidence limit
No improper payment or fraud is confirmed.
Entitlement
Project document repository contributor
Business need
Contract ended twelve days ago.
Approval status
No current sponsor or extension exists.
Activity evidence
No activity since contract end.
Owner
Project Owner
Risk
Orphaned identity with unnecessary access.
Decision
Disable the identity and preserve required records.
Evidence limit
No post-contract activity is observed in the supplied source.
Entitlement
Read and write access across backup repositories
Business need
Required for scheduled backup and restore testing.
Approval status
Current service owner and application dependency are documented.
Activity evidence
Matches scheduled jobs only.
Owner
Backup Service Owner
Risk
Broad access is justified but high impact.
Decision
Retain, verify credential rotation, restrict interactive use, and review repository scope.
Evidence limit
The supplied records do not prove every repository remains necessary.
Entitlement
User password reset and privileged group management
Business need
Password reset is required; privileged group management belongs to identity administration.
Approval status
Group-management role was inherited through an old nested group.
Activity evidence
No privileged group change is recorded.
Owner
Identity Operations Owner
Risk
Excessive inherited privilege.
Decision
Remove nested privileged access and validate effective permissions.
Evidence limit
No misuse is confirmed.
Entitlement
Production deployment administrator
Business need
Production deployment is part of the role.
Approval status
Current role approval exists.
Activity evidence
Recent approved deployments match change records.
Owner
Application Delivery Owner
Risk
High-impact access requires strong review and logging.
Decision
Retain with current controls and continue quarterly certification.
Evidence limit
Approval does not prove every future deployment is authorized.
Entitlement
Broad platform administration
Business need
Reserved for service recovery when normal administration is unavailable.
Approval status
Emergency-use procedure is current, but the last quarterly test is overdue.
Activity evidence
No production use in the last quarter.
Owner
Platform Owner and Security Owner
Risk
Critical recovery capability may be unvalidated.
Decision
Retain, perform an approved access test, verify monitoring, and rotate recovery material.
Evidence limit
The account's nonuse does not prove readiness.
Entitlement
Customer analytics dataset reader
Business need
Internship task requires access to a sanitized training dataset only.
Approval status
Current role grants both training and production dataset access.
Activity evidence
Only training dataset access is observed.
Owner
Analytics Data Owner
Risk
Production access exceeds documented need.
Decision
Reduce access to the training dataset and validate effective permissions.
Evidence limit
No production data access is confirmed.
Entitlement
Operations dashboard editor
Business need
The team needs dashboard maintenance capability.
Approval status
The shared model is legacy and lacks individual accountability.
Activity evidence
Recent edits cannot be attributed to one person.
Owner
Operations Service Owner
Risk
Weak accountability and difficult investigation.
Decision
Migrate to individual approved roles and retire the shared identity after validation.
Evidence limit
No harmful edit is confirmed.
Entitlement
Directory read and user-profile update
Business need
The current integration requires read-only directory data.
Approval status
Profile-update permission remains from an older version.
Activity evidence
No profile updates are observed in the review window.
Owner
Integration Owner
Risk
Unused write permission creates unnecessary capability.
Decision
Remove write permission, test the integration, and monitor for failure.
Evidence limit
Longer-term activity may not be fully represented.
Review Questions
Strong review
Confirm fictional employment, supplier, contractor, application, service, emergency, sponsor, and owner status.
Weak review
Assume an active account is valid.
Reviewer question
Who is accountable for this identity today?
Strong review
Compare the fictional role, task, service, project, data scope, supplier agreement, and time period.
Weak review
Retain access because it was approved once.
Reviewer question
Which approved work requires this exact capability now?
Strong review
Review fictional direct grants, groups, nested groups, roles, inherited permissions, conditions, and exceptions.
Weak review
Review only the visible primary role.
Reviewer question
Which hidden path may still grant access after removal?
Strong review
Compare fictional read, write, approve, administer, export, deploy, reset, and emergency capabilities with minimum need.
Weak review
Treat any business need as justification for broad access.
Reviewer question
What can be reduced without preventing the approved task?
Strong review
Identify fictional request, approval, payment, deployment, review, administration, and audit conflicts.
Weak review
Assume trusted users can hold incompatible roles.
Reviewer question
Could one identity complete a sensitive process without independent control?
Strong review
Check fictional approver authority, scope, start, expiration, controls, owner, renewal, and review evidence.
Weak review
Treat an expired exception as current until someone complains.
Reviewer question
What exact record authorizes the access today?
Strong review
Use fictional activity to understand use, nonuse, scheduling, scope, and anomalies without treating nonuse as the only decision factor.
Weak review
Remove every unused permission or retain every recently used permission automatically.
Reviewer question
Does the activity match the approved business purpose?
Strong review
Confirm fictional effective access, service function, owner signoff, exception closure, monitoring, residual risk, and reassessment date.
Weak review
Close the review when the ticket says completed.
Reviewer question
What evidence proves the intended access state now exists?
Decision Types
Use when
The fictional identity, business need, approval, scope, controls, activity, ownership, and review are current.
Fictional example
Retain the production deployment role with current quarterly certification.
Validation
Confirm effective access, change controls, logging, owner signoff, and next review.
Use when
The fictional identity is valid but some permissions exceed current business need.
Fictional example
Reduce the analytics intern to the sanitized training dataset.
Validation
Confirm production access is removed and approved work still functions.
Use when
The fictional entitlement is unsupported, stale, conflicting, inherited unnecessarily, or outside approved scope.
Fictional example
Remove help-desk privileged group management.
Validation
Confirm all direct and inherited access paths are gone.
Use when
The fictional identity itself is no longer legitimate or lacks a valid owner or relationship.
Fictional example
Disable the former contractor identity.
Validation
Confirm sign-in is blocked, sessions are closed, and retention requirements are met.
Use when
The fictional identity requires immediate temporary restriction while facts or authority are confirmed.
Fictional example
Suspend a supplier identity during urgent sponsor validation.
Validation
Confirm restriction, service impact, owner decision, and next review time.
Use when
A fictional expired entitlement remains necessary but requires a new approved scope, owner, duration, and controls.
Fictional example
Issue a new time-limited supplier support approval if current need is confirmed.
Validation
Confirm scope, expiration, monitoring, owner signoff, and automatic review.
Use when
The fictional access model is valid but should move to a safer identity or role design.
Fictional example
Convert a shared operations account to individual approved roles.
Validation
Confirm accountability, service continuity, and shared-account retirement.
Use when
The fictional access or activity cannot be safely decided because evidence, ownership, business context, or effective access remains unclear.
Fictional example
Investigate an unknown nested group before certification.
Validation
Record the evidence gap, owner, deadline, interim control, and final decision.
IAM Review Workflow
Identify fictional identities, systems, services, roles, groups, data, suppliers, time period, owners, privacy, authority, and required decisions.
Output: IAM review charter.
List fictional identity type, lifecycle status, sponsor, owner, role, service, project, supplier, and authentication state.
Output: Identity inventory.
Combine fictional direct grants, groups, nested groups, roles, inherited access, conditions, emergency paths, and exceptions.
Output: Effective-access matrix.
Compare fictional tasks, responsibilities, projects, contracts, data scope, approvals, expirations, exceptions, owners, and separation-of-duties rules.
Output: Need and approval assessment.
Use fictional sign-ins, role use, changes, service activity, schedule, source health, criticality, and potential impact without overclaiming misuse.
Output: Activity and risk findings.
Select fictional retain, reduce, remove, disable, suspend, renew, convert, monitor, investigate, or escalate with owners and deadlines.
Output: Access decision register.
Confirm fictional effective access, session state, service function, owner signoff, exception closure, monitoring, rollback, and residual risk.
Output: Validation record.
Complete fictional certification, communication, metrics, stale-access cleanup, role redesign, automation, training, governance, and next review.
Output: Closure and improvement package.
Fake Dashboard
Training dashboard for fictional identity and permission evidence only.
Identities reviewed
10
Employees, suppliers, contractors, service accounts, emergency accounts, shared identities, and application identities are represented.
Access changes required
7
The fictional set includes removal, reduction, disablement, conversion, renewal review, and assurance actions.
Confirmed misuse
0
The fictional evidence supports control gaps and unnecessary access but no confirmed misuse.
Fake SOC Alert
Source: Fake Northbridge IAM Governance Console • Time: 8:46 PM
Fake Log Panel
08:00 INVENTORY identities='10' 08:08 SUPPLIER exception='expired' 08:16 SUPPLIER sign-in='post-expiration' 08:24 FINANCE sod-conflict='confirmed' 08:32 CONTRACTOR relationship='ended' 08:40 SERVICE account-dependency='current' 08:48 HELPDESK nested-privilege='found' 08:56 CLOUD role-approval='current' 09:04 EMERGENCY test='overdue' 09:12 INTERN production-access='excessive' 09:20 SHARED attribution='weak' 09:28 CONNECTOR write-permission='unused' 09:36 DECISION remove='3' 09:44 DECISION reduce='2' 09:52 DECISION retain-with-controls='3' 10:00 VALIDATION effective-access='pending'
Training note: this is fake data for defensive analysis practice only.
Findings Matrix
Evidence support
Active identity, expired exception, ended project, confidential service scope, one post-expiration sign-in, and no recorded renewal.
Alternate explanation
A legitimate emergency support need may exist but is not documented.
Impact statement
Unsupported capability is confirmed; misuse and disclosure are unconfirmed.
Next action
Remove access now or issue a new narrow time-limited approval after independent owner validation.
Evidence support
Invoice-entry and payment-approval entitlements are both active, while the process owner identifies them as incompatible.
Alternate explanation
A temporary emergency control may justify dual access if documented and independently reviewed.
Impact statement
Control conflict is confirmed; improper payment is unconfirmed.
Next action
Retain invoice entry, remove payment approval, and validate the process.
Evidence support
Contract ended, no current sponsor exists, no extension is approved, and no activity is recorded after the end date.
Alternate explanation
A records-retention or transition task may require a noninteractive archive, not an active identity.
Impact statement
Unnecessary active identity is confirmed; post-contract misuse is not.
Next action
Disable sign-in, preserve required records, close sessions, and document owner confirmation.
Evidence support
Current owner, documented dependency, scheduled activity, business-critical backup function, and expected use pattern.
Alternate explanation
Some repository permissions may no longer be necessary.
Impact statement
High-impact capability is justified; excessive repository scope remains possible.
Next action
Verify rotation, block interactive use, test restore, and review repository scope.
Evidence support
Password-reset need is current, privileged group management is outside the role, and the extra access comes from an old nested group.
Alternate explanation
A temporary identity-administration duty may exist but is not documented.
Impact statement
Excessive access is confirmed; privileged misuse is unconfirmed.
Next action
Remove the nested path and validate effective access.
Evidence support
Current team need exists, but shared use prevents individual attribution and weakens investigation and accountability.
Alternate explanation
A short transition period may be required for service continuity.
Impact statement
Weak accountability is confirmed; harmful changes are unconfirmed.
Next action
Create individual roles, migrate work, validate service function, and retire the shared identity.
Analyze the Evidence
Common Mistakes
Safe Practice Lab
Your fictional assignment
Use only the supplied fictional Northbridge identity and permission records to produce a complete, evidence-limited IAM review package.
Required deliverables
Scenario Decision Lab
The fictional project ended and the exception expired, but the supplier owner cannot immediately confirm whether emergency support remains necessary.
Scenario Decision Lab
The fictional account has a current owner, documented dependency, scheduled activity, and no interactive use, but its repository scope is broad.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Fake IAM Permission Review Package for Northbridge. Include the review charter, identity inventory, effective-access matrix, business-need analysis, approval and exception review, separation-of-duties assessment, activity review, findings, access decision register, owner communication, implementation plan, validation record, residual risk, metrics, improvements, leadership summary, technical summary, reflection, and a portfolio-safety statement.
Key Takeaways
Navigation