Course overview
Most breaches do not start with exotic malware. They start with a login: a stolen password, an over-privileged account, or access that was never revoked when someone left. Identity and access management, or IAM, is the discipline of controlling who can reach what, and it has become the front line of security precisely because attackers find it easier to log in than to break in.
This course, held at EuroQuest International Training, covers IAM as a working practice: how identities are authenticated and authorized, how access is granted and removed across the employee life cycle, and how the whole system is governed and audited. Named protocols and standards are treated as educational subject matter; the course builds practical judgment and does not certify a product or an individual.
Why identity became the perimeter
When applications and data lived inside a corporate network, the firewall was the boundary. Now that work happens across cloud services and remote devices, that boundary has dissolved, and identity is what remains to control access. Getting IAM right, with strong authentication and least privilege, is what a zero-trust approach depends on, which is developed further in Zero Trust Security Framework Implementation.
What you will be able to do afterwards
By the end of the course, participants will be able to:
- Apply authentication and authorization best practices
- Enforce least-privilege access
- Manage the full identity life cycle
- Meet compliance and audit expectations
- Design an IAM approach that scales
Course outline
Unit 1: Fundamentals of identity and access management
- Identity, authentication, and authorization defined.
- The principle of least privilege.
- Role-based and attribute-based access control.
- Directory services and identity stores.
Unit 2: Authentication and authorization best practices
- Multi-factor authentication and its methods.
- Single sign-on with SAML, OAuth 2.0, and OpenID Connect.
- Passwordless and adaptive authentication.
- Privileged access management (PAM).
Unit 3: Identity lifecycle management
- Joiner, mover, and leaver processes.
- Automated provisioning and deprovisioning with SCIM.
- Access reviews and recertification.
- Managing service and machine identities.
Unit 4: Compliance, auditing, and risk management
- Identity governance and administration (IGA).
- Segregation of duties and toxic combinations.
- Audit trails and access reporting.
- Aligning with ISO 27001 and NIST guidance.
Unit 5: Building scalable IAM strategies
- IAM architecture across cloud and on-premises.
- Federation and managing external identities.
- Balancing security with user experience.
- Building an IAM roadmap.
How the course is delivered
The course is delivered through facilitated discussion, worked examples, and documented case studies of IAM deployments and breaches, with structured analysis of access-control decisions. It builds practical judgment and is educational; it does not certify a product, standard, or individual.
Who should attend
The course suits security and IT professionals, identity and access administrators, system architects, and managers responsible for access control and governance. Those building a broader security capability will find Building a Cybersecurity Strategy for Enterprises a useful companion.
About EuroQuest International Training
EuroQuest International Training, founded in 2015 and headquartered in Bratislava, delivers professional courses to more than 15,000 participants across over 1,000 titles, in cities including Dubai, London, Barcelona, Istanbul, Vienna, Paris, and Geneva, led by experienced practitioners.
Frequently asked questions
Do I need to know how to code?
No. The course explains protocols such as SAML and OAuth conceptually, focusing on how to design and govern access. It suits administrators and managers, not only engineers.
Does the course include a live lab?
It uses guided walkthroughs and documented cases rather than a formal technical lab. You work through access-control and life-cycle scenarios so the focus stays on sound design and governance.
Is it tied to a specific IAM product?
No. It is vendor-neutral and treats named protocols and standards as educational subject matter, so the principles apply whichever identity platform your organization uses.
Related courses
- ISO 27001: Information Security Risk Management
- Cloud Security and Data Protection Strategies
- Building a Cybersecurity Strategy for Enterprises
- Data Privacy and Information Security Compliance
Register for this course
To reserve a place or ask about dates and in-house delivery, contact EuroQuest International Training and our team will help you arrange the details.
All Course Dates & Locations
30 dates · 15 cities · Sep 2026 – Jun 2027