Learning Hub › Foundational Security › IAM Fundamentals
Foundations 01 · Interactive guide
IAM Fundamentals
Identity and Access Management decides who you are, what you may do, and keeps a record of it. Most breaches start with a stolen or misused identity, so IAM is the first line of defence. This guide goes from the basics to passkeys, RBAC vs ABAC, access reviews and single sign-on, with something to try in every section.
Identify, authenticate, authorise, account
Every access decision walks the same four steps. Click each step to compare a familiar office building with what happens when you sign in to a company app.
Authentication factors and MFA
A factor is something you know, have or are. Multi-factor authentication (MFA) means factors from different categories: a password plus a PIN is still one category. Build a sign-in and see how strong it is.
Pick the factors your sign-in uses
Password check, NIST SP 800-63B-4 style
Runs in your browserThe 2025 NIST rules flipped old advice: length beats complexity, no forced symbol rules, no expiry every 90 days, but block passwords that are common or known to be breached. Nothing you type leaves this page.
Authorisation: RBAC vs ABAC
Role-Based Access Control gives permissions to roles, then people to roles: simple and auditable. Attribute-Based Access Control decides each request from attributes of the user, resource and context: flexible, but harder to audit. Most companies use RBAC with a few ABAC rules on top. The hospital below is fictional.
RBAC: change someone's role
Teaching modelPick a role in the first column. The permissions follow the role, never the person.
ABAC: one request, many attributes
Teaching modelALLOW read on PatientRecord WHEN user.role IN [Nurse, Doctor] AND user.ward == record.ward AND device.managed == true AND (time IN shift OR user.role == Doctor)
Least privilege and the access review
Give each identity only the access it needs, for only as long as it needs it. Access piles up when people change jobs ("privilege creep"), so teams manage the joiner-mover-leaver lifecycle and run periodic access reviews. Try one.
Joiner
New starter gets a birthright role on day one: email, HR portal, team apps. Nothing more.
Mover
Changes team: new role added and old access removed. The removal is the step most often missed.
Leaver
Disable the account and revoke sessions and tokens on the last day, ideally driven automatically by HR.
Single sign-on: SAML, OAuth 2.0 and OpenID Connect
With SSO, one trusted identity provider (IdP) signs you in and vouches for you to many apps. Apps never see your password, and IT can switch off access in one place.
SAML 2.0
Authentication · 2005
XML "assertions" passed through the browser. Still the workhorse for enterprise web apps.
OAuth 2.0
Authorisation · 2012
Lets an app act on your behalf with a limited access token ("read my calendar"). On its own it doesn't say who you are.
OpenID Connect
Authentication · 2014
An identity layer on OAuth 2.0. Adds a signed ID token (a JWT) that says who signed in. The modern default for web and mobile.
Walk through an OIDC sign-in (authorization code flow with PKCE)
This is what happens behind "Sign in with your company account". PKCE stops a stolen authorization code from being useful.
Myth or fact?
Five common beliefs about identity security.
Sources & further reading
- NIST SP 800-63-4: Digital Identity Guidelines
Final 2025 revision. Part B covers authenticators, assurance levels and password rules.
- CISA: Implementing phishing-resistant MFA
Why FIDO2/WebAuthn and PKI beat SMS and push codes.
- FIDO Alliance: Passkeys
How passkeys work, synced and device-bound.
- NIST SP 800-162: Guide to ABAC
Definitions and considerations for attribute-based access control.
- OpenID Connect Core 1.0
With RFC 6749 (OAuth 2.0) and RFC 7636 (PKCE).
- OWASP Authentication Cheat Sheet
Practical guidance for developers building sign-in.
Next: the Zero Trust deep dive puts identity at the centre of every access decision, and Cryptography Basics explains the signatures behind passkeys and ID tokens.