UprootSecurityUprootSecurity

Curriculum · Phase 2

Identity & Access Management

The deepest skill: who can access what, and how you prove it

Identity is the number one audit focus area and the most differentiated skill for GRC Engineers. This phase covers IAM fundamentals, identity providers, SAML/OIDC/OAuth, MFA, AWS/GCP/Azure IAM, PAM, IGA, JIT access, and Zero Trust identity — everything you need to speak fluently about who can access what across any environment.

~8 hours

·

8 modules

·

307 points

Module 2.1

IAM Fundamentals

Authentication vs authorization, the principal/resource model, and how IAM decisions are evaluated under the hood. The foundation everything else in this phase builds on.

33 min

0 / 3

Module 2.2

Identity Providers

How identity providers work, what they centralize, and a comparison of Okta, Microsoft Entra ID, Auth0, and Google Workspace — the four IdPs you will encounter most often in audits and vendor assessments.

28 min

0 / 3

Module 2.3

SAML, OIDC, and OAuth 2.0

The three protocols that power single sign-on and API authorization. Deep dives into SAML 2.0 assertions, OIDC/OAuth flows, and how to choose the right protocol for each use case.

70 min

0 / 4

Module 2.4

Multi-Factor Authentication

MFA factors from SMS to FIDO2, why phishing-resistant MFA is the new baseline, and how to choose the right factor for different user populations and risk levels.

35 min

0 / 3

Module 2.5

AWS IAM

The deepest cloud IAM module: users, roles, policies, SCPs, permission boundaries, policy evaluation logic, and hands-on practice writing IAM policies for real-world scenarios.

100 min

0 / 4

Module 2.6

GCP and Azure IAM

IAM models for Google Cloud and Microsoft Azure: members and roles in GCP, Entra ID and RBAC in Azure, managed identities, Workload Identity Federation, and Conditional Access. Plus an exercise mapping AWS IAM concepts to their GCP and Azure equivalents.

60 min

0 / 3

Module 2.7

PAM, IGA, JIT, and Zero Trust

Advanced identity patterns: privileged access management, identity governance and administration, just-in-time access, and Zero Trust identity principles from NIST 800-207. The concepts that separate a GRC Engineer from a GRC Analyst.

60 min

0 / 3

Module 2.8

Phase 2 Capstone: Identity Architecture Design

Design a complete identity architecture for a mid-size SaaS company. Bring together everything from this phase: IdP selection, SSO, MFA, cloud IAM, service account governance, and access reviews in a single cohesive design document.

60 min

0 / 1

Identity & Access Management — UprootSecurity Bootcamp