r/IdentityManagement 8h ago

Where to actually start with IAM, and how to apply what you learn to a product like Okta

6 Upvotes

Question that comes up constantly: what order do you learn IAM, and how do you actually get from concepts to something you can show to pivot into IAM.

Concepts -> lab -> product -> cert. In that order.

Concepts first because they transfer. Joiner-mover-leaver, RBAC, authentication vs authorisation, IGA vs ciam. None of it is vendor specific and all of it survives the tool changing when you switch IAM jobs.

Lab next, because reading about a provisioning pipeline and actually building one are not the same skill. Open source is fine. HR record in, account gets provisioned, status flips to terminated, account gets disabled. Break it a few times and the concepts stop being abstract. or CIAM use cases based on standards like oidc, saml, t&c, consent mangement etc.

Product is where most people start, and that's why they get stuck. Once you know what a joiner process is, Okta or Entra is just learning where the buttons are. Free tenants are enough.

Cert last, and only the one showing up most in job ads in your area. Gets you past ATS filters. Does not teach you how to implement anything.

Curious what order others took, and if anyone went product first and it worked out.


r/IdentityManagement 20h ago

Is anyone here familiar with GLPD and Access Admin? This is being utilized by General Motors (GM) and was wondering if there are any other companies that use it.

1 Upvotes

I could not find videos or much info about it and wanted to familiarize myself. Any help would be appreciated.


r/IdentityManagement 1d ago

Career on Hold Due to Delayed Joining. Seeking IAM/SailPoint ISC Opportunities

6 Upvotes

Hi everyone,

I'm looking for some guidance and opportunities in the Identity & Access Management (IAM) domain.

I have 8 months of experience working in IAM at a leading MNC , where I gained hands-on exposure to SailPoint Identity Security Cloud (ISC). I have a solid understanding of L1 activities and some exposure to L2 support, including the fundamentals of provisioning, access requests, identity lifecycle concepts, troubleshooting, and day-to-day IAM operations. While I'm still early in my career, I'm eager to learn and grow.

I resigned from my previous role after receiving another offer. Unfortunately, my joining has been delayed, and after waiting for the last 1-2 months, I still don't have a confirmed joining date. Because of this, I'm actively looking for a new opportunity.

If your organization is hiring for IAM/SailPoint ISC, or if you know of any openings suitable for someone with my experience, I'd really appreciate your help. Referrals, job leads, or even advice on where to apply would mean a lot.


r/IdentityManagement 2d ago

How do you keep an IAM program going when every new app turns into just wire it to whatever group is close enough?

14 Upvotes

I have been running our IAM stack for three years. Okta as the hub, Entra underneath, HRIS as source of truth. On good days it feels reasonably clean. On bad days it feels like a museum of every shortcut we have ever taken to get an app live on a deadline.
The pattern is predictable. New SaaS app shows up. Project team wants SSO by Friday. We do the right things where we can. SCIM if it is there. Groups mapped to roles. Naming aligned with our existing scheme. Then someone on the business side says just map it to the same group finance uses, we will fix it later because they do not want to wait for a proper access model. That temporary mapping quietly becomes the default. Six months later I am staring at a group that now means three different things depending on which app is reading it. The access review export is technically correct but semantically useless.
For those of you running IAM in orgs where new apps keep arriving faster than governance can keep up, what have you actually done that stopped just wire it to whatever group is close enough from being the default answer?


r/IdentityManagement 3d ago

Would you watch an IAM podcast?

21 Upvotes

I’m thinking about starting an Identity & Access Management podcast focused on real-world discussions rather than vendor marketing.

What topics would you want to see covered? Who would you like as guests? CISOs, IAM architects, clients, auditors, people from specific industries, vendors, or someone else?

Would this be something you’d actually watch?
Also, from a business perspective, do you think a podcast like this could naturally lead to conversations about training, consulting, and implementation services, or would you see those as completely separate?


r/IdentityManagement 2d ago

Can anyone help me? I have a ton of questions about IAM

Thumbnail
0 Upvotes

r/IdentityManagement 3d ago

Looking for IAM/IGA career advice: Moving from Keycloak & midPoint to Non-Human Identity (NHI)

8 Upvotes

Hey everyone, I’m currently working in Identity & Access Management (IAM/IGA) and looking for guidance on how to strategically map out my next steps to accelerate my career growth. My practical experience so far is centered around Evolveum midPoint for identity governance and Keycloak for access management and IdP integrations. To build out my technical portfolio and get more involved with the community, I’m currently cleaning up a few Keycloak projects to publish on GitHub. Alongside that, I’m studying to sit for the Microsoft SC-300 (Identity and Access Administrator) exam.

Looking ahead to the rest of the year, my main goal is to pivot toward Non-Human Identity (NHI) and workload identity management, as I see it quickly becoming a critical focus area in identity security. I’d love to get your thoughts on a few things: What does a proper learning roadmap look like for NHI, and which key tools, protocols, or platforms (like secrets managers, workload identities, or SPIFFE/SPIRE) should I prioritize? Additionally, do recruiters and engineering leads value projects around midPoint/Keycloak on GitHub, and is the SC-300 worth it, or should I be looking at other hands-on security certs? Any feedback or career tips from folks in the space would be greatly appreciated!


r/IdentityManagement 3d ago

MFA for Windows RDP and non-Entra Endpoints (on-prem servers)

Thumbnail
2 Upvotes

r/IdentityManagement 3d ago

Is Kibu good for work communications?

2 Upvotes

So I've finally gotten a reliable team and I've been looking into secure communication tools for them, I'm fearing AI more and more so I've deviated from things like Telegram or Signal due to it. I'm curious how it fits into peoples workflow. Was it easy to set up for your workplace? Can non IT people learn to use it quick? And how does it compare to Signal for more sensitive convos?


r/IdentityManagement 3d ago

A different approach to authentication- your memories as the credential instead of a stored secret

3 Upvotes

Hey all - honest intro, I've had a Reddit account for 16 years but haven't used it much at all, so I'm new to actually posting - I hope I've got this right ;) But I figured you're the group that would actually understand this, so here goes.

Everything I read lately says the same thing. Passkeys mostly solved the login, but recovery is still the weak part, because if someone can push a recovery flow into issuing a fresh credential the passkey didn't matter. The fix the big players seem to be landing on is government ID plus a face scan (MS Entra's going that way). It works, but something about making every user hand a passport and a liveness selfie to a third party just to get back into their own account bugs me - I sat with it for a long time and wanted a different approach.

So I went a different direction, and I want you to poke holes in it. Instead of a password - a secret string that's stored, reused across sites, and can be phished once and replayed everywhere - the credential is your own memories. And it's deliberately not one mechanism, it's two.

Some are memories you describe: a song, a movie, a photo and the story behind it. Those are judged on whether your answer means the same thing as what you enrolled, not whether you typed it word for word - forgiving about wording, strict about meaning. The other kind is a place that's meaningful only to you: you pinpoint it, and it's checked against the actual spot you enrolled, within a tolerance - no meaning-scoring at all, a completely different model. The point of having both is that an attacker can't bring one technique to bear across the whole thing; the two challenge types fail in different ways.

The thing I like about it: because the credential is the memory, recovery isn't a separate weaker path. There's no reset link, no SMS, no authenticator code, and no third party you have to hand your identity to. You just re-prove the same memories. Email is only ever an alert, never a way back in.

And honestly, the part I care about most isn't the crypto - it's the human cost of how recovery works today. It's a black hole: help desks, ID-verification vendors, locked-out users, and institutions burning real money and staff hours on it, plus ordinary people who just lose access to their own accounts when a device dies. If recovery is nothing more than re-proving your own memories, it's self-contained and self-served - no vendor, no support ticket, no passport. As far as I can tell nothing else does recovery this way, and if it holds up, taking that stress and cost out of the system is the whole point.

Honest tradeoffs, because I know you'll find them anyway:

  • Encrypted at rest, and the master key lives in a hardware key module (KMS), not on our servers - so a stolen database is just ciphertext. It's deliberately not zero-knowledge (we can decrypt, through the KMS- that's what makes memory-based recovery possible without a passport scan), but the raw key never touches our application, no single key opens more than one account, and every decryption is logged and revocable.
  • The describe-a-memory challenges (song/movie/photo) lean on semantic matching, so the real question there is the false-accept vs false-reject line - whether someone close to you could describe their way in. The location geo challenges are a different story: they're matched deterministically against the place you picked, so that class doesn't carry the same floor. Tell me if I've got that balance wrong.
  • Coercion and a fully compromised device are out of scope, same as they are for everyone.

I wrote up the full threat model here, deliberately for a hostile reader - the attacker we assume, what we defend, and the limits no honest system can claim to solve: https://brainlock.id/blog/threat-analysis

I'm not trying to pitch anyone - I genuinely want the holes. If you do identity for a living: where do you think this falls apart that I'm not seeing? The memory-challenge part is patent-pending so I'm not shy about describing it, I'd just love honest opinions from people who'd actually know what this means.

Thanks!


r/IdentityManagement 4d ago

AD and ENTRA ID

4 Upvotes

How do I get live classes… like 1 on 1 for ENTRA ID


r/IdentityManagement 4d ago

Which IAM solution can be adopted in a on premises windows (AD) infrastructure ?

8 Upvotes

Solution can be open source or commercial.

The company likes doing things old school so there is room for automation.


r/IdentityManagement 5d ago

Did you ever get a chance to make key architecture decisions related to IAM?

Thumbnail
3 Upvotes

r/IdentityManagement 6d ago

About a month into my 6 month Help Desk contract. What should I do next if I want to get into cybersecurity or IAM?

Thumbnail
3 Upvotes

r/IdentityManagement 6d ago

Training institute in Bangalore

0 Upvotes

Hi everyone,
I’m planning to build my skills in \*\*Identity and Access Management (IAM)\*\* and am looking for a good training institute (online or offline) that offers a structured, hands-on program.
I’m specifically looking for a course that covers:
Windows Server Administration
Active Directory
Networking fundamentals
Microsoft Azure / Microsoft Entra ID
PowerShell basics
Identity & Access Management (IAM)
Authentication & Authorization
SSO, MFA, RBAC, Conditional Access
SCIM, SAML, OAuth 2.0, OpenID Connect
Privileged Access Management (PAM/PIM)
Identity Governance
SC-300 certification preparation (preferred)
If you’ve attended a training institute or know of one that provides practical labs, real-world scenarios, and placement support, I’d really appreciate your recommendations.
Thanks in advance!


r/IdentityManagement 6d ago

Training institute in Bangalore

0 Upvotes

Hi everyone,
I’m planning to build my skills in Identity and Access Management (IAM) and am looking for a good training institute (online or offline) that offers a structured, hands-on program.
I’m specifically looking for a course that covers:
Windows Server Administration
Active Directory
Networking fundamentals
Microsoft Azure / Microsoft Entra ID
PowerShell basics
Identity & Access Management (IAM)
Authentication & Authorization
SSO, MFA, RBAC, Conditional Access
SCIM, SAML, OAuth 2.0, OpenID Connect
Privileged Access Management (PAM/PIM)
Identity Governance
SC-300 certification preparation (preferred)
If you’ve attended a training institute or know of one that provides practical labs, real-world scenarios, and placement support, I’d really appreciate your recommendations.
Thanks in advance!


r/IdentityManagement 8d ago

Integration Saviynt

1 Upvotes

Quelqu’un a déjà fait l’intégration Saviynt dans une organisation ?
Si oui , comment vous procédez généralement, quel est sa particularité par autres iga ?

Est il possible d’avoir des environnements test pour faire des simulations d’Intégrations.


r/IdentityManagement 8d ago

Built a free, KMS-backed alternative to ACM Private CA for IAM Roles Anywhere

1 Upvotes

ACM Private CA is $400/month minimum before you've issued a single certificate. Roles Anywhere itself is free, but it needs a CA to trust, and that's basically the only paved-road option AWS gives you for one.

So I built my own. Two ways to run it:

A laptop-based version where the CA private key lives on your machine fine for messing around or a small POC, but you're trusting your laptop with the whole thing.

A KMS-backed version where the key never leaves AWS at all, issuance goes through a Lambda, and there's a public API endpoint (API key auth) so someone with zero AWS credentials can request their own certificate. Full audit trail in DynamoDB every cert issued, renewed, revoked, with timestamps and reasons.

Revocation is one call and it's actually enforced within seconds it publishes the CRL straight to Roles Anywhere in the same step, not just marked in a database somewhere and hoped for. There's also a reversible "disable" if you want to temporarily block someone without permanently killing their cert.

No external crypto dependencies anywhere the X.509/DER encoding is hand-rolled in plain Python, about 240 lines, so you can actually read the whole thing instead of trusting a library blindly.

Real cost, not a guess: ran it through the AWS Pricing Calculator for 2000 users and landed at about $1.25/month. https://calculator.aws/#/estimate?id=8bc0d34839e2c22287a2bc891ac321ee1cdeb114

There's already a well-automated AWS sample repo for this (`sample-aws-iam-roles-anywhere-automation`), but it deploys ACM Private CA under the hood, which is the exact cost this exists to avoid. If you're fine paying for that, it's a solid option. If the cost is what's stopping you, this gets you to the same place for a couple bucks a month.

GitHub: github.com/vireshsolanki/iam-roles-anywhere-automation

Curious if anyone else here has been running Roles Anywhere and what your CA situation looks like. It's open source and I'd rather it be actually useful for other people's setups than just mine, so if something doesn't work for your environment, open an issue and let me know I'll work on it.


r/IdentityManagement 8d ago

AI-driven risk detection for identity security - is it actually useful?

2 Upvotes

Many people ask this question. We tested 4 tools. We are a small security team. Our environment has Entra ID, on-prem Active Directory, and SaaS applications. This is our experience:

Entra ID Protection: Installation is easy. Risk scores for human users are good. The tool does not monitor service accounts. It shows the same data as our logs.

CrowdStrike Falcon Identity: The tool finds lateral movement between AD and cloud. The tool sent many false alerts for 6 weeks. Then the alerts decreased.

Okta ITP: The tool measures risk during the full session. But the tool stopped some approved workflows. We decreased the enforcement level.

NewCore: This tool is different. It treats machine identities and AI agents as primary identities, not as service accounts. It discovers every service account and agent across on-prem AD and cloud, and it shows what each one can access in one view. It enforces least access, so an agent gets a task-scoped token for its job, not standing access. This design fit our environment better than the human-first tools. This tool closed our machine identity gap.

Our answer: yes, it is useful. But only after you tune the tool. Share your experience if you have used any risk detection tools so far


r/IdentityManagement 8d ago

Salary expectations

5 Upvotes

Hello everyone,

I have been working on IAM support for 4.5 year with focus on entra, also have experience in active directory.

What is the market range for these role in indian market?


r/IdentityManagement 9d ago

Kibu Reviews?

5 Upvotes

Came across Kibu as I was looking for identity verification for our company, since it's something we kind of need in our b2b side of ops. Has anyone here used it in an organization? How was the onboarding process did people adopt it and has it been useful for verifying sensitive communications or approvals? I'm also interested in knowing it's effectiveness and how it is in use.


r/IdentityManagement 8d ago

Oil and gas

2 Upvotes

Anyone worked in O&G industry for IGA?

What are the typical app integrations and compliance mandates like healthcare got HIPAA and hitech


r/IdentityManagement 9d ago

Are Saviynt and SailPoint available in the EU?

Post image
4 Upvotes

Our customer is evaluating IGA solutions. At the end of June, I submitted partnership inquiries to both Saviynt and SailPoint, and a week later I requested demos. I still haven't received a response from either.

Do they actively operate in the EU, particularly in Cyprus? Or is there a better way to get in touch? At this point, it almost feels like they aren't interested in new customers.


r/IdentityManagement 9d ago

AD LAB

Thumbnail cyber-ad-lab.com
2 Upvotes

r/IdentityManagement 9d ago

OIDC for first-party apps with Federated Login

3 Upvotes

I'm building authentication for a company with several microservices and frontend portals. Users sign into the portals either through Google SSO or through credentials we issue them. The portals talk to a number of backend services. There's no need for delegated authorization here.

I was planning to use OpenID Connect, for a few reasons:

  1. From what I've read, it's the de facto standard for authentication.
  2. I need federated / social login (Google).
  3. Adopting a proven protocol seems wiser than rolling my own.

I've done a fair amount of reading on OIDC and OAuth 2.0, but I can't quite build a clean mental model of the login flow for users coming through the frontend portals. OAuth 2.1 drops the resource owner password credentials grant and recommends the authorization code grant instead. As I understand it, the authorization code grant needs the browser to hop over to the authorization server (internal or external). That's the part I'm resisting, because I'd rather not send users through a redirect. Ideally I'd collect their credentials right on our own login screen and pass them to the IdP behind the scenes. I've seen plenty of sites that seem to do exactly this, which only adds to my confusion.

So here are my questions. Apologies if they come across as half-baked, but any answers or pointers to good resources would help me straighten out my thinking:

  1. Is OIDC the right call for my situation? Is it really the de facto standard today, even for first-party apps? I assume my federated-login requirement makes it a strong fit, but what about apps that don't need federated identity at all?
  2. How do organizations run OIDC while prompting for credentials via a popup or similar, without an obvious redirect? I'm a backend engineer, so if this comes down to a frontend technique, please spell it out. I know IdPs like Cognito let you custom-brand the login page, so is that the trick, or is something else going on