Entra ID Identity and Access Management
Master Entra ID Identity and Access Management
Design, secure, and defend modern identity systems that stop breaches at the front door. Build Zero Trust identity architectures, enforce least-privilege access, and operationalize enterprise-grade IAM programs across Microsoft 365, Entra ID, and hybrid environments; so you can eliminate identity-based attacks before they happen.
What you'll be able to do
“I really liked how the Identity and Access Management course addressed the realities of hybrid environments rather than just the basic textbook scenario. The sections that focused on breaking down how legacy protocols are abused and actually locking them down without breaking production apps were really helpful.”
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Course Foundations
What Entra ID Identity and Access Management teaches: operationalize a governed identity program where every identity, human and machine, has an owner, a lifecycle, and compliance evidence, using Entra ID Governance, entitlement management, access reviews, and PIM. The lifecycle you'll govern, the program and ADRs you walk away with, and how the course is structured. Start here.
Show 8 lessonsHide lessons
- 0.1IAM0.1 What Identity Governance Actually IsPreview
- 0.2IAM0.2 The Identity Lifecycle in Your TenantPreview
- 0.3IAM0.3 Access Governance Principles. Why Access AccumulatesPreview
- 0.4IAM0.4 Non-Human Identity. The Governance Gap Nobody SeesPreview
- 0.5IAM0.5 The Northgate Engineering ScenarioPreview
- 0.6IAM0.6 Lab Setup and Cost ManagementPreview
- 0.7IAM0.7 Your IAM Program PackagePreview
- 0.8Module SummaryPreview
The foundation every subsequent module builds on. Identity types as governance objects, the data model that drives lifecycle automation, data quality as a governance prerequisite, group architecture as the access assignment mechanism, administrative units and delegation boundaries, licensing for governance features, and a full governance state assessment with the first ADRs and risk register entries.
Show 9 lessonsHide lessons
- 1.1IAM1.1 Identity Types as Governance Objects
- 1.2IAM1.2 The Identity Data Model
- 1.3IAM1.3 Data Quality as a Governance Foundation
- 1.4IAM1.4 Group Architecture for IAM
- 1.5IAM1.5 Administrative Units and Delegation Boundaries
- 1.6IAM1.6 Licensing for Identity Governance
- 1.7IAM1.7 The Governance State Assessment
- 1.8Module Summary
- 1.9Check My Knowledge
Phase 2: User Identities
The operational foundation. How user identities work in Entra ID, the object model, creation process, attributes, extension mechanisms, password policies, authentication method registration, lifecycle states, external identities, and production-scale management. You can't automate what you don't understand manually.
Show 14 lessonsHide lessons
- 2.1IAM2.1 The User Object Model
- 2.2IAM2.2 Creating User Identities
- 2.3IAM2.3 Bulk User Operations
- 2.4IAM2.4 User Attributes and Extension Attributes
- 2.5IAM2.5 Password Policies and Self-Service Password Reset
- 2.6IAM2.6 Authentication Method Registration
- 2.7IAM2.7 User Lifecycle States
- 2.8IAM2.8 External Identities and B2B Guests
- 2.9IAM2.9 User Management at Scale
- 2.10IAM2.10 NE User Identity Design
- 2.11IAM2 Module Lab. User Identity Deployment
- 2.12IAM2 Guided Walkthrough
- 2.13Module Summary
- 2.14Check My Knowledge
Groups are the access assignment mechanism in Entra ID. This module teaches how to design, implement, and govern a group architecture that maps organizational structure to access policy, dynamic groups for automated membership, role-based access for administrative delegation, and governance controls that prevent the sprawl most tenants already have.
Show 14 lessonsHide lessons
- 3.1IAM3.1 Group Strategy as IAM Infrastructure
- 3.2IAM3.2 Dynamic Groups for Automated Access
- 3.3IAM3.3 Dynamic Group Design Patterns
- 3.4IAM3.4 Role-Based Access Design in Entra ID
- 3.5IAM3.5 Custom Role Design
- 3.6IAM3.6 Group Governance
- 3.7IAM3.7 Group-Based Licensing
- 3.8IAM3.8 Group Nesting and Inheritance
- 3.9IAM3.9 Group Access Reviews
- 3.10IAM3.10 NE Group Architecture
- 3.11IAM3.11 Module Lab
- 3.12IAM3.12 Guided Walkthrough
- 3.13Module Summary
- 3.14Check My Knowledge
Phase 3: Authentication & Access
Authentication is how identities prove who they are. This module teaches how to design, implement, and govern an authentication architecture, from MFA registration through passwordless deployment to authentication strength policies that tie method selection to access tiers. You build the authentication layer that Module 5's Conditional Access policies will enforce.
Show 13 lessonsHide lessons
- 4.1IAM4.1 The Authentication Landscape
- 4.2IAM4.2 MFA Registration and Enforcement
- 4.3IAM4.3 FIDO2 Security Keys
- 4.4IAM4.4 Windows Hello for Business
- 4.5IAM4.5 Certificate-Based Authentication
- 4.6IAM4.6 Temporary Access Pass and Microsoft Authenticator
- 4.7IAM4.7 Authentication Strength Policies
- 4.8IAM4.8 Method Registration Policies
- 4.9IAM4.9 NE Authentication Architecture
- 4.10IAM4.10 Module Lab
- 4.11IAM4.11 Guided Walkthrough
- 4.12Module Summary
- 4.13Check My Knowledge
Conditional Access is the access policy engine that enforces every authentication and access decision in your tenant. This module teaches how to design, implement, and govern a Conditional Access architecture, from policy structure and risk-based evaluation through session management to the governance cadences that prevent policy sprawl. You build the access control layer that connects Module 4's authentication strengths to the resources they protect.
Show 14 lessonsHide lessons
- 5.1IAM5.1 Conditional Access as the Access Policy Engine
- 5.2IAM5.2 Policy Design Principles
- 5.3IAM5.3 Risk-Based Policies
- 5.4IAM5.4 CA for Guest and External Identities
- 5.5IAM5.5 CA Templates and Common Patterns
- 5.6IAM5.6 Session Management
- 5.7IAM5.7 Report-Only Mode and Impact Analysis
- 5.8IAM5.8 CA Governance
- 5.9IAM5.9 Token Protection and Token Lifetime
- 5.10IAM5.10 NE Conditional Access Architecture
- 5.11IAM5.11 Module Lab
- 5.12IAM5.12 Guided Walkthrough
- 5.13Module Summary
- 5.14Check My Knowledge
Phase 4: Apps & Workload Identities
Application access as an identity discipline rather than an app problem: OAuth consent fundamentals, consent policy design, reviewing what has already been granted, and governing the service principals that hold permissions nobody reviews.
Show 14 lessonsHide lessons
- 6.1IAM6.1 Application Access as an IAM Discipline
- 6.2IAM6.2 OAuth Consent Fundamentals
- 6.3IAM6.3 Consent Policy Design
- 6.4IAM6.4 Reviewing Granted Permissions
- 6.5IAM6.5 SaaS-to-SaaS Integration Risk
- 6.6IAM6.6 App Governance in Defender for Cloud Apps
- 6.7IAM6.7 SCIM Provisioning to SaaS Applications
- 6.8IAM6.8 Application Access Reviews
- 6.9IAM6.9 Application Risk Classification
- 6.10IAM6.10 NE Application Access Governance
- 6.11IAM6.11 Module Lab
- 6.12IAM6.12 Guided Walkthrough
- 6.13Module Summary
- 6.14Check My Knowledge
Build a governance framework for the non-human identities that outnumber your users, hold broader permissions, and operate without any of the controls you built in Modules 1–6.
Show 14 lessonsHide lessons
- 7.1IAM7.1 The Non-Human Identity Problem
- 7.2IAM7.2 App Registration vs Service Principal
- 7.3IAM7.3 App Registration Inventory and Classification
- 7.4IAM7.4 Credential Governance. Secrets
- 7.5IAM7.5 Credential Governance. Certificates
- 7.6IAM7.6 Permission Analysis and Right-Sizing
- 7.7IAM7.7 Consent Grant Analysis
- 7.8IAM7.8 Service Principal Lifecycle Governance
- 7.9IAM7.9 First-Party vs Third-Party App Governance
- 7.10IAM7.10 NE Service Principal Governance
- 7.11IAM7.11 Module Lab
- 7.12IAM7.12 Guided Walkthrough
- 7.13Module Summary
- 7.14Check My Knowledge
Govern the identities that have no credentials to steal, no passwords to rotate, and no human to blame, managed identities, workload identity federation, and the AI agents that are accumulating permissions in your tenant right now.
Show 14 lessonsHide lessons
- 8.1IAM8.1 Managed Identity Architecture
- 8.2IAM8.2 System-Assigned vs User-Assigned Design
- 8.3IAM8.3 Workload Identity Federation
- 8.4IAM8.4 Workload Identity in Conditional Access
- 8.5IAM8.5 Workload Identity Permissions and Monitoring
- 8.6IAM8.6 The AI Agent Identity Model
- 8.7IAM8.7 Agent Identity Blueprints and Sponsor Accountability
- 8.8IAM8.8 Agent Permission and Access Governance
- 8.9IAM8.9 Agent Risk Detection and Lifecycle
- 8.10IAM8.10 NE Workload and AI Agent Design
- 8.11IAM8.11 Module Lab
- 8.12IAM8.12 Guided Walkthrough
- 8.13Module Summary
- 8.14Check My Knowledge
Phase 5: Privileged Access & Delegation
How privileged access is governed and who manages the governance. PIM design, role governance, emergency access, administrative units, scoped roles, and delegation architecture, taught together because they're operationally inseparable.
Show 14 lessonsHide lessons
- 9.1IAM9.1 PIM as the Privileged Access Lifecycle
- 9.2IAM9.2 Role Assignment Governance
- 9.3IAM9.3 PIM Policy Design by Governance Tier
- 9.4IAM9.4 PIM for Groups and Application Roles
- 9.5IAM9.5 Emergency Access Governance
- 9.6IAM9.6 Privileged Access Reviews
- 9.7IAM9.7 Delegation Architecture
- 9.8IAM9.8 Administrative Unit Design Patterns
- 9.9IAM9.9 Delegated Governance Operations
- 9.10IAM9.10 NE Privileged Access and Delegation Design
- 9.11IAM9.11 Module Lab
- 9.12IAM9.12 Guided Walkthrough
- 9.13Module Summary
- 9.14Check My Knowledge
Phase 6: Identity Governance & Lifecycle
How identities are provisioned, moved, and deprovisioned across your M365 environment. Inbound provisioning architecture, lifecycle workflows for joiner-mover-leaver automation, guest identity lifecycle, custom workflow extensions, provisioning monitoring, and tenant-level governance configuration.
Show 14 lessonsHide lessons
- 10.1IAM10.1 Inbound Provisioning Architecture
- 10.2IAM10.2 Lifecycle Workflows. Joiner
- 10.3IAM10.3 Lifecycle Workflows. Mover
- 10.4IAM10.4 Lifecycle Workflows. Leaver
- 10.5IAM10.5 Legal Hold, Delayed Deprovisioning, and Rehire
- 10.6IAM10.6 Custom Workflow Extensions
- 10.7IAM10.7 Guest Identity Lifecycle
- 10.8IAM10.8 Provisioning Monitoring and Troubleshooting
- 10.9IAM10.9 Tenant Configuration for Identity Governance
- 10.10IAM10.10 Northgate Engineering Lifecycle Architecture
- 10.11IAM10.11 Module Lab
- 10.12IAM10.12 Guided Walkthrough
- 10.13Module Summary
- 10.14Check My Knowledge
The access request engine: catalog architecture, access package design, approval workflows, and the lifecycle policies that expire access without anybody having to remember.
Show 14 lessonsHide lessons
- 11.1IAM11.1 Entitlement Management as the Access Request Engine
- 11.2IAM11.2 Catalog Architecture
- 11.3IAM11.3 Access Package Design
- 11.4IAM11.4 Approval Workflows
- 11.5IAM11.5 Auto-Assignment Policies
- 11.6IAM11.6 Incompatible Access Packages
- 11.7Time-Bound Access and Recertification
- 11.8External Access via Entitlement Management
- 11.9Non-Human Identities in Entitlement Management
- 11.10NE Entitlement Management Design
- 11.11Module Lab
- 11.12Guided Walkthrough
- 11.13Module Summary
- 11.14Check My Knowledge
Why access reviews fail, and the design that stops them rubber-stamping: scope and targeting, choosing reviewers and cadence, automation and recommendations, and acting on the outcome.
Show 14 lessonsHide lessons
- 12.1IAM12.1 Why Access Reviews Fail
- 12.2IAM12.2 Access Review Design. Scope and Targeting
- 12.3IAM12.3 Access Review Design. Reviewers and Cadence
- 12.4IAM12.4 Review Automation and AI Recommendations
- 12.5IAM12.5 Guest and External Access Reviews
- 12.6IAM12.6 PIM Access Reviews
- 12.7IAM12.7 Application Access Reviews
- 12.8IAM12.8 Access Review Remediation
- 12.9IAM12.9 Building a Review Program
- 12.10IAM12.10 NE Access Review Program
- 12.11Module Lab
- 12.12Guided Walkthrough
- 12.13Module Summary
- 12.14Check My Knowledge
Identity monitoring as an IAM function rather than a SOC one: stale identities, permission creep, credential health, and the evidence a compliance conversation actually needs.
Show 14 lessonsHide lessons
- 13.1IAM13.1 Identity Monitoring as an IAM Function
- 13.2IAM13.2 Stale Identity Detection
- 13.3IAM13.3 Permission Creep Detection
- 13.4IAM13.4 Credential Health Monitoring
- 13.5IAM13.5 KQL Queries for IAM Operations
- 13.6IAM13.6 IAM Dashboards and Reporting
- 13.7IAM13.7 Compliance Framework Mapping
- 13.8IAM13.8 Automated Evidence Collection
- 13.9IAM13.9 IAM Maturity Roadmap
- 13.10IAM13.10 NE Monitoring and Compliance
- 13.11Module Lab
- 13.12Guided Walkthrough
- 13.13Module Summary
- 13.14Check My Knowledge
Phase 7: Capstone
Assembling the program: coherence across every control built so far, the risk register, the architecture decision portfolio, and the deliverable that survives your departure.
Show 15 lessonsHide lessons
- 14.1IAM14.1 IAM Program Assembly
- 14.2IAM14.2 Program Coherence Review
- 14.3IAM14.3 Risk Register Finalization
- 14.4IAM14.4 ADR Portfolio Review
- 14.5IAM14.5 CISO Challenge Simulation
- 14.6IAM14.6 IT Director Challenge Simulation
- 14.7IAM14.7 Audit Challenge Simulation
- 14.8IAM14.8 Operational Cadence Finalization
- 14.9IAM14.9 Executive Summary
- 14.10IAM14.10 Program Maintenance Plan
- 14.11IAM14.11 The Learner's Own Environment
- 14.12IAM14.12 Course Completion and Next Steps
- 14.13IAM14.13 Guided Walkthrough
- 14.14Module Summary
- 14.15Check My Knowledge
Phase 0: Course Resources
The commands and queries behind every IAM domain in the course, with what each answer decides and what it leaves open.
Show 14 lessonsHide lessons
- 1The Identity Data Model
- 2User Identity Operations
- 3Groups and Role-Based Access
- 4Authentication Methods
- 5Conditional Access
- 6Application Access and Consent
- 7Service Principal Governance
- 8Workload and Agent Identity
- 9Privileged Access and Delegation
- 10Lifecycle Operations
- 11Entitlement Management
- 12Access Reviews
- 13Monitoring and Compliance
- 14Cadences, Thresholds and Graph Reference
Ordered procedures for the identity work that recurs: onboarding at scale, offboarding properly, tightening consent, and cleaning up what accumulated.
Building a tenant with a population messy enough to behave like a real directory, where you can break governance safely.
Identity work reasoned end to end, including the cases where the number everybody quoted was wrong and the ones that end in doing nothing.
What to do when something fires or somebody asks: a compromised account, a stalled pipeline, an urgent access request, a departure, an audit.
Every practice surface available for this course, what each one gives you, and where the gaps are.
Microsoft documentation, security frameworks, compliance standards, threat intelligence, and vendor references used throughout the IAM course.
Course Completion
Entra ID Identity and Access Management end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.
Show 1 lessonHide lessons
Course overview
The Entra ID Identity and Access Management course is built specifically for Security Engineers, Microsoft 365 Administrators, Identity Engineers, and IT Leaders responsible for designing, operating, and defending identity programs. You'll gain hands-on expertise to:
By the end, you'll have the practical skills and strategic mindset to become the go-to identity defender who dramatically reduces risk, simplifies operations, and strengthens your entire organization's security posture.
How this course works
IAM is a governance discipline that happens to be implemented in a directory. This course runs the same loop for every access surface it governs.
1. Model the access before configuring it. Groups, roles and their nesting decide who can reach what long after anybody remembers why. Architecture first, then the objects.
2. Grant through a process that leaves a record. Access packages and entitlement management exist so a grant has a requester, an approver and an expiry rather than a memory.
3. Govern the identities with no human behind them. Service principals, workload identities and agent identities accumulate permissions and never leave the organization.
4. Review access as if the reviewer is busy. A review nobody can complete honestly gets rubber-stamped, and a rubber-stamped review is worse than none because it produces evidence of diligence.
5. Monitor for what governance misses. Stale identities, permission creep and credential health, measured rather than assumed.
The course closes by assembling the complete program: the controls, the risk register and the decision record that survives your departure.
What this course assumes
No minimum experience and no prerequisite course. The Entra object model, the governance features and the licensing that gates them are explained where they first matter.
What makes it go faster: a tenant with Entra ID P2, since most governance features are gated behind it. Not required, and the course states plainly which controls need which tier.
What this course does not cover: identity attack detection and incident response, which are separate courses, and directory administration. This is governance.
Who this course is for
You're a Security Engineer, Microsoft 365 Administrator, Identity Engineer, or IT Leader who designs, operates, and defends identity programs. This course is built for you if you want to:
In short: if you're ready to own the identity layer and dramatically strengthen your organization's security posture, this course is for you.
What you'll learn
By the end of this Entra ID Identity and Access Management course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches identity and access management from first principles. Familiarity with Entra ID and the Microsoft 365 admin center will help you move faster through the early modules, but neither is required. Every concept is explained at first use.
What are the device requirements?
A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) with an Entra ID Governance trial license for hands-on governance configuration. The course walks you through tenant setup in Module 0.
How will the course benefit your career?
Identity is the primary attack surface in modern environments. Organizations need people who can design and operate identity programs, not just manage user accounts. This course gives you the skills to architect Zero Trust identity infrastructure, govern non-human identities, automate lifecycle operations, and produce compliance evidence on demand.
The demand for identity engineers and architects continues to grow as organizations move from basic Entra ID administration to full identity governance programs that cover users, applications, workload identities, and AI agents.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy configurations, governance frameworks, scripts, and policies in your production environment. You may not redistribute course content or share account credentials.
Governance configurations: Test every configuration in a non-production tenant before production. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.