Entra ID Identity and Access Management

Master Entra ID Identity and Access Management

Design, secure, and defend modern identity systems that stop breaches at the front door. Build Zero Trust identity architectures, enforce least-privilege access, and operationalize enterprise-grade IAM programs across Microsoft 365, Entra ID, and hybrid environments; so you can eliminate identity-based attacks before they happen.

Included with Specialist, from $29/month, or $289/year and save 25%. Preview the first module free, no account needed.
Practice included: scored investigation scenarios, plus the Practice Hub.
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Design and implement enterprise-grade identity architectures using Microsoft Entra ID, Conditional Access, and Privileged Identity Management (PIM)
✓Enforce Zero Trust access policies that eliminate standing privileges and block modern identity attacks at the source
✓Protect against password spray, MFA fatigue, token theft, and account takeover across Microsoft 365 and hybrid environments
✓Operationalise Identity Governance, lifecycle workflows, and automated access reviews at scale
✓Rapidly investigate and respond to identity-based threats using Entra ID and Defender for Identity insights
✓Build and defend a least-privilege identity program that measurably reduces risk for your entire organization
What students say about this course

“I really liked how the Identity and Access Management course addressed the realities of hybrid environments rather than just the basic textbook scenario. The sections that focused on breaking down how legacy protocols are abused and actually locking them down without breaking production apps were really helpful.”

Ajay
ARC502 | Specialist tier | 15 modules across 7 phases | 36–40 hours at your own pace | 40 CPE credits | 20+ ADRs

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Course Foundations

Module 0Course OrientationCourse Preview

What Entra ID Identity and Access Management teaches: operationalize a governed identity program where every identity, human and machine, has an owner, a lifecycle, and compliance evidence, using Entra ID Governance, entitlement management, access reviews, and PIM. The lifecycle you'll govern, the program and ADRs you walk away with, and how the course is structured. Start here.

Show 8 lessonsHide lessons
  1. 0.1IAM0.1 What Identity Governance Actually IsPreview
  2. 0.2IAM0.2 The Identity Lifecycle in Your TenantPreview
  3. 0.3IAM0.3 Access Governance Principles. Why Access AccumulatesPreview
  4. 0.4IAM0.4 Non-Human Identity. The Governance Gap Nobody SeesPreview
  5. 0.5IAM0.5 The Northgate Engineering ScenarioPreview
  6. 0.6IAM0.6 Lab Setup and Cost ManagementPreview
  7. 0.7IAM0.7 Your IAM Program PackagePreview
  8. 0.8Module SummaryPreview
Module 1The Entra ID Identity Ecosystem

The foundation every subsequent module builds on. Identity types as governance objects, the data model that drives lifecycle automation, data quality as a governance prerequisite, group architecture as the access assignment mechanism, administrative units and delegation boundaries, licensing for governance features, and a full governance state assessment with the first ADRs and risk register entries.

Show 9 lessonsHide lessons
  1. 1.1IAM1.1 Identity Types as Governance Objects
  2. 1.2IAM1.2 The Identity Data Model
  3. 1.3IAM1.3 Data Quality as a Governance Foundation
  4. 1.4IAM1.4 Group Architecture for IAM
  5. 1.5IAM1.5 Administrative Units and Delegation Boundaries
  6. 1.6IAM1.6 Licensing for Identity Governance
  7. 1.7IAM1.7 The Governance State Assessment
  8. 1.8Module Summary
  9. 1.9Check My Knowledge

Phase 2: User Identities

Module 3Group Architecture and Role-Based Access

Groups are the access assignment mechanism in Entra ID. This module teaches how to design, implement, and govern a group architecture that maps organizational structure to access policy, dynamic groups for automated membership, role-based access for administrative delegation, and governance controls that prevent the sprawl most tenants already have.

Show 14 lessonsHide lessons
  1. 3.1IAM3.1 Group Strategy as IAM Infrastructure
  2. 3.2IAM3.2 Dynamic Groups for Automated Access
  3. 3.3IAM3.3 Dynamic Group Design Patterns
  4. 3.4IAM3.4 Role-Based Access Design in Entra ID
  5. 3.5IAM3.5 Custom Role Design
  6. 3.6IAM3.6 Group Governance
  7. 3.7IAM3.7 Group-Based Licensing
  8. 3.8IAM3.8 Group Nesting and Inheritance
  9. 3.9IAM3.9 Group Access Reviews
  10. 3.10IAM3.10 NE Group Architecture
  11. 3.11IAM3.11 Module Lab
  12. 3.12IAM3.12 Guided Walkthrough
  13. 3.13Module Summary
  14. 3.14Check My Knowledge

Phase 3: Authentication & Access

Module 4Authentication Methods and Passwordless

Authentication is how identities prove who they are. This module teaches how to design, implement, and govern an authentication architecture, from MFA registration through passwordless deployment to authentication strength policies that tie method selection to access tiers. You build the authentication layer that Module 5's Conditional Access policies will enforce.

Show 13 lessonsHide lessons
  1. 4.1IAM4.1 The Authentication Landscape
  2. 4.2IAM4.2 MFA Registration and Enforcement
  3. 4.3IAM4.3 FIDO2 Security Keys
  4. 4.4IAM4.4 Windows Hello for Business
  5. 4.5IAM4.5 Certificate-Based Authentication
  6. 4.6IAM4.6 Temporary Access Pass and Microsoft Authenticator
  7. 4.7IAM4.7 Authentication Strength Policies
  8. 4.8IAM4.8 Method Registration Policies
  9. 4.9IAM4.9 NE Authentication Architecture
  10. 4.10IAM4.10 Module Lab
  11. 4.11IAM4.11 Guided Walkthrough
  12. 4.12Module Summary
  13. 4.13Check My Knowledge
Module 5Conditional Access Architecture

Conditional Access is the access policy engine that enforces every authentication and access decision in your tenant. This module teaches how to design, implement, and govern a Conditional Access architecture, from policy structure and risk-based evaluation through session management to the governance cadences that prevent policy sprawl. You build the access control layer that connects Module 4's authentication strengths to the resources they protect.

Show 14 lessonsHide lessons
  1. 5.1IAM5.1 Conditional Access as the Access Policy Engine
  2. 5.2IAM5.2 Policy Design Principles
  3. 5.3IAM5.3 Risk-Based Policies
  4. 5.4IAM5.4 CA for Guest and External Identities
  5. 5.5IAM5.5 CA Templates and Common Patterns
  6. 5.6IAM5.6 Session Management
  7. 5.7IAM5.7 Report-Only Mode and Impact Analysis
  8. 5.8IAM5.8 CA Governance
  9. 5.9IAM5.9 Token Protection and Token Lifetime
  10. 5.10IAM5.10 NE Conditional Access Architecture
  11. 5.11IAM5.11 Module Lab
  12. 5.12IAM5.12 Guided Walkthrough
  13. 5.13Module Summary
  14. 5.14Check My Knowledge

Phase 4: Apps & Workload Identities

Phase 6: Identity Governance & Lifecycle

Phase 0: Course Resources

ResourcesCookbooks

Ordered procedures for the identity work that recurs: onboarding at scale, offboarding properly, tightening consent, and cleaning up what accumulated.

Show 7 lessonsHide lessons
  1. 1Offboarding Somebody Properly
  2. 2Tightening Consent Without Breaking Work
  3. 3Fixing the Attribute Data
  4. 4Cleaning Up the Guests
  5. 5Rolling Out PIM
  6. 6Building a Review Program That Works
  7. 7Responding to a Compromised Identity
ResourcesLab Setup

Building a tenant with a population messy enough to behave like a real directory, where you can break governance safely.

Show 5 lessonsHide lessons
  1. 1The Tenant and What It Carries
  2. 2Building a Directory That Misbehaves
  3. 3Applying Governance and Watching It Miss
  4. 4Breaking It on Purpose
  5. 5Verify, Delays, and What the Lab Cannot Teach
ResourcesWalkthroughs

Identity work reasoned end to end, including the cases where the number everybody quoted was wrong and the ones that end in doing nothing.

Show 6 lessonsHide lessons
  1. 1The Coverage Number That Was Wrong
  2. 2The Reviews That Certified Nothing
  3. 3The Group That Was Missing Nine People
  4. 4The Access Request That Should Be Refused
  5. 5The Cleanup That Would Have Broken Payroll
  6. 6The Compromise That Was Not One
ResourcesPlaybooks

What to do when something fires or somebody asks: a compromised account, a stalled pipeline, an urgent access request, a departure, an audit.

Show 7 lessonsHide lessons
  1. 1A Risky Sign-In Fires
  2. 2The Provisioning Pipeline Has Stopped
  3. 3Somebody Needs Access Now
  4. 4An Urgent Departure
  5. 5An Auditor Wants Evidence
  6. 6A Change Locked People Out
  7. 7A Supplier Has Been Breached
ResourcesPlayground

Every practice surface available for this course, what each one gives you, and where the gaps are.

ResourcesReferences & Further Reading

Microsoft documentation, security frameworks, compliance standards, threat intelligence, and vendor references used throughout the IAM course.

Course Completion

CompletionCourse Exam

Entra ID Identity and Access Management end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Entra ID Identity and Access Management

Course overview

The Entra ID Identity and Access Management course is built specifically for Security Engineers, Microsoft 365 Administrators, Identity Engineers, and IT Leaders responsible for designing, operating, and defending identity programs. You'll gain hands-on expertise to:

✓ Architect and implement secure authentication, authorization, and access control at scale
✓ Deploy Conditional Access, Privileged Identity Management (PIM), Identity Governance, and lifecycle workflows in Microsoft Entra ID
✓ Protect against modern identity threats including password spray, MFA fatigue, token theft, and account takeover
✓ Build Zero Trust identity strategies that hold across cloud, hybrid, and on-prem environments

By the end, you'll have the practical skills and strategic mindset to become the go-to identity defender who dramatically reduces risk, simplifies operations, and strengthens your entire organization's security posture.

How this course works

IAM is a governance discipline that happens to be implemented in a directory. This course runs the same loop for every access surface it governs.

1. Model the access before configuring it. Groups, roles and their nesting decide who can reach what long after anybody remembers why. Architecture first, then the objects.

2. Grant through a process that leaves a record. Access packages and entitlement management exist so a grant has a requester, an approver and an expiry rather than a memory.

3. Govern the identities with no human behind them. Service principals, workload identities and agent identities accumulate permissions and never leave the organization.

4. Review access as if the reviewer is busy. A review nobody can complete honestly gets rubber-stamped, and a rubber-stamped review is worse than none because it produces evidence of diligence.

5. Monitor for what governance misses. Stale identities, permission creep and credential health, measured rather than assumed.

The course closes by assembling the complete program: the controls, the risk register and the decision record that survives your departure.

What this course assumes

No minimum experience and no prerequisite course. The Entra object model, the governance features and the licensing that gates them are explained where they first matter.

What makes it go faster: a tenant with Entra ID P2, since most governance features are gated behind it. Not required, and the course states plainly which controls need which tier.

What this course does not cover: identity attack detection and incident response, which are separate courses, and directory administration. This is governance.

Who this course is for

You're a Security Engineer, Microsoft 365 Administrator, Identity Engineer, or IT Leader who designs, operates, and defends identity programs. This course is built for you if you want to:

✓ Move beyond basic user management to architecting secure, Zero Trust identity systems at enterprise scale
✓ Master Microsoft Entra ID, Conditional Access, PIM, and Identity Governance to stop identity-based attacks before they start
✓ Gain the practical and strategic skills needed to reduce identity risk and simplify operations across cloud, hybrid, and on-prem environments
✓ Become the go-to expert who organizations rely on to protect their most critical asset, identity

In short: if you're ready to own the identity layer and dramatically strengthen your organization's security posture, this course is for you.

What you'll learn

By the end of this Entra ID Identity and Access Management course you will be able to:

✓ Architect secure authentication, authorization, and access control using Microsoft Entra ID and Microsoft 365
✓ Deploy and optimize Conditional Access policies, Privileged Identity Management (PIM), and Identity Governance workflows
✓ Implement Zero Trust identity strategies that hold across hybrid and cloud environments
✓ Detect, investigate, and respond to modern identity threats including MFA fatigue, token theft, and account takeover
✓ Automate identity lifecycle processes and enforce least-privilege access at scale
✓ Measure, monitor, and continuously improve your organization's identity security posture

Key course takeaways

✓ Build and defend a production-grade Zero Trust identity program that organizations can actually rely on
✓ Master Microsoft Entra ID, Conditional Access, PIM, and Identity Governance to eliminate common identity attack paths
✓ Operationalize automated access reviews, lifecycle workflows, and least-privilege controls across Microsoft 365 and hybrid environments
✓ Rapidly investigate and neutralize identity-based threats using Defender for Identity and advanced Entra ID capabilities
✓ Reduce identity risk dramatically while simplifying operations for security and IT teams
✓ Become the identity expert who transforms how your organization designs, operates, and defends its most critical security layer

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches identity and access management from first principles. Familiarity with Entra ID and the Microsoft 365 admin center will help you move faster through the early modules, but neither is required. Every concept is explained at first use.

What are the device requirements?

A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) with an Entra ID Governance trial license for hands-on governance configuration. The course walks you through tenant setup in Module 0.

How will the course benefit your career?

Identity is the primary attack surface in modern environments. Organizations need people who can design and operate identity programs, not just manage user accounts. This course gives you the skills to architect Zero Trust identity infrastructure, govern non-human identities, automate lifecycle operations, and produce compliance evidence on demand.

The demand for identity engineers and architects continues to grow as organizations move from basic Entra ID administration to full identity governance programs that cover users, applications, workload identities, and AI agents.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy configurations, governance frameworks, scripts, and policies in your production environment. You may not redistribute course content or share account credentials.

Governance configurations: Test every configuration in a non-production tenant before production. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.