IB ⋅ Lab Command Center ⋅ v2

Build identity security skills by doing the work.

Seventy-one hands-on labs across ten tracks. From the first LDAP directory to policy-as-code, cloud federation, and executive reporting — practised end to end in disposable tenants and containers you control.

71
Guided labs
10
Content tracks
4
Difficulty levels
0
Prod tenants used
01 ⋅ Tracks

Ten content areas, one identity practitioner

Each track is a self-contained syllabus that opens with foundations and ends with reporting. Follow the order, or jump straight to the discipline you need for this quarter's work.

Track 01

IAM Foundations

Vocabulary, identity lifecycle, joiner-mover-leaver, RBAC vs. ABAC and the architecture reference every later lab assumes.

6 labsOpen track →
Track 02

Entra ID Security

Measure, harden and report on a Microsoft Entra tenant — from identity risk baseline to Secure Score and executive roadmap.

12 labsOpen track →
Track 03

Identity Standards

OpenLDAP, Keycloak, SAML, OIDC, SCIM, JWT/JWS/JWE, OAuth 2.1 hardening, token exchange and OPA/Rego policy.

14 labsOpen track →
Track 04

SSO & Federation

Zero-trust SSO, enterprise SAML federation, conditional access, and hybrid identity bridging patterns.

8 labsOpen track →
Track 05

Privileged Access

HashiCorp Vault JIT, SSH key discipline, and PIM patterns. Vendor-neutral PAM tradecraft.

7 labsOpen track →
Track 06

ZTNA & Network Trust

Teleport-based zero-trust network access and end-to-end zero-trust identity architecture.

3 labsOpen track →
Track 07

Cloud & Kubernetes Identity

AWS IAM, Organizations & Control Tower, Identity Center, GCP IAM, Kubernetes RBAC, multi-cloud federation, AZ-104.

7 labsOpen track →
Track 08

Entra & Microsoft Security

Entra enterprise, governance, multi-region, Sentinel identity security and Microsoft security labs.

6 labsOpen track →
Track 09

Governance & Lifecycle

Access reviews, joiner-mover-leaver automation, and identity governance across systems.

2 labsOpen track →
Track 10

Observability & SIEM

Grafana identity dashboards and Wazuh SIEM for identity detections that survive audit.

6 labsOpen track →
02 ⋅ Path

How to sequence the whole programme

Every lab is standalone. But if you want a career-shaped progression from junior engineer to identity architect, the order below builds each layer on the last.

The recommended order

  1. Foundations → get the vocabulary, principles, and reference architecture in your hands before touching a product.
  2. Entra Security → apply the foundations to a real cloud IdP and produce audit evidence at every step.
  3. Identity Standards → move under the hood — LDAP, Keycloak, SAML, OIDC, SCIM, OAuth 2.1, JWT, OPA. Vendor-neutral fluency.
  4. SSO & Federation → stitch identity providers together the way a real enterprise does.
  5. Privileged Access → collapse standing privilege into just-in-time, and secure the operator paths.
  6. ZTNA / Cloud / Microsoft → extend identity to the network edge, then across AWS, GCP, Kubernetes and Microsoft.
  7. Governance & Observability → keep the wheels on: access reviews, lifecycle automation, identity dashboards, SIEM detections.

Safe workspace ⋅ the contract

  • Use a personal, disposable Entra tenant or a throw-away lab VM. Never an employer or client environment.
  • Before each lab, note the objects and settings you will change, and how to reverse each one.
  • Do not proceed past a warning, or past output you can’t explain.
  • Capture verification evidence — a redacted screenshot, CSV or JSON — and record one sentence describing the risk each control reduces.
  • Follow the cleanup section at the end of every lab before starting the next.