Ten content areas, one identity practitioner
Each track is a self-contained syllabus that opens with foundations and ends with reporting. Follow the order, or jump straight to the discipline you need for this quarter's work.
IAM Foundations
Vocabulary, identity lifecycle, joiner-mover-leaver, RBAC vs. ABAC and the architecture reference every later lab assumes.
Entra ID Security
Measure, harden and report on a Microsoft Entra tenant — from identity risk baseline to Secure Score and executive roadmap.
Identity Standards
OpenLDAP, Keycloak, SAML, OIDC, SCIM, JWT/JWS/JWE, OAuth 2.1 hardening, token exchange and OPA/Rego policy.
SSO & Federation
Zero-trust SSO, enterprise SAML federation, conditional access, and hybrid identity bridging patterns.
Privileged Access
HashiCorp Vault JIT, SSH key discipline, and PIM patterns. Vendor-neutral PAM tradecraft.
ZTNA & Network Trust
Teleport-based zero-trust network access and end-to-end zero-trust identity architecture.
Cloud & Kubernetes Identity
AWS IAM, Organizations & Control Tower, Identity Center, GCP IAM, Kubernetes RBAC, multi-cloud federation, AZ-104.
Entra & Microsoft Security
Entra enterprise, governance, multi-region, Sentinel identity security and Microsoft security labs.
Governance & Lifecycle
Access reviews, joiner-mover-leaver automation, and identity governance across systems.
Observability & SIEM
Grafana identity dashboards and Wazuh SIEM for identity detections that survive audit.
How to sequence the whole programme
Every lab is standalone. But if you want a career-shaped progression from junior engineer to identity architect, the order below builds each layer on the last.
The recommended order
- Foundations → get the vocabulary, principles, and reference architecture in your hands before touching a product.
- Entra Security → apply the foundations to a real cloud IdP and produce audit evidence at every step.
- Identity Standards → move under the hood — LDAP, Keycloak, SAML, OIDC, SCIM, OAuth 2.1, JWT, OPA. Vendor-neutral fluency.
- SSO & Federation → stitch identity providers together the way a real enterprise does.
- Privileged Access → collapse standing privilege into just-in-time, and secure the operator paths.
- ZTNA / Cloud / Microsoft → extend identity to the network edge, then across AWS, GCP, Kubernetes and Microsoft.
- Governance & Observability → keep the wheels on: access reviews, lifecycle automation, identity dashboards, SIEM detections.
Safe workspace ⋅ the contract
- Use a personal, disposable Entra tenant or a throw-away lab VM. Never an employer or client environment.
- Before each lab, note the objects and settings you will change, and how to reverse each one.
- Do not proceed past a warning, or past output you can’t explain.
- Capture verification evidence — a redacted screenshot, CSV or JSON — and record one sentence describing the risk each control reduces.
- Follow the cleanup section at the end of every lab before starting the next.