Mastering IAM: Digital Identity & Security Principles

所在平台: Udemy

课程主页: https://www.udemy.com/course/mastering-iam-digital-identity-security-principles/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:掌握IAM:数字身份与安全原则 课程概述:欢迎来到“掌握IAM:数字身份与安全原则”课程!在此课程中,您将深入探讨构建健壮身份与访问管理解决方案所需的基本概念、架构和实用策略。您将学习如何保护用户身份、执行访问控制并维护行业标准的合规性。 课程首先探索数字身份的基础,考察如何在现代IT生态系统中创建、存储和管理标识符、属性和元数据。您将比较认证、授权和审计(AAA)方法,并理解核心身份类型,如用户、组、服务账户、设备和角色。 在“核心IAM模型与技术”部分,您将设计和实施基于角色的访问控制(RBAC)、基于属性的访问控制(ABAC)和基于策略的访问控制(PBAC)模型,以实现精细化授权。您将配置目录服务,包括LDAP、Active Directory和Azure AD,整合单点登录和联合协议,如SAML、OAuth 2.0和OpenID Connect,并自动化身份供应和生命周期工作流程。 您将掌握支持安全认证的密码学基础,包括公钥基础设施(PKI)、数字证书、哈希、加密和非对称密钥管理。实施多因素认证(MFA)方法并探索无密码登录选项,如FIDO2/WebAuthn和生物识别技术,以增强安全性和用户体验。此外,您还将通过特权访问管理(PAM)策略来保护特权账户。 高级模块深入探讨云身份和混合环境,比较AWS IAM、Azure AD和Google Cloud IAM功能。您将实施混合目录同步、配置目录联合,并采用自适应的风险基础认证,根据威胁情报和用户上下文动态调整安全政策。探索身份分析、异常检测和机器学习技术,以识别被攻击的账户和内部威胁。 在整个课程中,您将学习如何应用安全设计原则,如最小权限和零信任,以降低风险并限制横向移动。您还将研究主要合规标准,包括GDPR、HIPAA、PCI-DSS和SOC 2,并学习如何设计身份治理框架,包括访问审查、认证活动和审计准备过程。 完成课程后,您将掌握架构端到端IAM解决方案、保护云端和本地身份的技能,并为组织应对下一代身份挑战(如去中心化身份和自我主权身份)做好准备。本课程特别适合安全工程师、系统管理员、DevOps专业人员、云架构师以及希望提升身份与访问管理专业知识的任何人。 课程中包含动手实验、现实场景和实用练习,以巩固学习。您将与示范环境合作,执行配置任务,并通过模拟企业和云环境中常见的IAM挑战的测验和项目评估您的技能。

课程评论(0条)

课程详情

Welcome to Mastering IAM: Digital Identity & Security Principles! In this course, you will embark on a journey through the essential concepts, architectures, and practical strategies required to build robust identity and access management solutions. You will learn how to protect user identities, enforce access controls, and maintain compliance with industry standards.First, we explore the foundations of digital identity, examining how identifiers, attributes, and metadata are created, stored, and managed across modern IT ecosystems. You will compare authentication, authorization, and accounting (AAA) approaches, and understand core identity types such as users, groups, service accounts, devices, and roles.In the Core IAM Models & Technologies section, you will design and implement Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Policy-Based Access Control (PBAC) models to achieve fine-grained authorization. You will configure directory services including LDAP, Active Directory, and Azure AD, integrate single sign-on and federation protocols like SAML, OAuth 2.0, and OpenID Connect, and automate identity provisioning and lifecycle workflows.You will master cryptographic building blocks that support secure authentication, including public key infrastructure (PKI), digital certificates, hashing, encryption, and asymmetric key management. Implement multi-factor authentication (MFA) methods and explore passwordless login options such as FIDO2/WebAuthn and biometrics to enhance security and user experience. Additionally, you will secure privileged accounts with Privileged Access Management (PAM) strategies.Advanced modules dive into cloud identity and hybrid environments, comparing AWS IAM, Azure AD, and Google Cloud IAM features. You will implement hybrid directory synchronization, configure directory federation, and adopt adaptive, risk-based authentication that dynamically adjusts security policies based on threat intelligence and user context. Explore identity analytics, anomaly detection, and machine learning techniques to identify compromised accounts and insider threats.Throughout the course, you will learn how to apply security design principles like least privilege and Zero Trust to reduce risk and limit lateral movement. You will also examine major compliance standards including GDPR, HIPAA, PCI-DSS, and SOC 2, and learn to design identity governance frameworks with access reviews, certification campaigns, and audit-ready processes.By course completion, you will possess the skills to architect end-to-end IAM solutions, secure cloud and on-premises identities, and prepare your organization for next-generation identity challenges such as decentralized and self-sovereign identity. This course is ideal for security engineers, system administrators, DevOps professionals, cloud architects, and anyone seeking to advance their identity and access management expertise.Hands-on labs, real-world scenarios, and practical exercises are included to reinforce learning. You will work with sample environments, perform configuration tasks, and assess your skills through quizzes and projects designed to simulate common IAM challenges in enterprise and cloud settings.

课程标签

0人关注该课程

主题相关的课程