Online professional certificate
Identity & Access Management
Learn to take access requests and identity changes from first check to approved action, fresh verification and a clear handoff.
- Format
- Online, self-paced
- Study time
- Up to 1 month
- Curriculum
- 20 applied lessons
- Language
- English
Practical capability
Make access changes that stand up to a fresh check.
Practice the checks, decisions and records an IAM analyst uses across requests, lifecycle changes, sign-in support and access governance.
Match identity, business need, approval, entitlement and effective time before a change.
Plan joiner, mover and leaver work, including safe timing and removal of old access.
Check actual application permissions, exclusions and residual access before closing work.
Distinguish sign-in, token, provisioning and application-role problems for a useful handoff.
Prepare review populations and follow revoke decisions through to effective removal.
Record privileged and non-human identity questions and route decisions to their owners.
Who this course is for
For the people who make access work.
Designed for developing practitioners who need a clear, evidence-based path through IAM operations.
The operating cycle
From trigger to verified closure.
A practical sequence adapted from the model IAM operating playbook; local approval and decision rights govern every change.
Curriculum
Four modules. Twenty applied lessons.
Identity Operations and Access Decisions
You will follow an access request from its first message through identity checks, approval, role selection and a clear next action. You will practise questions, identity and entitlement reading, and records that let another owner continue without guessing.
01 Map an IAM request to the right owner
Route a mixed IAM queue to the right authority and first action.
Five practical steps
- Classify each queue item by work type and urgency.
- Find the authoritative source for the affected identity.
- Separate approval questions from sign-in and technical faults.
- Name the business approver and technical owner.
- Record the first safe action and receiving owner.
Primary deliverable: IAM work-routing note
02 Check identity and request completeness
Resolve an incomplete access request before any entitlement is changed.
Five practical steps
- Match the requester and person to the identity source.
- Read the requested application, role, purpose and time.
- Compare the request with the role catalogue.
- Ask one concise set of questions about missing scope and approval.
- Record who can answer and hold the change until resolved.
Primary deliverable: Access-request clarification
03 Read accounts, groups and roles
Translate business roles into actual accounts, groups and application permissions.
Five practical steps
- Identify the business role and target application.
- Trace the account, group and permission relationships.
- Compare expected access with the observed directory state.
- Mark exclusions, including permissions outside the role.
- Record the mapping and its evidence owner.
Primary deliverable: Entitlement mapping sheet
04 Match approvals to entitlements
Check that approved scope matches the entitlement a group would grant.
Five practical steps
- Read the approval for person, application, role and time.
- Translate the proposed group into its effective permissions.
- Identify any permission outside the approved scope.
- Send the mismatch to the designated decision owner.
- Record the bounded action or hold decision.
Primary deliverable: Approval-to-access decision note
05 Prioritize the IAM queue
Prioritize daily IAM work using exposure, timing and local commitments.
Five practical steps
- List the joiner, overdue approval, leaver and connector alert.
- Check exposure, effective time and local service commitments.
- Separate urgent safe checks from unapproved changes.
- Assign each first action and decision owner.
- Publish a queue plan with follow-up points.
Primary deliverable: Daily IAM queue plan
Lifecycle Changes and Reliable Fulfillment
You will work through joiner, mover and leaver changes, compare event data with requests and application state, and recognize decisions that need an owner. You will plan timing, perform bounded checks, test the actual result and explain outcomes, including failures and urgent departures.
06 Plan a joiner access change
Plan a joiner grant that becomes usable only at the approved time.
Five practical steps
- Confirm the hire, standard role and application-owner approval.
- Check the approved 09:00 America/New_York effective time.
- Verify no usable target access before that time.
- Hold group assignment until 09:00 where inactive staging is unverified.
- After assignment, check fresh target role and export exclusion.
Primary deliverable: Joiner access plan
07 Handle a mover without privilege drift
Move a worker between roles without overlapping incompatible effective permissions.
Five practical steps
- Map old export and new quality permissions against the SoD rule.
- Route the unapproved retention exception to the access-control owner.
- Before 09:00, verify no usable new quality permission.
- At 09:00, remove old standard and export groups under the supplied local rule; verify their effective absence before adding the quality group.
- Add the approved quality group and freshly verify quality permission present with export and old standard permissions absent.
Primary deliverable: Mover change checklist
08 Close a leaver exposure
Confirm a leaver has lost access across connected systems.
Five practical steps
- Confirm the departure event and authorized disable route.
- Check directory and connected application state.
- Identify the still-live application session.
- Escalate residual access to the application or security owner.
- Record fresh verification or the named open handoff.
Primary deliverable: Leaver verification record
09 Fulfill and verify an access change
Complete an approved change only after fresh target verification.
Five practical steps
- Match approval, role and effective time.
- Check no usable access before activation.
- Hold assignment until the approved time without verified inactive staging.
- Perform the assigned change and inspect synchronization.
- Read fresh target role and exclusion evidence before closure.
Primary deliverable: Access-change closure record
10 Resolve a provisioning exception
Investigate a provisioning timeout without assuming whether it succeeded.
Five practical steps
- Capture the source change and connector timeout.
- Avoid a blind retry while target state is unknown.
- Compare identity source, connector logs and fresh target read.
- Describe the possible partial result and risk.
- Hand the evidence and retry decision to engineering.
Primary deliverable: Provisioning exception handoff
Authentication, Integration and Service Support
You will distinguish identity data, authentication, authorization, federation and provisioning when access appears right in one system but fails in another. You will trace faults, prepare technical handoffs and test proposed integration changes, using current passkey, token and workload cases where relevant.
11 Trace a failed sign-in
Trace a failed sign-in across identity, policy, token and application role.
Five practical steps
- Confirm the identity and reported failure.
- Separate authentication success from app authorization failure.
- Read policy, token claim and application role evidence.
- Test the likely mismatch without changing unrelated credentials.
- Record the diagnostic result and assigned owner.
Primary deliverable: Sign-in diagnostic note
12 Support passkey enrollment and recovery
Support passkey enrollment or recovery under the local approved route.
Five practical steps
- Check whether the user and tenant are in the named rollout cohort.
- Confirm local opt-out and passkey mode.
- Follow the approved help-desk identity verification route.
- Guide synced or device-bound recovery as applicable.
- Test a fresh sign-in and record the result.
Primary deliverable: Passkey support guide
13 Specify an application onboarding handoff
Give an application owner and engineer testable IAM onboarding requirements.
Five practical steps
- Identify the application owner and user population.
- Document the authoritative source, roles and attributes.
- Specify SSO, provisioning and removal behavior.
- List approval and negative-test needs.
- Hand open design decisions to the engineering and business owners.
Primary deliverable: Application IAM requirements brief
14 Test a federation or token change
Test a federation change and record the technical owner’s follow-up.
Five practical steps
- Define expected issuer, audience and claims from local policy.
- Use sanitized token data for positive and wrong-audience tests.
- Check expiry and revocation behavior.
- Compare a short-lived option where feasible.
- Record results and engineer-owned signing trust or key checks; use workload preview checks only if locally available.
Primary deliverable: Federation test record
15 Review an automation change safely
Evaluate an automation proposal before a controlled pilot.
Five practical steps
- State the proposed group-assignment rule and approval boundary.
- Prepare a dry run with representative and duplicate events.
- Check logs, exception handling and rollback.
- Set a controlled pilot and success criteria.
- Send production-change approval to its owner.
Primary deliverable: IAM automation test plan
Access Governance, High-Risk Access and Improvement
You will prepare review data, support reviewer decisions, verify removals and make control evidence understandable to business and audit owners. You will address privileged and machine identities, exceptions, recurring defects and service measures through decisions within an analyst's remit.
16 Prepare an access review population
Prepare a review population with accurate users, resources and reviewers.
Five practical steps
- Reconcile active identities, accounts and duplicate rows.
- Check resource scope and assigned reviewers.
- Resolve unclear owners and exclusions.
- Validate a local campaign preview if available.
- Record the clean review population and unresolved issues.
Primary deliverable: Access-review preparation sheet
17 Track review decisions to removal
Follow a revoke decision through to effective target removal.
Five practical steps
- Capture the reviewer revoke decision and deadline.
- Identify the assigned removal executor.
- Track the directory change and connected application.
- Freshly verify that effective access is absent.
- Keep any mismatch open with owner and next check.
Primary deliverable: Access-review remediation tracker
18 Assess privileged and emergency access
Assess an elevated request within its special approval route.
Five practical steps
- Check the elevated-access purpose and special approval route.
- Confirm scope, duration and requested privilege.
- Identify session evidence and post-use review.
- Hold or route an unapproved exception to the privileged-access owner.
- Record the decision and next safe action.
Primary deliverable: Privileged-access decision brief
19 Inventory service and agent identities
Inventory non-human identities and route missing ownership or privilege concerns.
Five practical steps
- Reconcile the service account and key with their source record.
- Record purpose, owner, privilege and credential mode.
- Flag missing ownership or excess access for decision.
- Follow only an approved disable route.
- Freshly verify the target result and record any remaining owner.
Primary deliverable: Non-human identity inventory
20 Improve the IAM service from evidence
Propose one measured improvement from service evidence.
Five practical steps
- Sample missing approvals and repeated sync escalations.
- Separate observed defects from a proposed cause.
- Choose one controlled process change.
- Name its owner, pilot and measure.
- Write the proposal and decision needed before production change.
Primary deliverable: IAM service improvement proposal
Applied capstone
Resolve a transfer access conflict.
Use the relevant course methods to prepare one clear plan for the service lead.
The situation
In this fictional case, at 09:00 America/New_York, Maya moves from customer support to quality review. The old export permission and new quality-approval permission cannot coexist under the supplied separation-of-duties rule. A ticket asks to retain export, but the access-control owner has not approved an exception. The application snapshot is stale.
Your task
Use the relevant course methods to prepare a safe transfer plan under the supplied local mover rule: confirm no early quality access; at the approved time remove old standard and export access and verify their effective absence before adding the approved quality role; then use fresh target evidence to confirm the quality permission is present and old permissions are absent. Route the retention exception to its owner and keep conflicting or stale target state open with an app-owner handoff.
The people behind MTF
Meet MTF faculty and the learner community.
Explore the professional backgrounds of MTF faculty and learn more about the international community studying with the Institute.
Enrollment
Enroll in Professional Certificate in Identity & Access Management
One-time course price: €10, including applicable taxes. Payment is processed securely by Stripe. No card details are stored on the MTF Institute website.
You will receive an email with access to the course. If you have any difficulties, please write to welcome@gtf.pt.
Questions and details
Frequently asked questions
Open the sections that matter to you, including delivery format, AI-supported practice and the evidence used to design the curriculum.
How is the course delivered?
The course is online and self-paced in English. It contains four modules, 20 lessons and an applied capstone. Study at your own pace over up to one month.
Who is this course for?
It is designed for developing IAM analysts, identity operations specialists, IT service desk practitioners and security operations practitioners. The examples explain core IAM terms before asking you to use them.
What will I practise?
You will work through access requests, joiner, mover and leaver changes, sign-in and provisioning problems, reviews and higher-risk access questions. Each lesson asks for one practical work product, with a blank template and completed example.
What is included in the Role Starter Pack?
Three pages: a model job description, an ATS-friendly resume template and a model role SOP or operating playbook. They provide reusable starting points that you should adapt to an employer’s actual systems, approval routes and responsibilities.
How does the applied capstone work?
You will resolve one transfer-access conflict using the relevant course methods. The principal output is an access-change decision and action plan that makes authorization, timing, effective permissions, fresh checks and owner handoffs clear.
Is AI-supported practice included?
Lessons include optional copyable prompts and a supplied fictional case for drafting and critiquing a work product. Check any output against the stated sources, approvals and target evidence; do not treat a generated answer as an access decision.
What evidence informs the course?
The role design draws on a structured purposive sample of 108 U.S. vacancy advertisements observed on 6 October 2026. A separate article covers recent IAM technical changes. The vacancy study also has an openly archived PDF on Zenodo.