# Professional Certificate in Identity & Access Management

Canonical URL: https://mtfinstitute.com/programs/identity-access-management/
Official publisher: MTF Institute of Management, Technology and Finance
Language: English
Topics: Cybersecurity, Identity and Access Management, IAM Operations, Access Governance

> Learn to take access requests and identity changes from first check to approved action, fresh verification and a clear handoff.

## Program facts

- Format: Online, self-paced
- Recommended duration: Up to 1 month
- Study time: 20 applied lessons, 20 distinct work products, three Role Starter Pack resources and one applied capstone
- Tuition: €10
- Credential: Professional Certificate in Identity &amp; Access Management
- Enrollment: https://edu.gtf.pt/course/view.php?id=116


## Professional Certificate in Identity &amp; Access Management

Learn to take access requests and identity changes from first check to approved action, fresh verification and a clear handoff.

## Who this course is for

Designed for developing practitioners who need a clear, evidence-based path through IAM operations.

## What you will be able to do

- Validate the request: Match identity, business need, approval, entitlement and effective time before a change.

- Run lifecycle changes: Plan joiner, mover and leaver work, including safe timing and removal of old access.

- Verify the target: Check actual application permissions, exclusions and residual access before closing work.

- Trace service faults: Distinguish sign-in, token, provisioning and application-role problems for a useful handoff.

- Support reviews: Prepare review populations and follow revoke decisions through to effective removal.

- Handle higher-risk access: Record privileged and non-human identity questions and route decisions to their owners.

## Curriculum

### Identity Operations and Access Decisions

You will follow an access request from its first message through identity checks, approval, role selection and a clear next action. You will practise questions, identity and entitlement reading, and records that let another owner continue without guessing.

1. **Map an IAM request to the right owner** — Route a mixed IAM queue to the right authority and first action. Deliverable: IAM work-routing note.

2. **Check identity and request completeness** — Resolve an incomplete access request before any entitlement is changed. Deliverable: Access-request clarification.

3. **Read accounts, groups and roles** — Translate business roles into actual accounts, groups and application permissions. Deliverable: Entitlement mapping sheet.

4. **Match approvals to entitlements** — Check that approved scope matches the entitlement a group would grant. Deliverable: Approval-to-access decision note.

5. **Prioritize the IAM queue** — Prioritize daily IAM work using exposure, timing and local commitments. Deliverable: Daily IAM queue plan.

### Lifecycle Changes and Reliable Fulfillment

You will work through joiner, mover and leaver changes, compare event data with requests and application state, and recognize decisions that need an owner. You will plan timing, perform bounded checks, test the actual result and explain outcomes, including failures and urgent departures.

6. **Plan a joiner access change** — Plan a joiner grant that becomes usable only at the approved time. Deliverable: Joiner access plan.

7. **Handle a mover without privilege drift** — Move a worker between roles without overlapping incompatible effective permissions. Deliverable: Mover change checklist.

8. **Close a leaver exposure** — Confirm a leaver has lost access across connected systems. Deliverable: Leaver verification record.

9. **Fulfill and verify an access change** — Complete an approved change only after fresh target verification. Deliverable: Access-change closure record.

10. **Resolve a provisioning exception** — Investigate a provisioning timeout without assuming whether it succeeded. Deliverable: Provisioning exception handoff.

### Authentication, Integration and Service Support

You will distinguish identity data, authentication, authorization, federation and provisioning when access appears right in one system but fails in another. You will trace faults, prepare technical handoffs and test proposed integration changes, using current passkey, token and workload cases where relevant.

11. **Trace a failed sign-in** — Trace a failed sign-in across identity, policy, token and application role. Deliverable: Sign-in diagnostic note.

12. **Support passkey enrollment and recovery** — Support passkey enrollment or recovery under the local approved route. Deliverable: Passkey support guide.

13. **Specify an application onboarding handoff** — Give an application owner and engineer testable IAM onboarding requirements. Deliverable: Application IAM requirements brief.

14. **Test a federation or token change** — Test a federation change and record the technical owner’s follow-up. Deliverable: Federation test record.

15. **Review an automation change safely** — Evaluate an automation proposal before a controlled pilot. Deliverable: IAM automation test plan.

### Access Governance, High-Risk Access and Improvement

You will prepare review data, support reviewer decisions, verify removals and make control evidence understandable to business and audit owners. You will address privileged and machine identities, exceptions, recurring defects and service measures through decisions within an analyst&#039;s remit.

16. **Prepare an access review population** — Prepare a review population with accurate users, resources and reviewers. Deliverable: Access-review preparation sheet.

17. **Track review decisions to removal** — Follow a revoke decision through to effective target removal. Deliverable: Access-review remediation tracker.

18. **Assess privileged and emergency access** — Assess an elevated request within its special approval route. Deliverable: Privileged-access decision brief.

19. **Inventory service and agent identities** — Inventory non-human identities and route missing ownership or privilege concerns. Deliverable: Non-human identity inventory.

20. **Improve the IAM service from evidence** — Propose one measured improvement from service evidence. Deliverable: IAM service improvement proposal.

## Applied capstone

At 09:00 America/New_York, Maya moves from customer support to quality review. The old export permission and new quality-approval permission cannot coexist under the supplied separation-of-duties rule. A ticket asks to retain export, but the access-control owner has not approved an exception. The application snapshot is stale.

Use the relevant course methods to prepare a safe transfer plan under the supplied local mover rule: confirm no early quality access; at the approved time remove old standard and export access and verify their effective absence before adding the approved quality role; then use fresh target evidence to confirm the quality permission is present and old permissions are absent. Route the retention exception to its owner and keep conflicting or stale target state open with an app-owner handoff.

Deliverable: Access-change decision and action plan

## How the course works

Online, self-paced study in English across four modules, twenty lessons and one applied capstone. Each lesson includes theory, a worked example, a reusable blank template, independent practice and optional AI-supported drafting and review.

## Role Starter Pack

Model Job Description; ATS-friendly Resume Template; Model Role SOP / Operating Playbook.

## Certificate

The course includes a certificate section with learner-controlled completion.

## Evidence behind the course

https://mtfinstitute.com/insights/identity-access-management-us-vacancy-evidence-2026/

https://mtfinstitute.com/insights/identity-access-management-recent-changes-2026/

## Start the course

[ENROLL NOW](https://edu.gtf.pt/course/view.php?id=116)

## Frequently asked questions

### How is the course delivered?

The course is online and self-paced in English. It contains four modules, 20 lessons and an applied capstone. Study at your own pace over up to one month.

### Who is this course for?

It is designed for developing IAM analysts, identity operations specialists, IT service desk practitioners and security operations practitioners. The examples explain core IAM terms before asking you to use them.

### What will I practise?

You will work through access requests, joiner, mover and leaver changes, sign-in and provisioning problems, reviews and higher-risk access questions. Each lesson asks for one practical work product, with a blank template and completed example.

### What is included in the Role Starter Pack?

Three pages: a model job description, an ATS-friendly resume template and a model role SOP or operating playbook. They provide reusable starting points that you should adapt to an employer’s actual systems, approval routes and responsibilities.

### How does the applied capstone work?

You will resolve one transfer-access conflict using the relevant course methods. The principal output is an access-change decision and action plan that makes authorization, timing, effective permissions, fresh checks and owner handoffs clear.

### Is AI-supported practice included?

Lessons include optional copyable prompts and a supplied fictional case for drafting and critiquing a work product. Check any output against the stated sources, approvals and target evidence; do not treat a generated answer as an access decision.

### What evidence informs the course?

The role design draws on a structured purposive sample of 108 U.S. vacancy advertisements observed on 6 October 2026. A separate article covers recent IAM technical changes. The vacancy study also has an openly archived PDF on Zenodo.

## Professional education notice

Professional courses and certificates are taught under the terms of paragraph 3 of article 3 of Decree-Law No. 474/2010, published on July 8th by the Portuguese Ministry of Labour and Social Solidarity. The professional programs are related to professional / business education and are provided without official recognition (certificates are provided at a professional level and not academic degrees or diplomas and do not confer academic credits).

## Citation guidance

When quoting or summarizing this program, cite the canonical HTML page: https://mtfinstitute.com/programs/identity-access-management/
