This curriculum spans the full operational lifecycle of identity management, comparable in scope to an enterprise-wide IAM transformation program, addressing the same technical, procedural, and stakeholder coordination challenges encountered in real-world deployments across HR, IT, security, and compliance functions.
Module 1: Defining and Mapping Identity Customer Journey Stages
- Selecting segmentation criteria (e.g., role, access frequency, department) to differentiate journey paths for employees, contractors, and partners.
- Documenting entry points into the identity system, such as onboarding workflows, system migrations, or M&A integrations.
- Aligning journey stages with IAM lifecycle phases (provisioning, maintenance, deprovisioning) while accounting for business exceptions.
- Integrating HRIS and IT service management systems to synchronize trigger events with journey stage transitions.
- Validating journey maps with business unit stakeholders to reflect actual access request patterns and approval bottlenecks.
- Establishing criteria for when a user transitions from “new hire” to “active” to “offboarding” in the identity system.
Module 2: Identity Provisioning and Initial Access Delivery
- Configuring role-based access control (RBAC) templates that balance standardization with business unit-specific entitlement needs.
- Implementing automated provisioning workflows while defining manual override processes for time-sensitive access requests.
- Choosing between push-based (HRIS-driven) and pull-based (request-driven) provisioning models based on organizational maturity.
- Designing approval hierarchies that minimize latency without compromising segregation of duties (SoD) requirements.
- Handling just-in-time (JIT) access for contingent workers with time-bound entitlements and audit trail requirements.
- Testing provisioning accuracy across multiple downstream systems (ERP, CRM, cloud apps) during integration validation.
Module 3: Authentication and Ongoing Access Management
- Deploying adaptive authentication policies that escalate verification steps based on risk signals (location, device, behavior).
- Integrating step-up authentication into high-risk journey stages, such as accessing financial systems or PII data.
- Managing passwordless rollout timelines across user cohorts while maintaining fallback mechanisms for legacy applications.
- Configuring session timeout and re-authentication rules in alignment with regulatory requirements and user productivity needs.
- Monitoring and tuning false positive rates in risk-based authentication to reduce user friction and helpdesk load.
- Enforcing conditional access policies for remote workers accessing corporate resources from unmanaged devices.
Module 4: Access Review and Compliance Enforcement
- Scheduling access recertification campaigns by role criticality, with shorter cycles for privileged and sensitive roles.
- Assigning review responsibilities to data owners versus system owners, and resolving ownership disputes.
- Handling exceptions and justifications during access reviews, including documentation and retention for audit purposes.
- Automating revocation of non-validated access while implementing grace periods for business continuity.
- Generating evidence packages for internal and external auditors from access review logs and attestation records.
- Integrating access review outcomes with provisioning systems to enforce least privilege in real time.
Module 5: Identity Lifecycle Transitions and Role Changes
- Triggering re-provisioning workflows when users change roles, including revocation of former entitlements.
- Managing concurrent roles for users in matrix organizations without creating excessive privilege accumulation.
- Handling access during temporary assignments (e.g., secondments, project teams) with time-limited entitlements.
- Coordinating with HR to ensure role change events in HRIS propagate accurately to IAM systems.
- Implementing “access pause” states for leaves of absence, distinguishing from full deprovisioning.
- Designing workflows for mid-cycle access adjustments when formal role changes lag operational needs.
Module 6: Offboarding and Access Termination
- Defining the offboarding trigger event: last workday, resignation date, or manager confirmation.
- Sequencing deprovisioning across systems based on data sensitivity and recovery requirements.
- Handling access revocation for shared accounts or service IDs used by departing employees.
- Preserving audit logs and access history post-termination in compliance with data retention policies.
- Validating complete deprovisioning through automated attestation checks across integrated systems.
- Managing re-onboarding scenarios for returning employees while avoiding automatic reinstatement of prior access.
Module 7: Monitoring, Analytics, and Journey Optimization
- Instrumenting journey stages with event logging to measure cycle times and failure points in provisioning workflows.
- Correlating IAM metrics (e.g., access request duration, MFA failure rates) with user productivity data.
- Identifying anomalous behavior patterns that indicate compromised accounts or policy circumvention.
- Using journey analytics to prioritize IAM automation investments based on volume and risk exposure.
- Conducting root cause analysis on helpdesk tickets related to access issues by journey stage.
- Iterating journey design based on user feedback and system telemetry without introducing security gaps.