Identity & Access Management
Who and what gets access — proven and enforced.
Identity is the control plane. Once the perimeter stopped being a location, every
meaningful authorization decision moved into IAM — and the interesting failures moved with
it. The finding that used to be “the firewall was open” is now “the trust policy said *,”
or “the service principal had Owner and nobody reviewed it in two years.”
This pillar covers the three major clouds, the on-prem directory that most hybrid estates still ultimately trust, the federation layer that stitches them together, and the frameworks people invoke when they talk about identity — including the one that’s still being invented: identity for autonomous agents.
Why it matters
Section titled “Why it matters”IAM misconfiguration is the highest-leverage class of finding in security, because a single overpermissioned principal collapses the distance between “attacker got a foothold” and “attacker owns the environment.” It’s also the finding that’s hardest to explain upward, since the impact is a path, not a single flaw.
How this connects
Section titled “How this connects”- → Penetration Testing & Red Teaming: IAM privesc chains are the substance of cloud pentesting. The misconfigs listed here are what the enumeration tooling is looking for.
- → Detection Engineering: identity telemetry (CloudTrail, Entra sign-in logs) is the richest detection surface, and identity-centric containment is the fastest lever in cloud IR.
- → GRC: access review, joiner/mover/leaver, and least privilege are control requirements in every framework — this is where the evidence comes from.
- → AI & Automation: agent identity and agent orchestration are the same problem viewed from two sides. Delegated authority for a non-human actor is an IAM question wearing an AI hat.
- → AppSec: OIDC from CI to cloud is the correct fix for long-lived pipeline credentials — an IAM design decision made in the build system.
- → Threat Intel: identity is the reported initial-access path often enough that it should anchor prioritization.
- → Cloud & Infrastructure Security: the two-plane split. Identity policy lives here; org-level guardrail architecture — SCPs and Azure Policy as blast-radius design — lives there.
- → Incident Response & Digital Forensics: identity-centric containment is usually the fastest lever in an incident — revoke, rotate and cut the session before chasing hosts.
- → Data Security & Privacy Engineering: access is the enforcement point. A classification label with no authorization behind it is decoration.
What’s here
Section titled “What’s here”| Subsection | Focus |
|---|---|
| AWS Identity | Policy evaluation logic, STS, cross-account trust and confused deputy, iam:PassRole chains, boundaries/SCPs/Access Analyzer |
| Azure Identity | Entra objects, the Azure RBAC vs. Entra roles two-plane confusion, Conditional Access design, PIM and Access Reviews |
| GCP Identity | Additive inheritance down the resource hierarchy, service accounts as principal and resource, actAs escalation, key elimination and org policy |
| Active Directory & Hybrid Identity | Kerberos and NTLM attack surface as design rather than defect, AD CS, tiering and the clean source principle, Entra Connect as Tier 0 |
| Multi-Cloud & Federation | SAML/OIDC/SCIM differences, federated access patterns, secrets management, mTLS and machine-to-machine auth |
| Frameworks | The three “zero” framings compared, with a page each on Zero Trust, Zero Knowledge and Zero Knowledge Trust for agentic AI identity |
| Governance of Identity | Joiner/mover/leaver automation, entitlement review at scale, ITDR |
| Non-Human Identity | The estate-wide NHI program: sprawl and ownership, CIEM/secrets/ITDR by the question each answers, the secretless elimination path, JML for machines |
Graph View
Backlinks
Spotted an error on this page? Report it.