Identity & Access Management
Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.
Term
description · examples · notesIdentity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.
Description
IAM covers the entire user account lifecycle, from creation at onboarding through role changes to deactivation at offboarding. It includes role assignment, group management, password policies, and directory service integration.
Without adequate IAM, an organization loses track of who has access to what, creating risks of unauthorized access, privilege accumulation, and accounts remaining active after they are no longer needed.
What people often say
- IAM is just a password reset tool.
- Once configured, IAM requires no regular maintenance or review.
Covers / does not cover
Covers
- Centralized user account management and lifecycle
- Role-based and policy-based access assignment
- Automated account provisioning and deprovisioning on hire and departure
- Integration with directory services and applications
Does not cover
- Monitoring what a user does after login (that is the domain of monitoring and SIEM)
- Protection against credential theft (complemented by MFA and EDR)
- Privileged account control at the level requiring PAM
Mentioned in the news
- 11. JUL 2026. Metin novi AI alat koristi sadržaj javnih Instagram naloga za generisanje slika — bez pitanja korisnika →
- 6. MAJ 2026. Cisco kupuje Astrix Security zbog rizika mašinskih identiteta →
- 28. JUL 2026. Microsoftov AI sam testira mrežu i krpi propuste →
- 13. JUL 2026. Trojanac u Visual Studio projektima ostavlja zamke za razvojne inženjere →
- 11. JUL 2026. AI pregledači odali kredencijale korisnika jer im je rečeno da je to deo igre →
- 11. JUL 2026. Firewall se ne bira po brendu, nego po ljudima koji će ga održavati →
Threats
reduces 24Threats it reduces. Select one to open its page.
- Account Takeover→
- Business Email Compromise→
- Backdoor→
- Insider Threat→
- Accidental Data Leak→
- Cloud IAM misconfiguration→
- Shadow IT→
- Token Theft→
- Brute-force attack→
- API Abuse→
- Password spraying→
- Third-Party Compromise→
- Cloud storage exposure→
- Shared Account Abuse→
- MFA Fatigue→
- SIM Swapping→
- Privilege Misuse→
- Model theft / extraction→
- Prompt injection→
- Contractor Abuse→
- Deepfake Attack→
- Pretexting→
- Service Abuse→
- Kerberoasting→
Techniques
neutralizes 9Techniques it neutralizes. Select one to open its page.