CertClue
Courses · Security
IAM Analyst

Identity & Access Management (IAM) Analyst

Learn to run identity as a job: read a SAML assertion and a token payload, move joiners, movers and leavers through the lifecycle without leaving access behind, design roles that survive real people, run an access review that means something, and keep privileged accounts under control.
4.5 hrs taught · 5.5 to 10 hrs applied 7 modules 28 lessons 6 portfolio artifacts Completion certificate Updated August 2026
Created by the CertClue team
What you'll build

Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.

  • Access decision recordOne page per non trivial request: what was asked for against what the person actually needs to do, what they already hold, the segregation rules tested and the conflict found, the options weighed, who approved it, when it expires, and anything you noticed on the way that was raised separately.
  • Joiner, mover and leaver runbookThe lifecycle written so somebody else can run it: populations and their triggers, the joiner and mover steps with who decides, the leaver sequence in the order that works and why it is that order, the surfaces your directory cannot see, how each step is verified, and the gaps stated honestly.
  • Role definition and segregation matrixOne role defined properly: the job it serves in a sentence, the entitlements in it with the reason for each, the entitlements deliberately excluded, the owners on both the business and technical side, and a segregation matrix with the risk in plain words and the number of people currently in breach.
  • Access certification campaign reportA campaign written up for somebody who was not there: scope and what was left out, a participation table with median seconds per item beside the completion figure, reviews judged unreliable and what you did about them, revocations decided against revocations executed, exceptions with risk owners, and what changes next quarter.
  • Privileged access registerEvery privileged and non human identity in one table: owner and deputy, standing or just in time, how old the credential is, whether a person can sign in as it, whether anybody would be alerted if they did, and when it was last reviewed. Filled in from the simulation, including the account nobody owns.
  • Federation trust recordEvery federated application in one table, filled in from the outage: how each one learns the identity provider's signing key, what its own sign on diagnostics actually said, what that evidence rules out and what it cannot tell you, the faster fix that was refused and the one sentence why, and an owner and an expiry for every certificate somebody pastes in by hand. Including the one whose expiry nobody knows.

What you'll learn

Fundamentals, kept short
The role decoded
A day in the role
The recurring calendar
Live simulation: a week on the identity desk
Artifacts
Handoff

Course content · 7 modules, 28 lessons

Sign up to unlock every lesson - the titles below show exactly what is inside.

Identity as the control plane, authentication kept apart from authorisation, the protocols that carry a sign in between two companies, and the lifecycle everything else in this course hangs from.

Identity is the control plane
Authentication and authorisation, kept apart
Single sign on, and what actually travels
OpenID Connect, tokens and scopes
The directory, the source of truth, and the lifecycle
Factors and conditional access, as policy

Requirements

  • No prior experience in this field is required to start.
  • A computer with a reliable internet connection.
  • Comfortable using a web browser - no software to install.

Description

Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for iam analyst.

Who this course is for

Anyone aiming to become a iam analyst, including career changers with no background in it yet. This is the entry rung of a realistic ladder:

entry
IAM Analyst

Provisions and deprovisions access, runs access reviews, and follows the joiner-mover-leaver process.

ProvisioningAccess reviewsJML process
mid
IAM Engineer

Owns identity architecture for a set of systems, and automates provisioning and review workflows.

Identity architectureAutomationSSO/MFA
senior
Senior IAM Engineer / Lead

Sets identity strategy across the org, and leads on privileged access management.

Identity strategyPAMTeam leadership

Where it leads

This course prepares you for the Microsoft SC-300, or Okta Certified Professional role or credential path. Named for preparation only - no partnership or endorsement is implied.

Reviews

No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.

Sign in to leave a review.

Students also explore