Implement Identity and Access Management
Goals
- Implement password-based and multifactor authentication
- Implement account policies and authorization solutions
- Implement single sign-on and federated identity solutions
Authentication
- Authentication Design
- Password Policy
- Password Managers
- Authentication Methods
- Biometric Authentication
- Authentication Tokens
- Hard Authentication Tokens
- Soft Authentication Tokens
- Passwordless Authentication
Authorization
An access control model describes the principles that govern how users receive rights.
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- Rule-Based Access Control (RuBAC)
- Principle of Least Privilege
- User Account Provisioning
- Account Attributes and Access Policies
- Group Policy Object (GPO)
- Account Restrictions
- Privileged Access Management (PAM)