Missiora
Identity & Access Management (IAM)

Technology Fundamentals

Identity & Access Management (IAM)

1 min readPublished 22 Jul 2026

Track your progress. Sign in to mark this guide complete and build your Job Readiness Score.

Identity is the new perimeter — most breaches involve stolen or misused credentials, so controlling who can do what is central to security.

Interactive explainer

Access Control Models

The four ways systems decide what you are allowed to do.

1DAC2MAC3RBAC4ABAC

Tap or hover a part to learn more.

DAC

Discretionary.

The resource owner decides who gets access (e.g. file permissions you set yourself). Flexible but easy to misconfigure.

Check your understanding

1. Which model attaches permissions to roles that users inherit?

2. Which model uses labels and clearances enforced by the system?

Practise this in AI Interview™

The essentials

  • Authentication (who you are) vs authorisation (what you can do) — don't confuse them.
  • Access control models: DAC, MAC, RBAC (roles — most common in business) and ABAC (attributes — supports zero trust).
  • MFA dramatically reduces credential-theft risk; SSO improves usability and central control.
  • Least privilege and separation of duties limit the damage any one account can do.

This builds on Windows Fundamentals identity and feeds every cyber role and Security+.

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

Identity is the top attack vector, so IAM knowledge is expected in every security role.

Technical questions
Explain RBAC vs ABAC and when you'd use each.+

RBAC assigns permissions via roles (simple, scalable); ABAC uses attributes/context for fine-grained, zero-trust decisions.

Behavioural questions
Tell me about enforcing least privilege in practice.+

Show scoping access to need, reviewing entitlements and removing permission creep.

Real-world scenarios
“A manager requests admin rights 'to be safe'.”+

Expected answer: Apply least privilege — grant only what the task needs and explain the risk of over-provisioning.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
Security EngineerSOC AnalystIAM Engineer
Skills you're proving
IAMMFA/SSOLeast privilege
Recommended certifications
CompTIA Security+CompTIA CySA+CompTIA PenTest+
Career progression

Cyber Fundamentals → Security+ → Security/IAM Engineer.

What employers expect

That you understand core security principles and can apply them to real risks, controls and incidents.

Frequently asked questions

What is the difference between authentication and authorisation?

Authentication proves who you are; authorisation decides what you're allowed to do once authenticated.

What is RBAC?

Role-Based Access Control — permissions are attached to roles that users inherit, the most common model in business.

Why is MFA important?

It requires more than a password, blocking the vast majority of credential-theft attacks.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.