Azure Fundamentals Identity Access
Azure Fundamentals Identity Access — Pluralsight course. Visit the course page for full details, prerequisites, and pricing.
Welcome to RecertHero!
Submit bugs, feature requests, and feedbackBrowse · 27 certifications tracked
Search webinars, courses, videos, and vendor training — each mapped to the certifications you’re actually renewing.
42 results for “Identity & Access”
Azure Fundamentals Identity Access — Pluralsight course. Visit the course page for full details, prerequisites, and pricing.
Introduction Aws Identity Access Management Iam — Pluralsight course. Visit the course page for full details, prerequisites, and pricing.
Azure Identity And Access Fundamentals — Pluralsight course. Visit the course page for full details, prerequisites, and pricing.
Protect identity and access in Azure
Learn to create and manage identity and access using Microsoft Entra ID. Explore the basics of creating users, groups, and how to control access with conditional access.
Azure Security Engineer Associate AZ 500 Manage Identity And Access — Pluralsight course. Visit the course page for full details, prerequisites, and pricing.
Access Control And Identity Management — self-paced course on Cybrary. Visit the course page for full details and prerequisites.
In this course, you’ll explore the world of authorization and authentication, and understand the concepts of two-step authentication and single sign-on policies. You’ll also become familiar with the features and capabilities of Azure Active Directory (Azure AD), particularly those relating to the benefits of using Azure AD to manage an enterprise’s security requirements including access management, identity governance, and management. This course will take you one step closer to the Microsoft Cybersecurity Analyst Professional Certificate, which requires no degree or prior experience.
Identity and access management has been a pillar in security for decades now; it has emerged, changed, and evolved many times over as the problems it solved grew larger and more complex. Identity governance, identity providers, and authorization platforms are all required to deliver a secure identity practice. Authorization, like every piece of identity, enables the modern business, reduces risk, tightens security, and protects access to your digital assets. Join PlainID and ISC2 to hear a discussion where speakers dive into the project and business drivers they see that require centralized authorization. his talk will help you: · Distinguish how IGA (Identity Governance and Administration) and IAM (Identity Access Management) tools control access through RBAC and ABAC approaches · Learn how Policy-based Access Control (PBAC) compares with previous methods · Understand the growing importance of authorization in today's threat and compliance landscape and how it protects digital assets.
Learn about the Microsoft Learn for Educators program and how to best deliver its content to your students. Prepare to deliver Microsoft’s security solutions, SC-900 Microsoft Security, Compliance, and Identity Fundamentals in academic program.
Learn how to work with subscriptions, users, and groups by configuring Microsoft Entra ID for workloads.
In the world of increasing security risks, do you know which threats are most critical to your network? Using actionable intelligence, you can not only identify but resolve immediate threats by applying proactive analytics to your enterprise and create in-depth views of areas of access. This intelligence allows the application of custom analytics to massive amounts of data and provides a comprehensive, real-time view of the multi-dimensional relationships between identities, access rights, policies, resources, vulnerabilities, and more across enterprise systems. Join Core Security and (ISC)2 on June 9, 2016 at 1:00PM Eastern for a Security Briefings that will examine the opportunities for using actionable insight with your data to deter, detect, and remediate vulnerability and access risk.
Implement end-to-end security for Azure SQL Database and SQL Managed Instance. Configure Entra ID authentication with managed identity access, deploy private endpoints, and apply encryption and access controls to protect sensitive financial data. Establish compliant audit trails and enable Microsoft Defender for Databases to detect SQL injection, anomalous access, and vulnerability exposures.
Learn how to secure identities used by AI workloads in Azure. Build skills in workload identity architecture, access management, Conditional Access, and identity risk response by using Microsoft Entra.
Every second counts in the fight to prevent, detect and respond to an Insider Threat. You need to be able to make smarter, faster decisions when it comes to detecting suspicious behavior and preventing further damage. Join this webinar to learn about how you can properly secure access to your critical crown jewel data, automate the process of identifying risky users through user behavior analytics, and shutting down their access with identity governance. See how integration between security analytics and identity and access management tools provide automated, user-centric threat mitigation.
***This course was developed by members of AWS Technical Field Communities (TFC), an AWS community of technical experts. The content is intended to complement our standard training curriculum and augment your AWS learning journey. We are aware some courses have accessibility limitations and are working to address. If you require accommodation, please contact [AWS Training and Certification Customer Support](https://support.aws.amazon.com/#/contacts/aws-training).*** In this course you will learn how to choose an AWS identity or access management service, what each service does, and which services are applicable to your current needs.
The ongoing transition to cloud platforms has meant that more sensitive data is stored in the cloud, making it more tempting for adversaries to exploit. When it comes to securing the cloud, identity is the first line of defense. Proper identity and access management (IAM) policies are the foundation of comprehensive cloud security principles. To understand how IAM policies affect organizations' cloud security posture, Unit 42 researchers analyzed 680,000+ identities across 18,000 cloud accounts from 200 different organizations. The results of our research were shocking - nearly all organizations we analyzed lack the proper IAM management policy controls to remain secure. Misconfigured IAM policies open the door for cloud threat actors. We define a cloud threat actor as "an individual or group posing a threat to organizations through directed and sustained access to cloud platform resources, services or embedded metadata." Cloud threat actors merit a separate definition as they employ a fundamentally different set of tactics, techniques and procedures (TTPs) that are unique to the cloud – such as taking advantage of the ability to perform both lateral movement and privilege escalation operations simultaneously. Join Palo Alto and (ISC)² June 2, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webinar where the audience will be guided through the latest research in overprivileged IAM identities in real-world cloud environments and how cloud threat actors are zeroing in on these excessive permissions to expand their control of cloud environments. Detection and mitigation of these risks are possible, join us to find out how!
The identity and access (IAM) management market is experiencing a watershed moment in the wake of the global pandemic. The implementation of cloud, data analytics, and other digital initiatives. Have accelerated, but so too have cyber threats. IAM initiatives have risen in priority as organizations look to enable the digital business, while simultaneously tightening their belts on security. Join SailPoint and BeyondTrust, along with (ISC)2 on January 11, 2022 at 1:00 p.m. for a discussion on the ever evolving threat landscape and how it is shaping IAM business drivers. We’ll explore how regulations like GDPR, CCPA and the recent Biden Administration’s Executive Order on Improving the Nation’s Cybersecurity are impacting the IAM market. Lastly, we’ll outline the Top 5 IAM Market trends for 2022.
Want to know which IT security technologies are hot and which ones are not? 2020 has thrown many purchasing and deployment plans into a state of flux and your organization has probably been caught up in this. Join Steve Piper, Founder & CEO of CyberEdge (and a proud CISSP) and (ISC)2 on Tuesday, July 28, 2020 at 1:00PM Eastern as Steve reviews key purchase insights from the 2020 Cyberthreat Defense Report. Specifically, this webcast will examine which security technologies are most widely deployed and most planned for acquisition in 2020 so you can benchmark your company’s current and planned investments against your peers. Purchase intent across five key security technology categories will be focused on including: •Network security •Endpoint security •Application and data security •Security management and operations •Identity and access management
Want to know which IT security technologies are hot and which ones are not? Join Steve Piper, Founder & CEO of CyberEdge (and a proud CISSP), and (ISC)2 as Steve reviews key purchase insights from the 2021 Cyberthreat Defense Report. Specifically, this webcast will identify those security technologies most widely deployed and most planned for acquisition in 2021 so you can benchmark your company’s current and planned investments against your peers. We'll review adoption rates of emerging technologies, such as ZTNA and SASE, and examine purchase intent across five key security technology categories, including: • Network security • Endpoint security • Application and data security • Security management and operations • Identity and access management
According to the CrowdStrike 2025 Global Threat Report, voice phishing (vishing) attacks surged 442% between the first and second half of 2024, and there was a 50% rise in dark web advertisements selling stolen credentials in 2024 . Adversaries like CURLY SPIDER and SCATTERED SPIDER exploit stolen credentials and legacy privileged access management tools to escalate privileges and move undetected within minutes. Join us for an exclusive look at how CrowdStrike Falcon® Privileged Access delivers just-in-time protection to stop them. In this session, you’ll discover how CrowdStrike’s latest innovation: • Delivers just-in-time access without the operational complexity • Blocks privilege escalation and lateral movement in real time • Supercharges your SOC with identity-driven automation • Expands protection across hybrid environments
AI agents operate with real enterprise permissions. They can gain those permissions quickly through their own identity or a borrowed one, while most identity programs still move at the pace of employee onboarding. Netwrix’s 2026 Data and Identity Security Report shows the cost of this mismatch: Organizations where AI significantly expanded the identity footprint reported a 43% breach rate, compared with 11% where it did not. Many fast adopters were already ahead of their peers on security fundamentals. This session on September 15, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific examines the data behind the gap: why 74% of organizations lack a unified view of sensitive data and the identities that can access it, why only 19% fully govern non-human identities even though 41% already use agentic AI in production, and why compromised identities and misconfigured permissions account for 75% of sensitive data exposures. We will close with the two areas where organizations fall furthest behind: remediation speed, with only one in four acting immediately through automation, and hidden escalation paths in Active Directory, where just 26% trust that their environment has no misconfiguration that could enable privilege escalation. Attendees will leave with a maturity benchmark for governing identity and data at machine speed. 1 Group A CPE
Safeguarding health systems against cyberattacks is a round-the-clock responsibility. 75% of all detections are malware-free activities and involve identity techniques, as analyzed by our CrowdStrike Overwatch team. What this means is most adversaries are not “breaking in” but are “logging in” oftentimes without being detected by stealing credentials and bypassing unmanaged endpoints to execute an attack. Listen to this on-demand session where CrowdStrike healthcare executive strategists, Todd Felker and Wael Younan, discuss ways to prevent your health system from identity-related attacks. Together, they explore how cross-domain visibility and enforcement can enable security teams to detect lateral movement, gain comprehensive insight into attack paths, and identify malicious activity. Key takeaways: • How adversaries are using identity attacks and their impact to healthcare • Use of Remote Monitoring and Management (RMM) tools and social engineering tactics • Understanding of Access Brokers and their involvement in identity attacks • Key solutions to identify sophisticated adversary access methods to help prevent and protect against them
When it comes to making access decisions, it’s all about being smart. In the speed of today’s business agility requirements, we cannot stop users at the door all the time and ask for their ID. We need to know them. Intelligent Authentication provides the benefit of reducing friction AND adding security to protect applications and data that are critical to the business. It provides security and convenience, considering the needs of the modern workforce. In this session we will discuss a simple process to gain visibility into the right listening posts, derive actionable insights and then drive action to protect the organization’s most valuable assets from rogue access and drive Identity Assurance.
Explore the digital footprints of a malicious hacker and uncover their attack path, as we take you for a journey inside the mind of a threat analyst responding to a cybersecurity incident that brought a business to a complete halt. Discover the evidence left behind, uncover the attack path, and understand the techniques used by the attackers. This session will delve into a real-world incident response, showcasing the methods employed by attackers to compromise identities and credentials. Join ISC2 and Delinea as we guide you through the steps taken by cybercriminals during a damaging identity compromise attack, including: • Access Gaining and Patient Zero Identification: Learn how attackers initially infiltrated systems and identified the first compromised system. • Establishing Staging, Footholds and Persistence: Understand how attackers set up their presence within the network and maintained access over time. • Tools and Commands Used: Discover the specific tools and commands utilized by the attackers, including RDP Brute Force, Mimikatz and Responder. • Credential Harvesting and Misuse: See how attackers harvested credentials and used them to escalate privileges and move laterally within the network. • Active Directory (AD) Elevation: Learn how attackers achieved AD elevation to gain further access and control over the infrastructure. Gain a comprehensive understanding of the tactics, techniques and procedures (TTPs) used by cyber criminals to compromise identities and credentials. This knowledge will empower you to better defend your organization against such cyberattacks.
This lightboard video explores how modern adversaries use stolen credentials to log in rather than break in, making identity a primary attack target. It explains how CrowdStrike Falcon Next-Gen Identity Security unifies SaaS posture management, identity threat detection, and secure privileged access to deliver complete visibility and protection across every identity to stop threats.
Changes in how we build, run and secure information systems have also changed how we look at authentication and access control. The emerging concept of identity is transforming the ways that humans and non-human actors alike make use of data and compute power. At the same time, organizations’ focus on identity also means that it has become a focus for attackers. To assess the ways that old and new attacks are targeting digital identities, F5 Labs is presenting findings from our 2023 Identity Threat Report: The Unpatchables. In a follow-up to the September session on credential stuffing, this talk will focus on phishing and multi-factor authentication bypass techniques. As phishing has grown over the last several years, its tools and tactics have transformed. We will identify which organizations are most targeted and explore recent developments that make it harder to spot and trickier to mitigate, using a combination of Dark Web intelligence and quantitative methods. This talk on October 19, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific will cover recent developments in attacker approaches to circumvent multi-factor authentication, what these developments mean for defenders, and which forms of MFA are able to resist the new approaches.
Changes in how we design, build, run and secure information systems have also changed how we look at authentication and access control. The emerging concept of identity is transforming the ways that humans and non-human actors alike make use of data and compute power. At the same time, the emergence of identity as a focus for organizations also means that it has become a focus for attackers. To assess the ways that old and new attacks are targeting digital identities, F5 Labs is presenting findings from our 2023 Identity Threat Report: The Unpatchables. On September 19, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific this session will focus on credential stuffing. This will be the first of two sessions. We will quantify its prevalence, explore targeting trends such as attackers’ choice of industries and endpoints, and outline credential stuffing tactics, techniques and procedures (TTPs). We will also take a deeper look into some case studies, with a particular focus on the differences between basic and sophisticated attacks. This talk will also assess the stolen credentials supply chain before focusing on mitigation strategies for combating credential stuffing.
Learn to design and implement strong authentication controls, apply Just-in-Time privileged access strategies, and extend identity-based security to AI-powered applications using Microsoft Entra.
As organizations have rapidly migrated to the cloud, adversaries have honed their craft to exploit the gaps that leave businesses vulnerable to cyberattack. In this CrowdCast, we take an adversary-focused approach to defend against three commonly exploited attack vectors: supply chain, cloud environments and user identities. Join CrowdStrike to: • Learn why taking an adversary-focused approach helps security and incident response teams focus their resources and proactively apply defenses • Understand how global cloud adoption and remote work has left organizations vulnerable to cyberattacks • Learn how real-world adversaries are currently exploiting cloud misconfigurations, user identities and supply chains • Gain access to best practices to defend against sophisticated adversary attacks
SCATTERED SPIDER, COZY BEAR, and other identity-focused adversaries have made identity-based attacks on cloud environments more prevalent than ever. The alarming rise in access brokers have made it easy for adversaries to buy stolen credentials. To combat these threats, you need a trusted Identity Threat Detection and Response (ITDR) solution that goes beyond only focusing on Microsoft AD. CrowdStrike is proud to unveil significant product innovations that extend our industry-leading ITDR solution to protect cloud-based identity environments—like Microsoft Entra ID—and support the latest authentication frameworks. Watch this CrowdCast to: -Learn from CrowdStrike experts as they detail the anatomy of SCATTERED SPIDER’s successful identity-based attacks. -See how CrowdStrike Falcon® Identity Protection can safeguard your organization against the latest identity tactics, techniques, and procedures (TTPs) of today’s prolific adversaries. -Watch a LIVE demo highlighting the latest identity protection product innovations introduced by CrowdStrike.
“Identity Security is the foundation for Zero Trust”. This statement has been widely accepted within the cyber-security industry since most breaches result from weak credentials and unmanaged accounts. Identity is the foundation by which you assert your relationship with an organization. How you justify the applications and data, you should be allowed to access and what you can do with it. Join SailPoint and Optiv, along with (ISC)2 for a discussion on why Identity Security is decidedly the foundation for Zero Trust, how it enables the other Zero Trust pillars, and how to set the foundation for your entire Zero Trust journey.
Passwords are easily the most irritable thing for securing your digital identity. Be it workforce or consumers, everybody gets bogged down with the task of remembering passwords for multiple websites and applications. They are also the weakest form of security, often hacked by cybercriminals. With the advent of biometrics and their widespread reach (thanks to smartphones), passwordless access became a reality with mobile push authentication. As biometrics are unique to every individual, it is a pretty secure way to access applications and authorize transactions. Passwordless techniques were further modified with the introduction of physical keys (USB devices). But the foremost approach to passwordless access is credential based authentication which works on the principal of securing both your device and identity. Join us for a session where we will talk about all things passwordless. We’ll examine: · How security paradigms changed with COVID-19 ? · Why is the world moving towards passwordless ? · Different types of Passwordless solutions offered by Entrust Identity · How to secure your workforce with Entrust Identity's high assurance passwordless solution
Ever heard the expression, “you can’t hit what you can’t see?” Well that sentiment rings true when it comes to protecting access to critical resources. You can only secure what you actually take steps to protect. .As such, secure access needs to be pervasive and cover all access user cases, regardless of whether applications and resources live on-premises or in the cloud. And because it’s likely have both, you need a solution that works equally well across these hybrid environments. In this session we will explore five critical secure access use cases, and how you can achieve a high-level of identity assurance that users are who that claim to be so that you can avoid falling victim to the next wave of credential-based attacks.
The rise of agentic AI does not replace your existing PKI and Data Security priorities. It makes them more urgent. You must still protect the sensitive data AI agents can access, secure cryptographic assets such as encryption and signing keys, and reduce reliance on fragmented, manual PKI processes. As agents become more autonomous, you will also need to establish verifiable identities for them and manage their certificates at greater speed and scale. On October 20, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific, sponsor Entrust and host ISC2 will examine what agentic AI means for data protection and PKI teams today, and how those requirements will evolve as agents become more autonomous. We will discuss how a modern cryptographic foundation can help protect data, improve visibility, automate certificate lifecycles, discover AI agents and their dependencies, assess compliance readiness, and establish verifiable identities for agents and AI workloads. You will gain a pragmatic framework for preparing existing PKI and data protection environments for agentic AI, while building on infrastructure and security practices you already trust.
Identity is the front line in the battle against modern cyber threats. Nearly 80% of cyberattacks leverage compromised credentials to gain access and evade detection. These attacks often come in via unmanaged or rogue endpoints, legacy systems, supply chain vendors or other attack vectors that are outside the scope of endpoint-centric security controls. Join CrowdStrike experts as they will unpack the current state of identity-based threats and how Falcon Complete managed detection and response is changing the game for security teams. In this webcast, you’ll hear: • Insights from Falcon OverWatch elite threat hunters, who’ll share trends and stories about how today’s attackers are obtaining and abusing credentials, and. blending in with day-to-day activity • How the Falcon Complete team of security analysts are leveraging identity threat protection to keep ahead of the evolving threats • Guidance you can use to protect your own organization from identity-based threats
Identity is the front line in the battle against modern cyber threats. Nearly 80% of cyberattacks leverage compromised credentials to gain access and evade detection. These attacks often come in via unmanaged or rogue endpoints, legacy systems, supply chain vendors or other attack vectors that are outside the scope of endpoint-centric security controls. Join CrowdStrike experts as they will unpack the current state of identity-based threats and how Falcon Complete managed detection and response is changing the game for security teams. In this webcast, you’ll hear: • Insights from Falcon OverWatch elite threat hunters, who’ll share trends and stories about how today’s attackers are obtaining and abusing credentials, and. blending in with day-to-day activity • How the Falcon Complete team of security analysts are leveraging identity threat protection to keep ahead of the evolving threats • Guidance you can use to protect your own organization from identity-based threats
Remote and hybrid work are now permanent realities, but they have dramatically expanded the attack surface and introduced new security challenges. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores how organizations can protect users, devices, and data—without slowing down the business or frustrating employees. This webinar will cover practical strategies for securing access, managing endpoints, and protecting sensitive information across distributed environments. Steve will discuss how modern identity controls, cloud security, and user-focused policies can reduce risk while supporting flexibility and performance. Attendees will leave with actionable guidance to balance strong security with a seamless employee experience.
Peel back any compliance framework, and you'll find a person hiding under it. Attestation means somebody put their name on a claim and would rather not be embarrassed. Access review means asking whether this particular human still needs this particular key. Every one of those mechanisms runs on intent, judgment, and consequences, and every one of them stops meaning anything the moment you remove the human. Agents bring none of the three to work. An agent has objectives rather than intent, inference rather than judgment, and no meaningful exposure to being walked out by HR on a Friday. What it does have is production credentials, commit access, the ability to provision infrastructure, and sometimes a company card. Most organizations have onboarded an extraordinarily privileged insider who skipped the background check, never got a least-privilege review, reports to nobody in particular, and has no offboarding process. This session on September 29, 2026 at 1:00 p.m.Eastern/10:00 a.m.Pacific sponsor Snyk does the practical translation. We'll figure out how to build an evidence trail that can answer "who granted this capability?" now that "who performed this action?" returns something unhelpful. Key Takeaways -How to treat AI agents as non-human identities with a complete lifecycle: provisioning, least privilege, periodic review, and revocation that actually happens. -How to relocate accountability to the point of delegation. -What breaks in attestation, access review, and incident response when your actor can't be held responsible for anything. 1 Group A CPE
Watch this video on how CrowdStrike secures non-human identities against modern threats including AI agents, API's and SVC accounts. Complete visibility and across on-prem, cloud and SaaS applications. Manage and enforce privileged access accounts in real-time.
The number of exposed consumer records more than doubled in 2018 from 2017, according to the Identity Theft Resource Center, but enterprises don’t have to be a victim. Most attacks can be prevented by deploying the right mixture of products and processes. The primary goal is to coordinate and optimize your security defenses. A simple, but coordinated, security defense strategy allows you to: • Validate equipment readiness • Prevent access from bad IP addresses • Decrypt malicious traffic • Analyze traffic in real-time • Perform advanced data analytics • Enable DPI In this webcast, Keysight and (ISC)2 will explore an overview of defensive security, a six step approach to defensive security and examples of visibility and security solutions that make this approach work.
ISC2 Security Congress 2025 is right around the corner, and we’re so excited about this year’s speaker line-up that we decided to bring a sample of this year’s content to you early! Join three of our esteemed conference speakers as they provide highlights into their session content – all focused around AI. By joining this session you’ll get a snapshot of session content, which includes the following presentations: Agentic AI: Navigating the Uncharted Waters of Non-Human Identity and Liability How AI Will Shape the Shift-Left approach in AppSec Threat Modeling AI: STRIDE Was a Good Start, But This Is Weirder Join us live to be among the first to gain valuable insights into these sessions, plus have an opportunity to as your questions. Like what you see? Register for ISC2 Security Congress 2025to unlock access to even more great content this October. You won’t want to miss this enlightening webinar that's the first in a series of three, 2025 Security Congress Sneak Peek webinars!