Identity
Treat identity as the primary control plane for deciding who receives access and under what conditions.
Identity & Access
A hands-on security lab focused on identity as the control plane: authentication, authorization, Conditional Access, lifecycle management, privileged access, and practical Zero Trust design.
Overview
Many security decisions eventually become identity decisions: who is requesting access, what they are allowed to reach, what conditions should apply, and how that access changes over time.
This lab gives me a structured environment for studying identity security beyond certification theory. The focus is on designing access around business roles and security conditions rather than simply granting permissions.
The project is intentionally iterative. I am building and documenting scenarios as my Entra ID, IAM, cloud security, and Zero Trust skills expand.
Identity Architecture
Treat identity as the primary control plane for deciding who receives access and under what conditions.
Use stronger authentication controls and MFA to reduce dependence on passwords alone.
Apply role-based access and least privilege so users receive only the permissions required for their responsibilities.
Design repeatable joiner, mover, and leaver processes so account access follows the user's relationship with the organization.
Lab Work
The lab is organized around practical identity problems rather than isolated product features.
Project Status
This project is actively being developed. The page documents the lab design and the areas being implemented as my identity security work expands.
Design access policies around authentication strength, device state, user risk, location, and application sensitivity.
Explore how stronger authentication can be introduced while maintaining usability and operational continuity.
Model permissions around job responsibilities instead of assigning broad access directly to individual users.
Build repeatable processes for creating, modifying, disabling, and reviewing user access.
Evaluate how administrative access should be separated, limited, monitored, and used only when required.
Explore periodic validation of permissions so access does not accumulate indefinitely as roles change.
Zero Trust
Use identity, authentication context, risk, device state, and other available signals when making access decisions.
Reduce standing access and design permissions around what users and administrators actually need.
Design access so one compromised account or device does not automatically provide unrestricted movement.
“Identity should answer more than who you are. It should help determine what you can reach, under what conditions, and for how long.”
Lessons
Identity architecture is as much about lifecycle and governance as authentication.
Least privilege becomes harder to maintain when access is assigned directly instead of through well-designed roles.
Security controls need to account for user experience and operational requirements.
Documentation makes identity decisions easier to review and improve.
Next Steps
Build additional Conditional Access scenarios
Document joiner, mover, and leaver workflows
Expand privileged-access design
Add access-review exercises
Map controls to practical business scenarios
More Projects