# ICAM and MFA Fundamentals Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/icam-and-mfa-fundamentals-self-paced>

## Overview

Identity, Credential, and Access Management, taught for the federal staff who need to understand the identity layer without being identity engineers. The course runs the full chain in order: identity, proofing, authentication and MFA, authorization, federation, and the access decision itself.

Lead with the MFA material, because that is the part agencies are under pressure on. Most identity training stops at "turn on MFA"; this one explains which MFA and why. Multifactor is broken apart rather than treated as a single checkbox: authenticator types are separated, the assurance levels behind them are explained, and the attacks aimed directly at MFA are covered in detail — phishing, MFA fatigue, credential theft, and adversary-in-the-middle. Learners come away able to say why a push notification and a PIV card are not equivalent controls. The final module is applied. Short scenario exercises framed as "Should this user get access?" require learners to pull identity, credential, authentication, and authorization into a single decision, in the way a Zero Trust access decision is actually made. The course works with the federal assurance-level model (IAL, AAL, and FAL), PIV credentials in federal environments, Zero Trust access decisions, RBAC and ABAC, and introductory SAML, OAuth, and OpenID Connect.

## What you'll learn

- Distinguish identity, account, credential, and authenticator, and explain how identity, authentication, authorization, and access relate to each other
- Explain identity proofing and the joiner, mover, and leaver lifecycle, including provisioning, revocation, and termination
- Apply the assurance-level model, IAL, AAL, and FAL, to real access situations
- Compare common MFA methods and explain why stronger methods provide greater assurance
- Recognize attacks aimed at MFA, including phishing, MFA fatigue, credential theft, and adversary-in-the-middle
- Apply least privilege, need-to-know, role-based access control, and attribute-based access control to authorization decisions
- Explain federation and single sign-on, including identity providers, relying parties, credentials, and assertions
- Work a full access transaction end to end and judge whether a given user should be granted access

## Prerequisites

Basic cybersecurity knowledge.

## Curriculum

#### Module 1

- Identity Is the New Perimeter: ICAM Foundations
- What ICAM means
- Identity versus account versus credential versus authenticator
- Human and non-person identities
- Why ICAM is foundational
- ICAM's role in Zero Trust

#### Module 2

- Who Are You? Identity Proofing and the Identity Lifecycle
- Proofing and enrollment
- Establishing confidence in a claimed identity
- Identity Assurance Levels
- Provisioning
- Joiner, mover, and leaver
- Authoritative sources
- Disabling, revocation, and termination

#### Module 3

- Prove It: Authentication and MFA Essentials
- Identification versus authentication
- The three-factor types
- Single-factor versus MFA
- Multi-factor authenticators versus multiple authenticators
- Passwords, OTPs, cryptographic authenticators, and biometrics
- AAL1, AAL2, and AAL3
- Phishing-resistant authentication

#### Module 4

- Beyond the Password: MFA Technologies and Threats
- Authenticator apps and one-time passcodes
- Push-based authentication
- Smart cards and cryptographic credentials
- PIV credentials in federal environments
- Biometrics
- Phishing, MFA fatigue, credential theft, and adversary-in-the-middle attacks

#### Module 5

- Who Gets Access? Authorization and Access Control
- Authentication versus authorization
- Subjects, objects, permissions, and entitlements
- Least privilege and need-to-know
- RBAC and ABAC
- Privileged access; access reviews and recertification
- Separation of duties

#### Module 6

- Trust Across Systems: Federation and Single Sign-On
- What federation means
- Identity provider and relying party
- Credentials versus assertions
- Single sign-on
- Federated authentication
- Federation Assurance Levels
- Introductory SAML, OAuth, and OpenID Connect
- Benefits and risks of centralized and federated identity

#### Module 7

- Putting ICAM to Work: From Identity to Access Decision
- A typical access transaction from sign-in to resource access
- Applying IAL, AAL, and FAL
- MFA selection based on risk
- Zero Trust access decisions
- Logging and monitoring identity activity
- Common ICAM implementation mistakes
- Scenario exercises

## Pricing

**Tuition:** $799
