Identity Access Management: PAM, JIT, JEA, ABAC, SAML, OAuth
In a cloud-native world, firewalls don't matter if your identity is compromised. "Identity is the New Perimeter." In this video, Sec Guy explains why Permanent Admin Rights are a security failure, how to implement Just-in-Time (JIT) access to stop attackers, and clearly defines the difference between SAML (XML/Enterprise), OAuth (Authorization), and OIDC (Authentication). π₯π₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide π₯π₯ [Exam Ready Route - FREE] Pass your certification for $0. β
Training Videos & Practice Tests β
Sec Guy Mobile Lab (On-the-go training powered by AI voice) β
Discord Access (Study sessions & Industry networking) π Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. π₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs π₯ Salary Negotiator Workshop π₯ Experience Builder: Real-world projects to fill your resume π Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 1.3: Identity and Access Management (SAML, OAuth, OIDC, ABAC vs. RBAC) [ ] Domain 1.4: Access Control Schemes (PAM, JIT, JEA) CISSP [ ] Domain 5: Identity and Access Management (Federated Identity, SAML, OIDC, Authorization vs. Authentication) CISM [ ] Domain 3: Information Security Program (Identity Lifecycle & Access Governance) CRISC [ ] Domain 2: IT Risk Assessment (Privileged Access Risks) CCSP [ ] Domain 4: Cloud Application Security (Federated Identity Management & XML/JSON usage) SecurityX (CompTIA) [ ] Domain 1.0: Security Architecture (Implementing Zero Trust Identity) GIAC GSEC (SANS) [ ] Access Control & Password Management: Federation & OAuth AWS CSS (Certified Security β Specialty) [ ] Domain 3: Infrastructure Security (IAM Roles, Federation, & Temporary Credentials) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Token Theft & Forging SAML Assertions) CEH (Certified Ethical Hacker) [ ] Domain 6: System Hacking (Privilege Escalation via Misconfigured IAM) SecAI+ [ ] AI Security: Workload Identity Federation for AI Agents (Non-Human Identities) [Timestamps] 0:00 - Intro: Identity is the New Perimeter 0:32 - Privileged Access Management (PAM): The Keys to the Kingdom 1:00 - Just-In-Time (JIT) vs. Just-Enough-Administration (JEA) 1:56 - ABAC vs. RBAC: Why Context Matters (Time/Location/Device) 2:32 - Federated Identity: Moving Trust Across the Internet 2:45 - SAML (XML): The Enterprise SSO Standard 3:05 - OAuth 2.0 (Authorization): "What You Can Do" vs. "Who You Are" 3:22 - OIDC (Authentication): The JSON Layer on Top of OAuth 3:42 - The Cryptography of Tokens: Signing & Hashing (JWTs) 4:42 - Non-Human Identities (NHI): Securing AI Agents & Service Accounts 5:14 - Summary: Identity is Proof, Not Just a Username 5:31 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=y_2UfJnrYtM