In this lesson, I take a deep dive into the identity lifecycle, including identity creation, identification, authentication, authorization, and deprovisioning. We will also look at DAC, MAC, role-based access control (RBAC), attribute-based access control (ABAC), and needed authorization solution attributes.
Table of Contents
00:00 - Intro
00:45 - Identity Lifecycle
01:15 - Identity Creation
02:00 - Authentication and Authorization
03:45 - Deprovisioning
05:00 - Unique ID Requirement
05:45 - Privileged Access Management
07:37 - Single Sign-on
08:44 - Factors of Authentication
09:47 - Type I Authentication
11:52 - NIST 2021 Password Guidelines
14:26 - Cognitive Passwords (Secret Questions)
15:41 - Type II Authentication
16:11 - OTP Walkthrough
17:26 - Type III Authentication
18:20 - Biometrics Errors
19:42 - Approaches to Authorization
20:02 - Role-based Access Control (RBAC)
20:58 - Rule-based Access Control
21:45 - Mandatory Access Control (MAC)
22:37 - Discretionary Access Control (DAC)
23:22 - Attribute-based Access Control (ABAC)
24:43 - Desirable Traits of Authorization Schemes