IAM fundamentals: The 4 A’s framework

What is IAM

IAM is identity and access management. It answers the question: WHO gets to do WHAT in your systems, and can you PROVE it later.

The question breaks into 4 jobs, and I call them the 4 A's: Administration, Authentication, Authorization and Audit. Every IAM vendors sells 1/2 of them, usually not all due to complexity of each phases

If you learned network security, this looks like AAA: authentication, authorization, accounting. Identity has 2 other things. Administration help you manage granting and removing access automatically. And Accounting now becomes audit, from counting what happened to proving it to a regulator or checker that what did happen.

The 4 A's as capabilities

Capabilities at the top, vendor at the bottom, and a dot where a vendors sells that capability

IAM as four capabilities, and which vendor market sells each

Expanding the 4 A's in detail

Administration is the lifecycle: joiner, mover, leaver. Access is granted when someone arrives, adjusted when they change roles, removed when they go. It sounds boring but in reality it is where most real failures start: the mover who kept last year's access, the leaver still had account.

Authentication proves you are who you say you are. Passwords, MFA, passkeys, single sign-on, and then a signed token that other systems trust. The answer, the resouces they can access changes a lot between an employee, a customer and a machine.

Authorization decides what you may do once you are in. Roles, attributes, policies. The useful split here is the decision point, which says yes or no, and the enforcement point, which actually blocks or allows. Many apps or system mix the two together to have layering of authorization.

Audit proves all of the above to someone else later. Who had access, who approved it, who used it, and whether anyone reviewed it. There will be audit when having failure, incident to know exactly the actor is a normal people or a thread actor that we dont allow to acess.

Vendor market

Vendor provide solutions for mostly 2/4 A's

  • IGA (identity governance and administration) sells administration and audit together: who should have access, and can we prove it. SailPoint and Saviynt live here. The products are certification campaigns, role models and lifecycle plumbing.
  • IdP (identity provider) sells authentication: prove the person, then sign them into things. Okta for workforce, Auth0 for customers, Entra ID if you live in the Microsoft empire, Ping in heavy-federation enterprises, Keycloak when you would rather host it yourself and dont want to spend money.
  • PAM (privileged access management) sells authorization at its sharpest edge, plus its own audit: who can act as root, and are we watching them do it. CyberArk is the key vendor for banks. Think about vaults and session recording.

In a standard RFP process, map what you need to vendor that offering the capability, and you own the gap from angle of end-to-end on how it should work together in your enterprise workflow.

Try it on your computer

You can learn both the model and how vendors package it without buying anything Authentication with Keycloak. Run it in Docker, create a realm and users, and put login in front of a mini app with OpenID Connect. Turn on MFA and look at the token you get back. This is what an IdP does.

docker run -p 8080:8080 \
  -e KC_BOOTSTRAP_ADMIN_USERNAME=admin \
  -e KC_BOOTSTRAP_ADMIN_PASSWORD=<pick-a-local-password> \
  quay.io/keycloak/keycloak:latest start-dev

Authorization with OPA. Build one small app where the decision lives in a policy engine like Open Policy Agent instead of if-statements, so the decision point and the enforcement point are really separate things.

docker run -p 8181:8181 openpolicyagent/opa:latest run --server

Administration with roles you mine yourself. Generate a few hundred synthetic identities with deliberately messy entitlements. Try bottom-up role mining against top-down role design, and compare what each finds. Add joiner, mover and leaver events and see what drifts.

Privileged access and audit with Vault. HashiCorp Vault is a secrets vault, not a full PAM product like CyberArk, but it shows the core idea: short-lived credentials handed out on request, with an audit log of every request.

vault server -dev
vault audit enable file file_path=/tmp/vault-audit.log

Then explore, break things based on a script and test the policies, and read the logs to see what happened. This will help you to have a detail view on how it work in real life before making the decision of buy or build

Why IAM and these gate matter more now

AI nowaday is helping attackers find and use a hack these gates faster than before, so who gets in, what they can do and what you can prove afterwards is more important to help business stays alive not just a security holes like before.