// syllabus

From zero background to job-ready in identity security.

The complete path across Level 1 foundations and Level 2 advanced tooling, the full governance, risk, and compliance stack, and a capstone that becomes a defensible line on your resume.

Format: Remote · self-paced (Bronze) or live sessions (Analyst & Engineer Tracks) Membership: Month to month · join anytime Mentors: Chad & Lance
Apply now. Spots are limited.
// the path

Two levels, one path.

Identity security is a specialty, not a generalist track. You go deep on the exact tools and frameworks that show up in real job descriptions, working in live environments instead of watching slides. Level 1 lays the foundations with Chad. Level 2 takes you into advanced work and the full GRC stack with Lance. No one advances to Level 2 before the fundamentals are genuinely solid.

Each topic lists what you'll be able to do, a hands-on lab, what you'll produce, and the industry certification it maps toward. Certifications are taken separately. Privance prepares you for them; it does not issue or guarantee them.

// level 1 · foundations · with chad

Foundations: the platforms underneath everything.

Assumes no prior tech background. You build a working understanding of how enterprise identity is structured, get your first hands-on privileged-access work, and learn the tooling the rest of the membership connects to.

Privileged access CyberArk

Privileged accounts are the most powerful credentials in any organization, and CyberArk is the platform most enterprises use to lock them down.

  • Vault and safe structure: how credentials are stored and segmented
  • Account onboarding and the basics of managing privileged accounts
  • Introduction to the Central Policy Manager (CPM) and rotation
  • Introduction to the Privileged Session Manager (PSM)
  • Core access policies and least-privilege thinking
You'll be able to
  • Explain what a privileged account is and why it's the top target in a breach
  • Navigate the vault, locate safes, and describe how credentials are segmented
  • Onboard a basic privileged account and retrieve a credential through the vault
  • Describe how CPM rotation and PSM session isolation protect a credential

Hands-on lab: Onboard a Windows local-admin account into a safe and check out its password through the vault.

You'll produce: A short walkthrough of one onboarded account and the safe and policy you placed it in.

Maps toward: CyberArk Defender (PAM-DEF), foundational track.

Identity and SSO Okta

Okta is how modern organizations centralize who can sign in and what they can reach. You learn how SSO and MFA work, then practice the lifecycle tasks identity teams handle every day.

  • Single sign-on (SSO) and federation fundamentals
  • Multi-factor authentication (MFA) and authentication policies
  • User lifecycle: create, update, deactivate, and offboard
  • Groups, roles, and application assignments
  • How Okta connects to directories and downstream apps
You'll be able to
  • Explain how SSO and federation let one login reach many applications
  • Enroll and enforce MFA for a user
  • Run the full user lifecycle: create, update, deactivate, offboard
  • Assign applications to users through groups and roles

Hands-on lab: Create a test user, enroll MFA, assign two apps via a group, then deactivate and confirm access is revoked.

You'll produce: A lifecycle checklist showing the user's access at create → active → offboarded.

Maps toward: Okta Certified Professional.

Active Directory Microsoft AD

Active Directory is the backbone that nearly everything else in IAM connects to. You learn how enterprise identity is organized and how the pieces of a domain fit together.

  • Domains, forests, and organizational units (OUs)
  • Users, groups, and group-based access
  • Delegation and basic administrative boundaries
  • Group Policy fundamentals
  • How AD feeds identity into Okta and CyberArk
You'll be able to
  • Explain domains, forests, and OUs and how they organize identity
  • Grant access through group membership instead of per-user permissions
  • Read a Group Policy object and describe what it enforces
  • Trace how AD identities flow into Okta and CyberArk

Hands-on lab: Build an OU, create a security group, add users, and apply a basic Group Policy setting.

You'll produce: A simple OU and group design diagram for a 20-person department.

Maps toward: CompTIA Security+ (identity & access domain); SC-300 readiness.

The Gate: readiness check

Chad signs off against a clear checklist before you advance. The fundamentals have to be solid first; advanced work only lands when the foundation is real.

// level 2 · advanced · with lance

Advanced: deeper into the same platforms.

Level 2 takes the tools you met in foundations and pushes into the work real identity engineers do: designing access, automating it, and managing privileged sessions at scale. Led by Lance, a practicing identity and privileged-access engineer.

Advanced CyberArk operate the vault

You move from understanding the vault to operating it: session management, credential rotation, and onboarding at scale become hands-on skills you can speak to in an interview.

  • Privileged Session Manager (PSM): monitoring and isolating sessions
  • Central Policy Manager (CPM): automated credential rotation
  • Bulk account onboarding and platform configuration
  • Safe design, access workflows, and approval flows
  • Session recording and audit trails for privileged activity
You'll be able to
  • Configure PSM to monitor and isolate a privileged session
  • Set a CPM policy to rotate credentials automatically
  • Onboard accounts in bulk and configure a platform
  • Design a safe with an access workflow and dual-control approval
  • Pull session recordings and audit trails for an investigation

Hands-on lab: Stand up a safe with an approval workflow, rotate a credential via CPM, and record an isolated PSM session end to end.

You'll produce: A documented safe design and rotation policy you can walk through in an interview.

Maps toward: CyberArk Sentry (PAM-SEN), advanced track.

Advanced Okta and provisioning identity at scale

You go beyond logging in to designing how identity flows through an organization: automated provisioning, policy-driven access, and the integrations that connect Okta to everything else.

  • Automated provisioning and deprovisioning across applications
  • SAML and OIDC application integration
  • Conditional and risk-based authentication policies
  • Directory integration and identity sources
  • Lifecycle automation and access request workflows
You'll be able to
  • Build automated provisioning and deprovisioning across connected apps
  • Integrate one app via SAML and another via OIDC
  • Write conditional and risk-based authentication policies
  • Connect a directory as an identity source and automate lifecycle events

Hands-on lab: Configure automated (SCIM) provisioning to one app, integrate a second via SAML, and trigger a risk-based MFA policy.

You'll produce: A provisioning and authentication-policy design for a sample organization.

Maps toward: Okta Certified Administrator (and the Consultant pathway).

Advanced Active Directory design & secure

You learn to design and secure the directory, not just navigate it: how access is structured, where it goes wrong, and how identity teams keep it clean and auditable.

  • Group and OU design for least privilege
  • Delegated administration and tiered access models
  • Group Policy at scale and security baselines
  • Synchronization between AD and cloud identity
  • Common access risks and how to remediate them
You'll be able to
  • Design groups and OUs for least privilege at scale
  • Implement a tiered administration model
  • Apply Group Policy and security baselines across many objects
  • Synchronize AD with cloud identity and spot and remediate access risks

Hands-on lab: Design a tiered-admin OU structure, apply a security-baseline GPO, and document three access risks with fixes.

You'll produce: A least-privilege AD design document with a tiering model.

Maps toward: SC-300 (Microsoft Identity & Access Administrator); CISSP IAM domain.

// level 2 · governance, risk & compliance

The compliance work that keeps regulated companies running.

Technical skill gets you in the door. Knowing the governance and compliance side is what makes you valuable to regulated employers in finance and healthcare. You learn the frameworks from real practice and connect them back to the access work you have already done.

Governance and SOX where identity meets the auditor

The access-control work that keeps public companies compliant, and how to produce the evidence an audit actually asks for.

  • Access reviews and periodic recertification
  • Segregation of duties (SoD) and conflict detection
  • IT general controls (ITGC) over access
  • Gathering and presenting audit evidence
  • Provisioning and deprovisioning as a controlled process
You'll be able to
  • Run a user access review and produce recertification evidence
  • Detect segregation-of-duties conflicts
  • Map IT general controls (ITGC) over access
  • Assemble an audit evidence pack an auditor will accept
  • Treat provisioning and deprovisioning as a controlled, evidenced process

Hands-on lab: Build a quarterly access-review evidence pack for a sample app, including a flagged SoD conflict and its remediation.

You'll produce: A SOX-style access-review evidence package.

Maps toward: ISACA CISA (audit), foundational exposure; CGRC pathway.

HIPAA and healthcare data protecting PHI

Healthcare is one of the largest employers of identity and access talent. You learn how protected health information is safeguarded through access control and what compliance looks like day to day.

  • Protected health information (PHI) and why it is regulated
  • The Privacy and Security Rules at a working level
  • Role-based access and the minimum-necessary principle
  • Access logging and audit controls for sensitive data
  • How identity teams support HIPAA compliance
You'll be able to
  • Identify PHI and explain why it is regulated
  • Apply the Privacy and Security Rules at a working level
  • Enforce role-based access and the minimum-necessary principle
  • Configure access logging and audit controls for sensitive data

Hands-on lab: Design a minimum-necessary RBAC model for a clinic application and define the audit logging it requires.

You'll produce: A HIPAA access-control and logging spec for a sample healthcare system.

Maps toward: HCISPP (HealthCare Information Security & Privacy Practitioner).

NIST frameworks a language for risk

NIST gives organizations a recognized language for managing risk. You learn how the major frameworks fit together and how identity controls map into them.

  • The Cybersecurity Framework (CSF) and its core functions
  • The Risk Management Framework (RMF) at a high level
  • Access-control families and how they map to your work
  • Identifying, assessing, and managing risk against a standard
  • How frameworks connect to SOX and HIPAA in practice
You'll be able to
  • Walk the CSF core functions: Identify, Protect, Detect, Respond, Recover
  • Describe the Risk Management Framework (RMF) lifecycle at a working level
  • Map access-control families to the hands-on work you've done
  • Assess and document risk against a recognized standard

Hands-on lab: Map your CyberArk, Okta, and AD work to NIST 800-53 access-control families and rate residual risk.

You'll produce: A control-mapping matrix tying your hands-on work to NIST families.

Maps toward: CGRC (Certified in Governance, Risk & Compliance); CISSP Security & Risk Management domain.

// bringing it together

A capstone that ties the tools to the frameworks.

Level 2 closes with applied work that connects what you've learned: privileged access, identity, and directory skills put to work against real governance and compliance requirements, the same way the job will ask you to. On the IAM Engineer Track, your capstone runs under Privance and becomes a defensible line on your resume, not a fabricated one.

// tracks

What each track includes.

 BronzeIAM Analyst TrackIAM Engineer Track
Target role Explore first IAM Analyst · ~6 months IAM Engineer · ~12 months
Typical US pay for the role $70k–$110k $110k–$160k+
Price $299one-time · yours to keep $275/mo · cancel anytime $675/mo · cancel anytime
Best for Self-paced foundations Getting hired as an IAM Analyst Going all the way to IAM Engineer
Recorded curriculum Entry IAM & CyberArk + compliance basics Everything in Bronze Everything in the Analyst Track
Live sessions No Foundations with Chad, advanced with Lance Foundations with Chad, advanced with Lance
Hands-on labs & full GRC track No Yes Yes
One-on-one with Lance No Bounded 1:1 time Extensive 1:1
Career services Private community Resume & LinkedIn coaching, mock interviews, portfolio project Resume & LinkedIn done for you, mentor support for as long as you stay a member
Real capstone under Privance No Portfolio project Capstone you can list as experience + a paid CyberArk course included

Month to month: every membership is an open-ended monthly subscription you can cancel anytime. No deposit, no upfront lump sum, no fixed term. A rotating weekly promotion may discount one membership further. The live deal is always shown on the pricing page.

// who teaches you

Taught by two people, start to finish.

Chad foundations lead

Entry IAM and CyberArk, IT and Active Directory fundamentals, core identity concepts. Runs Level 1 and signs off the readiness gate.

Lance advanced & GRC lead

A practicing identity and privileged-access engineer with enterprise and SOX-audit experience. Leads Level 2, the full GRC stack, the capstone, and career work.

// straight talk

What we promise, and what we don't.

No job is guaranteed. Privance provides the skills, verifiable hands-on experience, and mentorship; the effort and the interviews are yours. Certifications are earned separately through their providers. The membership prepares you for them but does not issue or guarantee them. No tech background is required. Bronze and Level 1 start from the fundamentals. Delivery is remote: Bronze is self-paced, while the IAM Analyst Track (~6 months) and IAM Engineer Track (~12 months) add live sessions you can join anytime.

// next steps

Ready when you are.

Apply now and we will help you pick the right track. Most people start with the Analyst Track. Month to month, cancel anytime. Engineer Track spots are limited. Questions? Email hello@privance.io.