# ICAM and MFA Fundamentals

Canonical URL: <https://www.nobledesktop.com/classes/icam-and-mfa-fundamentals>

## Overview

A foundational course on Identity, Credential, and Access Management for anyone who needs to understand the identity layer without becoming an identity engineer. It runs the full chain in order — identity, proofing, authentication and MFA, authorization, federation, and finally the access decision itself — so each piece arrives with the previous one already in place.

The MFA material is what buyers are asking for. Most identity training stops at "turn on MFA." This course explains _which_ MFA, and why. Rather than treating multifactor as one checkbox, it separates the authenticator types, sets out the assurance levels behind them, and works through the attacks aimed squarely at MFA: phishing, MFA fatigue, credential theft, and adversary-in-the-middle. Participants finish able to explain why a push notification and a hardware security key are not equivalent controls. The closing module is applied. Participants work short scenario exercises framed as "Should this user get access?", pulling identity, credential, authentication, and authorization together into a single judgment, the way a Zero Trust access decision is actually made. Across the course participants work with the IAL, AAL, and FAL assurance-level model, PIV and other hardware-backed credentials, Zero Trust access decisions, RBAC and ABAC, and an introduction to SAML, OAuth, and OpenID Connect.

## What you'll learn

- Distinguish identity, account, credential, and authenticator, and explain how identity, authentication, authorization, and access relate to each other
- Explain identity proofing and the joiner, mover, and leaver lifecycle, including provisioning, revocation, and termination
- Apply the assurance-level model, IAL, AAL, and FAL, to real access situations
- Compare common MFA methods and explain why stronger methods provide greater assurance
- Recognize attacks aimed at MFA, including phishing, MFA fatigue, credential theft, and adversary-in-the-middle
- Apply least privilege, need-to-know, role-based access control, and attribute-based access control to authorization decisions
- Explain federation and single sign-on, including identity providers, relying parties, credentials, and assertions
- Work a full access transaction end to end and judge whether a given user should be granted access

## Prerequisites

Basic cybersecurity knowledge.

## Schedule
- Jan 7, 2027 9:00am–4:30pm — Live Online
- Feb 22, 2027 9:00am–4:30pm — Live Online
- Mar 9, 2027 9:00am–4:30pm — Live Online
- Apr 26, 2027 9:00am–4:30pm — Live Online
- May 19, 2027 9:00am–4:30pm — Live Online
- Jun 11, 2027 9:00am–4:30pm — Live Online
- Jul 23, 2027 9:00am–4:30pm — Live Online

## Pricing

**Tuition:** $799
