{"product_id":"identity-security-fabric-unifying-ai-powered-iam-and-itdr","title":"Identity Security - AI Powered IAM and ITDR","description":"\u003cdiv\u003e\n\u003cp\u003eThis course is an \"Identity Bootcamp\", providing a progression from foundational identity best practices to advanced AI-driven implementation. It bridges the gap between proactive Identity and Access Management (IAM) and reactive Identity Threat Detection and Response (ITDR), using AI as the intelligence layer for real-time detection, behavioral analytics (UEBA), and automated response. The included LABs are built on a stack that supports Identity Orchestration, Behavioral Analytics, and Machine Identity Management.\u003c\/p\u003e\r\n\u003cp\u003eThe content is organized into 4 areas: The Human Element \u0026amp; Risk Orchestration, The Machine \u0026amp; Agentic Explosion, Identity Threat Detection \u0026amp; Response, and Privacy, Governance, and the Future. Zero Trust is the foundational philosophy of this course, woven into the curriculum by shifting focus from traditional perimeter security to \"Identity-First\" security.\u003c\/p\u003e\n\u003c\/div\u003e\u003cdiv\u003e\n\u003ch3\u003eIdentity Security - AI Powered IAM and ITDR Benefits\u003c\/h3\u003e\n\u003cul\u003e\u003cli\u003e\n\u003cp\u003e\u003cb\u003eCourse Benefits\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eModernize authentication with FIDO2, WebAuthn, and passkeys, replacing vulnerable shared-secret methods.\u003c\/li\u003e\n\u003cli\u003eBuild AI-driven risk engines using behavioral biometrics for continuous identity verification.\u003c\/li\u003e\n\u003cli\u003eSecure machine identities with SPIFFE and HashiCorp Vault using just-in-time credentials.\u003c\/li\u003e\n\u003cli\u003eGovern agentic AI through security guardrails that control permissions and prevent data leakage.\u003c\/li\u003e\n\u003cli\u003eMap identity attack paths and shadow administrators using graph analytics and BloodHound.\u003c\/li\u003e\n\u003cli\u003eAutomate threat response with Sigma rules and Wazuh-driven active defense playbooks.\u003c\/li\u003e\n\u003cli\u003eImplement next-generation privacy using Zero-Knowledge Proofs (ZKP) and Decentralized Identifiers (DID).\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003ePrerequisites\u003c\/b\u003e\u003c\/p\u003e\n\u003cp\u003eAttendees should have intermediate knowledge in networking and cybersecurity and knowledge of AI at the level of AI and Cyber Security: Attack and Defend.\u003c\/p\u003e\n\u003c\/li\u003e\u003c\/ul\u003e\n\u003c\/div\u003e\u003cdiv\u003e\u003ch3\u003eAI Identity Security Training Outline\u003c\/h3\u003e\u003c\/div\u003e\u003cdiv\u003e\n\u003ch4\u003eLearning Objectives\u003c\/h4\u003e\n\u003cp\u003e\u003cb\u003eModule 1: Architecture of Modern Authentication\u003c\/b\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eUnderstand the shift from shared secrets to cryptographic identity verification.\u003c\/li\u003e\n\u003cli\u003eAnalyze the limitations of SMS and TOTP-based MFA against modern attacks.\u003c\/li\u003e\n\u003cli\u003eImplement strong authentication using FIDO2 and WebAuthn.\u003c\/li\u003e\n\u003cli\u003eDeploy passkeys and passwordless authentication workflows.\u003c\/li\u003e\n\u003cli\u003eSecure account recovery with AI-assisted identity verification.\u003c\/li\u003e\n\u003cli\u003eConfigure trusted certificate authorities and identity trust chains.\u003c\/li\u003e\n\u003cli\u003eLAB: Establish ADFS trust relationships using Microsoft PKI.\u003c\/li\u003e\n\u003cli\u003eLAB: Implement passwordless X.509 certificate-based authentication.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 2: Real-Time Risk Engines\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eBuilding the AI \"Brain\" that decides when to trust a login signal\u003c\/li\u003e\n\u003cli\u003eBehavioral Biometrics: Capturing keystroke dynamics, mouse velocity and touch pressure\u003c\/li\u003e\n\u003cli\u003eContextual Telemetry: Analyzing \"Geo-velocity\" and IP reputation signals\u003c\/li\u003e\n\u003cli\u003eML Anomaly Detection: Training Scikit-learn models on \"Normal\" user login patterns\u003c\/li\u003e\n\u003cli\u003eLAB: Adaptive Risk Orchestration\u003c\/li\u003e\n\u003cli\u003eLAB: \"Geo-Velocity\" Risk Trigger\u003c\/li\u003e\n\u003cli\u003eLAB: Adding, executing and reviewing tests with Playwright\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 3: \u003c\/b\u003eSecuring the Machine Workforce (NHI)\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eManaging identities for the 95% of accounts that aren't human\u003c\/li\u003e\n\u003cli\u003eWorkload Identity Federation: Understanding the SPIFFE standard for platform-agnostic identity\u003c\/li\u003e\n\u003cli\u003eDynamic Secret Injection: Using HashiCorp Vault for \"Just-in-Time\" database credentials\u003c\/li\u003e\n\u003cli\u003eAttestation Mechanics: How containers prove integrity before receiving OAuth tokens\u003c\/li\u003e\n\u003cli\u003eMutual TLS (mTLS): Securing the connection between Keycloak and autonomous AI agents\u003c\/li\u003e\n\u003cli\u003eAPI Security: Ensuring that autonomous agents have the correct OAuth \"scopes\" and \"claims\" before they can access backend data\u003c\/li\u003e\n\u003cli\u003eAuto-Enrollment AI Audit: Using AI to monitor AD CS logs for certificate anomalies\u003c\/li\u003e\n\u003cli\u003eLAB: Securing n8n workflows with mTLS\u003c\/li\u003e\n\u003cli\u003eLAB: mTLS with SPIRE Workload Attestation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 4: \u003c\/b\u003eIdentity Governance for Agentic AI\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eDesigning security guardrails for autonomous AI agents\u003c\/li\u003e\n\u003cli\u003eThe \"On-Behalf-Of\" Problem: Manage how an AI agent proves it has explicit user consent to perform a task with OAuth\u003c\/li\u003e\n\u003cli\u003eBlast Radius Management: Restricting agent access based on intent with OAuth scopes\u003c\/li\u003e\n\u003cli\u003eIdentity-Aware LLM Chains: OAuth tokens carry the identity context for AI prompts to prevent data leakage\u003c\/li\u003e\n\u003cli\u003eLAB: AI Agent Secret Retrieval\u003c\/li\u003e\n\u003cli\u003eLAB: AI Agent \"Human-in-the-Loop\" Approval\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 5: \u003c\/b\u003eVisualizing the Identity Attack Surface\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eUsing Graph Theory AI to see what the attacker sees\u003c\/li\u003e\n\u003cli\u003eIdentity Graph Fundamentals: Mapping nodes (users) and edges (permissions)\u003c\/li\u003e\n\u003cli\u003eShadow Admins: Detecting users with excessive permissions outside standard groups\u003c\/li\u003e\n\u003cli\u003eTiered Administration: Implementing the \"Red Forest\" or Enterprise Access Model\u003c\/li\u003e\n\u003cli\u003eESC (Escalation) Vulnerabilities: Using BloodHound to find Certificate Template misconfigurations\u003c\/li\u003e\n\u003cli\u003eMonitoring CA Logs: Sending AD CS \"Certificate Issued\" events to Wazuh\u003c\/li\u003e\n\u003cli\u003eLAB: The \"BloodHound\" Attack Path Hunt\u003c\/li\u003e\n\u003cli\u003eLAB: Detecting Certificate Forgery\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 6: \u003c\/b\u003eActive Defense \u0026amp; Autonomous Response\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eDetecting and killing sessions in the middle of an attack\u003c\/li\u003e\n\u003cli\u003eEmbody Zero Trust continuous monitoring and automated remediation\u003c\/li\u003e\n\u003cli\u003eToken Theft \u0026amp; Session Hijacking: Real-time detection of \"Cookie Replay\" attacks with OAuth bearer tokens\u003c\/li\u003e\n\u003cli\u003eSigma for Identity: Writing rules for Kerberoasting, DCSync and Brute Force\u003c\/li\u003e\n\u003cli\u003eAutomated Remediation Playbooks: Configuring Wazuh to trigger a \"Global Logout\" via OAuth APIs when an attack is detected\u003c\/li\u003e\n\u003cli\u003eLAB: Detecting \"Golden Ticket\" Anomalies\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 7: \u003c\/b\u003eActive Defense \u0026amp; Autonomous Response\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eUsing AI to automate the tedious parts of compliance\u003c\/li\u003e\n\u003cli\u003eEntitlement Outlier Detection: Using Peer Group Analysis to find excessive permissions\u003c\/li\u003e\n\u003cli\u003eContinuous Access Certification: Moving from quarterly reviews to real-time reviews\u003c\/li\u003e\n\u003cli\u003eJoiner-Mover-Leaver (JML) Pipeline: Automating role changes during department switches and termination\u003c\/li\u003e\n\u003cli\u003eCRL and OCSP: Using Keycloak to check if a Windows certificate has been revoked\u003c\/li\u003e\n\u003cli\u003eLAB: Entitlement Auditing with \"Baton\"\u003c\/li\u003e\n\u003cli\u003eLAB: The Offboarding Workflow\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 8: \u003c\/b\u003eThe Future of Privacy: ZKP \u0026amp; DID\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eDecoupling \"Who you are\" from \"What you are allowed to do\"\u003c\/li\u003e\n\u003cli\u003eDecentralized Identifiers (DID): Giving users ownership of their own identity \"Wallet\"\u003c\/li\u003e\n\u003cli\u003eZero-Knowledge Proofs (ZKP): Mathematically proving a claim without revealing raw data\u003c\/li\u003e\n\u003cli\u003eVerifiable Credentials: Issuing digitally signed \"badges\" for offline verification\u003c\/li\u003e\n\u003cli\u003eLAB: Building a Zero Knowledge Proof Circuit\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/div\u003e","brand":"Learning Tree","offers":[{"title":"26AA54CN \/ 2026-10-07T09:00:00 \/ Ottawa","offer_id":48484044439709,"sku":"US-1214-IL","price":2228.0,"currency_code":"USD","in_stock":true},{"title":"26BD31US \/ 2026-11-18T09:00:00 \/ Herndon, VA","offer_id":48484044472477,"sku":"US-1214-IL","price":2228.0,"currency_code":"USD","in_stock":true},{"title":"271A73CN \/ 2027-01-06T09:00:00 \/ Ottawa","offer_id":48484044505245,"sku":"US-1214-IL","price":2228.0,"currency_code":"USD","in_stock":true},{"title":"272C01US \/ 2027-02-17T09:00:00 \/ Herndon, VA","offer_id":48484044538013,"sku":"US-1214-IL","price":2228.0,"currency_code":"USD","in_stock":true},{"title":"273A67CN \/ 2027-03-31T09:00:00 \/ Ottawa","offer_id":48484044570781,"sku":"US-1214-IL","price":2228.0,"currency_code":"USD","in_stock":true},{"title":"275C77US \/ 2027-05-19T09:00:00 \/ Herndon, VA","offer_id":48484044603549,"sku":"US-1214-IL","price":2228.0,"currency_code":"USD","in_stock":true},{"title":"276A80CN \/ 2027-06-28T09:00:00 \/ Ottawa","offer_id":48526022934685,"sku":"US-1214-IL","price":2228.0,"currency_code":"USD","in_stock":true}],"url":"https:\/\/learningtreeinternational-asrcfederal.myshopify.com\/products\/identity-security-fabric-unifying-ai-powered-iam-and-itdr","provider":"Learning Tree International","version":"1.0","type":"link"}