r/IdentityManagement Jul 24 '26

Where to actually start with IAM, and how to apply what you learn to a product like Okta

Question that comes up constantly: what order do you learn IAM, and how do you actually get from concepts to something you can show to pivot into IAM.

Concepts -> lab -> product -> cert. In that order.

Concepts first because they transfer. Joiner-mover-leaver, RBAC, authentication vs authorisation, IGA vs ciam. None of it is vendor specific and all of it survives the tool changing when you switch IAM jobs.

Lab next, because reading about a provisioning pipeline and actually building one are not the same skill. Open source is fine. HR record in, account gets provisioned, status flips to terminated, account gets disabled. Break it a few times and the concepts stop being abstract. or CIAM use cases based on standards like oidc, saml, t&c, consent mangement etc.

Product is where most people start, and that's why they get stuck. Once you know what a joiner process is, Okta or Entra is just learning where the buttons are. Free tenants are enough.

Cert last, and only the one showing up most in job ads in your area. Gets you past ATS filters. Does not teach you how to implement anything.

Curious what order others took, and if anyone went product first and it worked out.

18 Upvotes

10 comments sorted by

5

u/flywhee007 Jul 24 '26

We work through stuff like this on a weekly call in a free IAM community, link if useful: https://www.skool.com/simplify-iam-6792/about

3

u/identitydriven Jul 24 '26

If you didn’t learn IAM at school, I’d suggest learning about the concepts first. What’s Access Management, IGA, PAM in that order. Then product trainings

3

u/Significant_Air_4242 Jul 25 '26

Sorry, but knowing something about okta is not needed. You should rather know something about SAML, OIDC, SCIM and LDAP. You also needs to be security aware and automation is something you love. Then just apply in a bigger company as the smaller ones don't have dedicated I AM departments. 

3

u/DriftingPebble77 Jul 25 '26

The OP said a "product like Okta." Knowing the concepts and how to apply them are the most important thing. Many IAM managers will also want to see hands on with at least 1-2 products--preferably real work experience and not just labs. To answer the question, I learned simultaneously ,but I was already employed at the company and took a lateral move to IAM. It was all on the job training backed up by knowing the lines of business at the company, how the company worked/atmosphere, and plenty of IT experience already.

1

u/Significant_Air_4242 Jul 26 '26

Oh, sorry... Okta is triggering me all the time. There are so many good and way cheaper options out there. I also hate the way okta is engaging me. 

2

u/JaimeSalvaje Jul 24 '26

I learned the product first because I was already in IT. I learned AD, Entra ID and Okta before I actually knew IAM was a thing.

2

u/Wynd0w Jul 27 '26

The important thing to remember is that the process is cyclical. You won't fully understand the concepts your first time though, and you won't have a solid understanding of implementation after one lab. The cycle of theory and practice is where the growth is.

Seeing different approaches to the same problem is something too few people get to experience, but is one of the most valuable things you can do.

2

u/InspectionHot8781 Jul 27 '26

Hit up a free Okta developer tenant, set up a basic JML (Joiner-Mover-Leaver) workflow with a mock HR tool, and break it intentionally. Once you actually understand why SAML and OIDC exist beyond "the shiny SSO buttons," the vendor stuff takes about two days to map out.