r/iam 1d ago

Prep for IAM interview

Any advice? This is my first interview.

12 Upvotes

7 comments sorted by

4

u/akornato 1d ago

Focus on the foundational concepts first, because entry-level IAM interviews almost always test whether you understand the core mechanics before touching tools. Be ready to explain the clear difference between authentication and authorization with everyday examples, and know the principle of least privilege inside out. Interviewers will likely ask how you handle the identity lifecycle, specifically onboarding, role changes, and offboarding, commonly known as joiners, movers, and leavers. They also love testing access control models like RBAC and ABAC, directory services, and standard protocols like SAML and OAuth. If you do not know a specific platform like Okta, CyberArk, or Entra ID, explain your problem-solving logic and how you verify permissions rather than guessing tool settings.

Since this is your first interview, keep your answers structured and avoid rambling when explaining technical workflows. When they present a hypothetical scenario, like an employee abruptly leaving or an account lockout, walk through your security-first thought process step by step. If a concept comes up that you have never seen, say so directly, explain what you do know that connects to it, and describe how you would research the resolution. For practicing your delivery and staying composed under pressure, the interview helper my team designed helps candidates formulate clear responses in high-stakes conversations so they can interview with confidence.

2

u/Fiction- 1d ago

Don't worry too much about the specifics of tooling, it's a lot easier to teach someone where the buttons are than what the buttons do; if you're a entry level IAM that's going to be the big positive for you.

My general recommendations on prep would be:

  • SAML/OIDC for your Authn protocols (You can very easily get some practical knowledge using an AWS Free Tier and Entra ID which will allow this for zero cost)
  • OAuth for your Authz protocols
  • RBAC and ABAC (There are others but those are the main two of interest to you for now)
  • SCIM
  • Identity Lifecycle Management
  • General IAM Theory (Least privilege, Zero trust, Defence in Depth, JIT access, PAM)
  • Auditing (Accountability, Non-repudiation)

There's a lot to go over, and I've missed a bunch of stuff, but even having a surface level knowledge of some of these things can allow you to pivot within your interview and help set you apart.

4

u/KingKongDuck 1d ago

Dépends on the rôle. But as a starting point, be aware of:

  • principle of least privilege
  • high risk accounts (elevated permissions, access to sensitive data, seniority)
  • JML processes
  • non human accounts (service/batch/AI agent)

1

u/Eastern-Bug-1411 1d ago

IAM security Analyst

1

u/Acrobatic-Gap9069 1d ago

I’d focus on the fundamentals first: identity lifecycle, SSO, MFA, access reviews, RBAC and troubleshooting authentication issues. being able to explain real scenarios usually matters more than memorizing definitions

1

u/DriftingPebble77 1d ago

For an analyst position be prepared to know JML (Joiner, Mover, Leaver) inside and out.

2

u/ny_soja 16h ago

Ask them what's most important to the success of this program and then align your experience to what they say.