Jason Edwards
This chapter reframes identity and access management as the primary control plane for modern Blue Team operations, reflecting the realities of distributed systems, cloud services, and software-driven business processes. It explains why identity has replaced the traditional network perimeter as the most reliable enforcement point and clarifies the operational distinction between authentication, authorization, and session control. Readers gain a clear understanding of how access decisions are actually made and where attackers exploit weaknesses when identity controls are poorly designed or inconsistently governed. The chapter explores how role-based access control, least privilege, and entitlement management function in real operational environments rather than in idealized policy models. It examines how permission sprawl, privilege creep, and machine identity overreach emerge through normal business activity and why these issues persist without deliberate lifecycle management. Practical attention is given to access reviews, transfers, offboarding, and change management as daily operational controls, highlighting how identity governance succeeds or fails based on execution rather than intent. The chapter also addresses detection and response through identity signals, focusing on how access patterns, behavioral indicators, and session activity reveal misuse that traditional security controls often miss. It explains how AI-assisted risk scoring can support triage and prioritization when grounded in strong telemetry, explainability, and human approval boundaries. Throughout, the chapter emphasizes operational realism, accountability, and auditability, showing how mature IAM practices reduce blast radius, speed investigations, and align security controls with business execution.