Certified Identity & Access Management Technologist (eIAMA)
eIAMA Certification
eIAMA is a practical, role-aligned certification that validates the hands-on skills required to implement, operate, troubleshoot, and secure identity and access management controls across modern enterprise environments.
The Exam
The eIAMA certification evaluates a candidate’s ability to implement, operate, and troubleshoot IAM controls in a modern, zero-trust-aligned environment. Candidates are assessed on their ability to work across identity sources, identity providers, applications, policy layers, and logging systems to enforce and validate secure access.
About the Certification Exam
The eIAMA certification covers the end-to-end fundamentals of implementing and operating modern identity and access management controls, including identity architecture, lifecycle management, authentication, federation, authorization, privileged access, monitoring, incident response, and audit readiness.
This certification exam emphasizes practical, real-world capability over theory. Candidates are evaluated not only on their understanding of IAM concepts, but on their ability to think like an IAM practitioner by configuring controls, validating access behavior, troubleshooting failures, analyzing logs, and producing evidence aligned to security and governance requirements.
Domains + Objectives
The eIAMA evaluates an individual’s ability to implement, operate, and troubleshoot IAM controls across key identity and access management domains.
eIAMA
Exam Domains
IAM Foundations (10%)
Directories, Identity Data, and Lifecycle (15%)
Authentication, SSO, and Federation (20%)
Authorization & Policy Engineering (20%)
Privileged Access & Secrets (15%)
IAM Operations, Monitoring, and Incident Response (10%)
Governance, Risk, and Compliance for IAM (10%)
IAM Foundations (10%)
Explain the role of IAM within modern enterprise security models. Differentiate authentication, authorization, and accounting in applied scenarios. Identify common IAM threats, including credential theft, session hijacking, and privilege escalation, and map core IAM components such as identity providers, service providers, directories, MFA, and logging to end-to-end enterprise workflows.
Directories, Identity Data, and Lifecycle (15%)
Model identity attributes, groups, and organizational structures for workforce access control. Implement Joiner-Mover-Leaver lifecycle workflows for users and service accounts. Design and compare access provisioning approaches, configure account deprovisioning, validate identity data integrity, and troubleshoot directory synchronization issues.
Authentication, SSO, and Federation (20%)
Configure SSO flows and troubleshoot common authentication failures, including clock skew, claims issues, metadata errors, redirect URI issues, scopes, and certificate trust. Implement MFA policies, differentiate SAML and OIDC/OAuth2 protocols, configure token and session lifetimes, and design secure enrollment and account recovery flows.
Authorization & Policy Engineering (20%)
Design RBAC models and justify role granularity decisions based on least privilege and manageability. Implement authorization using groups, claims, and scopes across identity and application layers. Compare RBAC and ABAC models, apply attribute-based conditions, configure conditional access policies, and validate authorization decisions using logs, test accounts, and application behavior.
Privileged Access & Secrets (15%)
Apply privileged access principles, including just-in-time access, just-enough access, and separation of duties. Implement administrative role separation and privileged identity protections. Manage service account risks, including credential rotation, scope limitation, and secure storage patterns, while recognizing and mitigating common PAM anti-patterns.
IAM Operations, Monitoring, and Incident Response (10%)
Centralize IAM logs and identify high-risk events such as MFA fatigue, impossible travel, privilege escalation, and anomalous authentication behavior. Analyze IAM telemetry, triage IAM incidents, determine appropriate containment and remediation actions, troubleshoot authentication and provisioning issues, and produce incident evidence using logs and trace data.
Governance, Risk, and Compliance for IAM (10%)
Implement access reviews and generate audit-ready evidence. Map IAM controls to common frameworks, define and measure IAM KPIs, document exception handling and compensating controls, and create IAM runbook content for regulated environments.
Who It’s For?
The eIAMA certification is designed for practitioners who implement and operate IAM in real-world environments, bridging help desk and infrastructure roles into security and advancing analysts and engineers toward IAM technologist and architecture responsibilities.
Get eIAMA Certified
To take the eIAMA exam, you’ll need both an INE subscription and an exam voucher.
Buying for a team? INE Enterprise and Professional Team Licenses include eIAMA courses and certification prep.
The Process
Whether you are attempting the eIAMA certification exam independently or after completing the recommended learning path, the process is simple.