Kubernetes & AKS Academy · Enterprise Knowledge Graph

Identity and Security Knowledge Graph

Connect workforce identity, workload identity, privileged access, devices, networks, applications, data and security operations.

Objective: Understand how identity becomes the primary control plane across modern cloud and hybrid environments.

Practical guidance

Foundations and prerequisites

01

Authentication, authorisation and directory concepts

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Users, groups, roles, service principals and managed identities

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

MFA, conditional access and least-privilege principles

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

Practical guidance

Technology relationships and dependencies

01

PIM and access reviews govern privileged and persistent access

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Device compliance and risk signals influence access decisions

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Applications, APIs, secrets, certificates and tokens create trust paths

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

Practical guidance

Architecture, delivery and operations

01

Apply Zero Trust controls across identity, device and workload access

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Centralise logging, detection, investigation and response

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Create joiner, mover, leaver and emergency-access processes

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

Practical guidance

Validation and learning evidence

01

Test access grant, denial, revocation and privilege elevation

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Validate break-glass accounts and tenant recovery dependencies

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Map each critical application to identity owners and authentication flows

Apply this point to a real Kubernetes & AKS Academy design, delivery or operational scenario and record the evidence used to validate the outcome.