Identity, Authentication, and Access Management Questions

Designing and operating identity and access control systems. Covers authentication protocols and standards (OAuth, SAML, OIDC, MFA), authorization models (RBAC, ABAC), identity lifecycle and privilege management, IAM architecture and automation, and access control across cloud and on-premises environments. The 'who can do what' control plane, distinct from cryptographic key management.

MediumTechnical
44 practiced

You must onboard external partners with SAML or OIDC federation. Draft a federation onboarding checklist covering metadata exchange, certificate validation, required attributes, scopes/claims, test cases, operational contacts, and trust lifecycle management including periodic validation and revocation procedures.

HardTechnical
39 practiced

Design a secure cross-domain SSO architecture that minimizes trust exposure: token exchange patterns, limiting claims and scopes, short token lifetimes, partner-scoped client credentials, automated metadata validation, and contractual/operational controls for partner access.

EasyTechnical
57 practiced

Compare common Multi-Factor Authentication (MFA) approaches : TOTP (time-based OTP), SMS OTP, push-based approval, and hardware-backed/U2F/WebAuthn tokens : in terms of security, usability, deployability, and attack surface. For each method, list typical threats (e.g., SIM swapping, phishing, device theft) and describe when you would choose or avoid that method for a user-facing application.

MediumSystem Design
37 practiced

You must integrate on-prem Active Directory with a cloud IdP to support SSO for cloud services and legacy apps. Describe the architecture patterns for directory synchronization versus federation, including security trade-offs (password hash sync vs pass-through auth vs federation), account provenance, how to synchronize groups and nested groups, and how to handle password policy differences.

HardTechnical
39 practiced

Design a cryptographic key management and signing infrastructure for tokens (JWT/SAML) that supports key rotation, HSM-backed storage, cross-region replication, graceful rollover (support old keys for token lifetime), and fast compromise recovery. Describe key metadata (kid/version), rotation cadence, signer/verifier patterns, publishing of public keys (JWKS), and how services discover and cache key material securely.

Unlock Full Question Bank

Get access to all Identity, Authentication, and Access Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.