Identity, Authentication, and Access Management Questions

Designing and operating identity and access control systems. Covers authentication protocols and standards (OAuth, SAML, OIDC, MFA), authorization models (RBAC, ABAC), identity lifecycle and privilege management, IAM architecture and automation, and access control across cloud and on-premises environments. The 'who can do what' control plane, distinct from cryptographic key management.

HardSystem Design
34 practiced

Design a high-availability and multi-region deployment for an IdP and directory service that must provide low latency (e.g., <5s for local auth) and survive a region failure. Discuss active-active vs active-passive replication, consistency tradeoffs, session state handling, DNS/routing strategies, and data residency constraints.

HardSystem Design
44 practiced

Design an automated, auditable account lifecycle system for 20,000 employees across 1,000 Linux servers that integrates with HR events (joiner/mover/leaver), central identity (AD/LDAP), and supports temporary elevated access for contractors (Break-Glass). Describe the components, data flows, how to handle disconnected hosts, temporary access expiry, and how you will provide an auditable trail of changes.

HardTechnical
45 practiced

You are hired as Head of Security Engineering for a mid-size company with limited budget and a fragmented IAM program. Produce a prioritized 90-day plan that focuses on IAM improvements across preventive (controls), detective (monitoring) and responsive (playbooks) measures. Include measurable KPIs, quick wins that require minimal budget, medium-term projects that reduce risk, stakeholder engagement, and how you'd measure success at day 30/60/90.

EasyTechnical
57 practiced

List and describe the purpose of these built-in privileged groups in Windows/AD: 'Administrators' (local), 'Domain Admins', 'Enterprise Admins', and 'Account Operators'. For each group explain the scope of their privileges, typical membership practices, and why least-privilege principles matter when assigning membership.

HardTechnical
44 practiced

Discuss differences between symmetric (HS256) and asymmetric (RS256) JWT signing algorithms. Create a migration plan to move from HS256 to RS256 across many services: key generation, distribution, library updates, handling tokens signed with old keys, preventing algorithm-confusion attacks, and operationalizing kid-based key rotation.

Unlock Full Question Bank

Get access to all Identity, Authentication, and Access Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.