Skip to content
Tech Interview Prep home
Technical interview guide

Identity & Access Management (IAM) Design

Designing identity, roles, and access policies across an entire organization, not just one system.

Read
31 min
Practice MCQs
25
Interview QA
25
Edition
v4
Editorial status
Reviewed
Relevant for
Security Architect

Scope: NIST SP 800-63-4 suite (final July 2025); SCIM RFCs 7643/7644; OAuth Security BCP RFC 9700 (January 2025); OpenID Connect Core 1.0.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Design an enterprise IAM operating model.

QA-2

Design joiner, mover, and leaver automation across hundreds of applications.

QA-3

Design a resilient SCIM provisioning integration.

QA-4

Create an enterprise role and entitlement model without role explosion.

QA-5

Design an access-request and approval workflow.

QA-6

Build a meaningful periodic access-review program.

QA-7

Design just-in-time privileged access across cloud and on-premises systems.

QA-8

Design federation for a multi-tenant SaaS application.

QA-9

Secure OAuth clients and API access in an enterprise platform.

QA-10

Design identity and access for non-human workloads.

QA-11

Prevent confused-deputy and delegation flaws.

QA-12

Design segregation-of-duties controls across multiple applications.

QA-13

Govern nested groups and dynamic membership rules.

QA-14

Design delegated administration without enabling self-escalation.

QA-15

Handle mergers, acquisitions, and multiple identity domains.

QA-16

Design contractor and partner identity lifecycle.

QA-17

Design customer identity at large scale with privacy and recovery.

QA-18

Design identity recovery and break-glass for IAM control-plane outage.

QA-19

Detect and remediate orphaned, dormant, and excessive access.

QA-20

Measure IAM effectiveness without rewarding approval volume.

QA-21

Threat-model an enterprise IAM platform.

QA-22

Respond to compromise of the enterprise identity provider.

QA-23

Design enterprise session lifecycle and revocation.

QA-24

Migrate identity providers without account takeover or mass lockout.

QA-25

Review IAM architecture for a global enterprise.