25 IAM Interview Questions and Answers
25 IAM interview questions for identity and access roles, with what each one tests and what a strong answer includes, from SSO and MFA to token theft.
These 25 IAM interview questions are for the person hiring an identity and access management engineer or analyst: an IAM lead, security manager or Head of Security. They cover fundamentals, real scenarios and short hands-on tasks, and each comes with what it tests and what a strong answer includes. A table further down groups them by focus, from identity threats to access governance.
Identity is now where most attacks start: a phished password, a stolen session token, a forgotten admin account. A strong IAM candidate understands both how access is granted and how it is abused, and the questions below test both. For questions that apply to every cyber role, see the main list of cyber security interview questions.
IAM interview questions on the fundamentals
Use two or three to check the foundations. Strong candidates explain where each one breaks in practice.
| Question | What it tests | What a strong answer includes |
|---|---|---|
| 1. What is the difference between authentication, authorisation and accounting? | Core concepts | Authentication proves who you are, authorisation decides what you can do, and accounting records what you did. Gives an example of a failure in each. |
| 2. What is the difference between SAML, OAuth 2.0 and OpenID Connect? | Protocols | SAML is an XML-based standard for single sign-on. OAuth 2.0 delegates access to resources and is not an authentication protocol on its own. OpenID Connect adds an identity layer on top of OAuth 2.0 with an ID token. |
| 3. What is the difference between role-based and attribute-based access control? | Access models | Role-based grants access through roles; attribute-based decides using attributes of the user, resource and context. Knows roles are simpler to run and attributes give finer control, and that many organisations use both. |
| 4. What is the joiner, mover, leaver process, and where does it usually fail? | Identity lifecycle | Creating, changing and removing access as people join, change roles and leave. It fails on movers who keep old access, and on leavers whose access to apps outside single sign-on is never removed. |
| 5. What is privileged access management? | Protecting admin access | Vaulting admin credentials, granting elevated access just in time with approval, recording privileged sessions, and keeping the number of standing admins low. |
| 6. Which MFA methods resist phishing, and why? | Modern threats | FIDO2 security keys and passkeys, because they are bound to the real website and cannot be replayed through a fake one. SMS, one-time codes and push notifications can all be phished through an adversary-in-the-middle proxy. |
| 7. What is Conditional Access, and how would you use it? | Policy-based access | Policies in Microsoft Entra ID that use signals such as user, device compliance, location and risk to allow, block or require stronger checks. See Microsoft’s Conditional Access overview. |
Scenario-based IAM interview questions
These show how a candidate protects identity under real conditions. Listen for answers that keep the business working while closing the gap.
| Question | What it tests | What a strong answer includes |
|---|---|---|
| 8. A user’s session token was stolen through a phishing proxy, even though MFA was on. What happened, and what do you change? | Token theft | Explains that the proxy captured the session after MFA was completed. Revokes sessions and resets credentials, then moves high-risk users to phishing-resistant MFA, requires compliant devices for sensitive apps, and uses token protection where available. |
| 9. You find 40 accounts with permanent Global Administrator rights. What do you do? | Privilege reduction | Reduces the number to a handful, moves the rest to just-in-time elevation, keeps two monitored break-glass accounts, and assigns narrower admin roles for specific tasks. |
| 10. Access reviews show managers approve everything without looking. How do you fix it? | Access governance | Makes reviews smaller and risk-based, shows reviewers when access was last used, removes unused access automatically, and holds owners accountable for decisions. |
| 11. A Conditional Access policy is blocking the CEO while they travel. What do you do? | Exceptions under pressure | Verifies it is really the CEO, applies a narrow, time-limited exception rather than disabling the policy, and records it. |
| 12. Service accounts have passwords that never expire. What do you do? | Non-human identities | Inventories them, moves them to managed identities or group managed service accounts where possible, rotates the rest, cuts their permissions, monitors them and gives each an owner. |
| 13. Your company has acquired another business. How do you bring its identities in? | Integration | Starts with federation or guest access for quick collaboration, then maps roles, cleans up stale accounts and migrates in stages, without trusting the other directory blindly. |
| 14. An application team wants to store users’ passwords themselves instead of using single sign-on. What do you say? | Architecture influence | Pushes for single sign-on with OpenID Connect or SAML. If that is impossible, insists on proper password hashing, MFA and the same lifecycle controls. |
| 15. A leaver still had access to a SaaS app three months after leaving. Why, and how do you stop it happening again? | Root cause | The app was not connected to single sign-on or automated provisioning. Fixes it with SCIM deprovisioning and by discovering apps outside central control. |
| 16. How would you roll out passkeys across the company? | Change planning | Starts with admins and high-risk users, checks device support, designs secure account recovery, and phases out weaker methods once adoption is proven. |
| 17. An app has requested permission to read the mailboxes of many users. What do you do? | Consent phishing | Treats it as a possible illicit consent grant, reviews and revokes the app’s consent, checks audit logs for data access, and restricts users from consenting to unverified apps. |
Hands-on IAM interview tasks
Short tasks to run in the interview with demo data. Watching a candidate read real sign-in logs and policies tells you more than any answer above.
| Task | What it tests | What a strong answer includes |
|---|---|---|
| 18. Here are Entra ID sign-in logs for one account. Is it compromised? | Identity investigation | Spots signs such as a new location, a session token reused from a new address, or MFA satisfied by a claim in the token rather than a fresh prompt. |
| 19. Here is a set of Conditional Access policies. Find the gaps. | Policy review | Spots broad exclusions, legacy authentication left open, no device requirement for admins, and policies still in report-only mode. |
| 20. Here is an export of role assignments. Which are risky? | Privilege review | Flags permanent highly privileged roles, guests with admin rights, and app owners who could add credentials to powerful apps. |
| 21. Decode this JWT and tell me what it grants. | Token knowledge | Reads the issuer, audience, expiry, scopes and roles, knows a JWT is encoded rather than encrypted, and lists what the receiving app must validate. |
| 22. Write a query to find successful sign-ins that used only a single factor. | Querying identity logs | A working query on the sign-in logs’ authentication requirement, summarised by user and app. See the example below. |
| 23. Here are the permissions an OAuth app is requesting. Would you approve it? | Consent review | Separates delegated from application permissions, questions anything broader than the app needs, and checks the publisher. |
| 24. Here is a post-mortem of an identity attack that bypassed Conditional Access. What should have stopped it? | Learning from incidents | Identifies the gap, such as an excluded app or a missing device condition, and proposes specific policy changes. |
| 25. Design the joiner, mover, leaver process for a company of 2,000 people. | Process design | HR as the source of truth, automatic provisioning by role, access changes on moves, same-day removal on leaving, and regular reviews. |
For task 22, one answer in Microsoft Sentinel looks like this:
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == "0"
| where AuthenticationRequirement == "singleFactorAuthentication"
| summarize SignIns = count() by UserPrincipalName, AppDisplayName
| order by SignIns desc
Which IAM questions for which focus?
IAM roles range from engineering the platform to governing who has access. Pick from the areas the person will own.
| Focus | What it covers | Questions to use |
|---|---|---|
| Identity threats | Phishing, token theft and consent attacks | 6, 8, 17, 18, 21, 24 |
| Access governance | Lifecycle, reviews and non-human identities | 4, 10, 12, 15, 20, 25 |
| Privileged access | Admin rights and elevation | 5, 9, 11 |
| Architecture and protocols | SSO, policies and design | 1, 2, 3, 7, 13, 14, 16, 19, 22, 23 |
For identity in AWS, Azure or GCP infrastructure, add from the cloud security interview questions.
What are the red flags in an IAM interview?
- MFA as the finish line. Believes any MFA stops account takeover, and has not heard of session token theft.
- Standing admin rights. Sees nothing wrong with dozens of permanent administrators.
- Ignoring non-human identities. Has no plan for service accounts, apps and their credentials.
- Disabling policies to fix problems. Turns off Conditional Access instead of scoping an exception.
- Protocol confusion. Describes OAuth 2.0 as a login protocol, or cannot say what a token contains.
Why a hands-on task beats any IAM interview question
Most candidates can describe MFA. Fewer can look at a sign-in log and see that MFA was satisfied by a stolen token, not by the real user. That is the skill that stops account takeover, and it only shows when they work with real data.
Used before the interview, this shows you who understands how identity is attacked. The interview can then focus on design, governance and how they bring the business along.
Frequently asked questions
What does an IAM engineer do?
An IAM engineer designs and runs the systems that control who can access what: single sign-on, MFA, directory services, access policies, privileged access and the processes for granting and removing access.
What skills does an IAM engineer need?
Knowledge of identity protocols such as SAML, OAuth 2.0 and OpenID Connect, a directory platform such as Microsoft Entra ID, access policy design, privileged access management, and an understanding of how attackers abuse identity.
What is the difference between IAM and PAM?
IAM covers how every user and system gets the access it needs. Privileged access management (PAM) is the part of it that protects the most powerful accounts, with stronger controls such as vaulting, just-in-time elevation and session recording.
How do you assess an IAM candidate before the interview?
Give them real sign-in logs or a set of access policies and ask them to find the compromise or the gap. Score what they find and how they would fix it.
How CyberHire tests IAM engineers before the interview
CyberHire is cyber technical screening that shows you who can secure identity before you book an interview. Paste your job specification and generate an assessment, or build one from the library. Identity challenges include a KQL lab on MFA bypass and token replay detection, an Azure AD investigation of adversary-in-the-middle session token theft, an M365 OAuth consent phishing analysis, and a post-mortem of an identity attack that bypassed Conditional Access.
Every candidate is scored the same way, with integrity signals next to each score, and you see their actual answers. IAM engineers are one of the roles we assess; see all use cases. If you would rather not build the assessment yourself, our team will build it with you.
Hiring an IAM engineer?
See who can secure identity before you interview anyone.
Send us the job spec. Within 48 hours we send you a hands-on assessment built around it, in your branding, free. Real sign-in logs and real identity attacks, scored the same way for every candidate.