Group Purchasing
Group Purchasing
BETA

SEC559: Identity Security for Cloud and Hybrid

SEC559Cloud Security
  • 5 Days (Instructor-Led)
  • 30 Hours
Course authored by:
Maxim Deweerdt
Maxim Deweerdt
SEC559: Cloud and Hybrid Identity Security
Course authored by:
Maxim Deweerdt
Maxim Deweerdt
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person or Virtual

    Attend a live, instructor-led class from a location near you or virtually from anywhere

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 16 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Build the skills to detect, govern, and respond to identity-based attacks across human, workload, and AI agent identities throughout the full identity lifecycle.

Course Overview

Today, identity is the main way to control access in organizations and is also the top target for attackers. Instead of using old methods, attackers now take advantage of tokens, applications, hybrid trust setups, and non-human identities including AI agents and automated workloads to get ongoing and often hidden access. SEC559 gives defenders the knowledge and hands-on experience they need to secure, monitor, and respond to identity-based attacks in Microsoft Entra ID and hybrid Active Directory environments. The course covers the whole identity lifecycle, including authentication, token issuance, trust abuse, governance of human and agent identities, and AI-assisted detection and response in Microsoft Entra ID and Active Directory. The main goal is to teach practical detection, safe remediation, and how to stop identity attacks before they spread across cloud and on-premises systems.

Over five days, students track a real-world identity breach as it develops from initial access to a full hybrid compromise. The course covers the whole identity lifecycle, including authentication, token issuance, trust abuse, and governance issues in Microsoft Entra ID and Active Directory. The main goal is to teach practical detection, safe remediation, and how to stop identity attacks before they spread across cloud and on-premises systems.

Hands-On Training in Identity Attack Detection, Governance, and Response

SEC559 uses hands-on exercises that reflect how modern identity attacks happen in real environments, covering human, workload, and new agent identities. Students learn how attackers misuse OAuth consent, tokens, service principals, synchronization, and cross-tenant trust to stay hidden and move through systems without setting off standard alerts. The course also explores how gaps in governance, lifecycle issues, and too many privileges can allow attackers to keep access over time.

In twenty practical labs, students examine authentication flows, token relationships, application permissions, hybrid identity sync, and trust boundaries using real data from Entra ID and Active Directory. Each lab helps students spot subtle signs of identity abuse that can look like normal activity, such as token misuse, application access, and hybrid privilege escalation.

By the end of the course, students will have practiced spotting unauthorized access, mapping identity attack paths in cloud and hybrid setups, and carrying out safe remediation steps. These steps include revoking sessions, rotating credentials, securing sync infrastructure, and restoring trust in identity systems without interrupting business operations.

Author Statement

Over the years, I have seen many cases where defenders followed best practices, but attackers still found ways to keep access. The main reason was usually the same: identity compromise has moved far beyond just stolen passwords. Attackers now take advantage of tokens, application identities, hybrid trust relationships, and synchronization methods in ways that seem normal unless you really know how identity systems work.

In systems that use Microsoft Entra ID and Active Directory, identity is not just part of the attack surface: it is now the main control point. Still, many defenders do not have enough hands-on experience to spot and handle attacks on this control plane. Most identity security training covers design or prevention, but few courses help defenders investigate real incidents that involve cloud, on-premises, and non-human identities like applications and agents.

SEC559 was created to fill that gap. The course teaches how to detect, respond to, and control identity-based attacks throughout the entire identity lifecycle. With real-world scenarios and hands-on labs, students learn how modern identity attacks happen, how to spot subtle abuse in hybrid environments, and how to stop attackers from keeping access even when trust, tokens, and automation are at risk.

- Maxim Deweerdt

What You'll Learn

  • Detect OAuth consent abuse, token replay, and Graph API misuse across user, workload, and agent identities
  • Analyze OAuth, OIDC, and SAML authentication flows to identify anomalies in tokens, claims, and session behavior
  • Identify and remediate compromised applications, service principals, managed identities, and AI agents operating as application workloads, including credential abuse and persistence
  • Map and investigate identity attack paths across cloud and hybrid environments, including Active Directory to Microsoft Entra ID escalation scenarios
  • Detect and respond to hybrid identity attacks such as synchronization abuse, federation trust manipulation, and Kerberos-based escalation
  • Uncover governance and lifecycle weaknesses that enable long-term persistence, including overprivileged access, ungoverned agent identities, and external identity abuse
  • Execute safe, effective remediation by revoking sessions, rotating credentials, securing identity infrastructure, applying AI-assisted and agentic workflow, and restoring trust without disrupting operations

Business Takeaways

  • Reduce risk from identity-based attacks that bypass traditional defenses by targeting the identity control plane
  • Detect attackers operating with legitimate credentials, tokens, non-human workloads, and application identities before they escalate access
  • Prevent tenant-wide and domain-wide compromise by breaking identity attack paths early across cloud and hybrid environments
  • Improve visibility across Microsoft Entra ID and Active Directory to enable faster, more accurate detection and response
  • Strengthen Zero Trust by enforcing strong authentication, conditional access, and continuous session evaluation
  • Mature identity governance programs by addressing privilege sprawl, ungoverned agent identities, ownership gaps, and lifecycle weaknesses
  • Enhance incident response capabilities with AI-assisted and agentic workflow, repeatable processes to contain, remediate, and validate identity compromises across the full identity lifecycle

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC559: Cloud and Hybrid Identity Security.

Section 1Identity as the Control Plane

Day 1 introduces identity as the core security control plane, including agent identity foundations and limitations of service principals for autonomous AI workloads. Students explore identity types, applications, permissions, and relationships in Microsoft Entra ID, learning how misconfigurations, privilege paths, and ownership gaps create attack surfaces.

Topics covered

  • Identity-first security model and control plane concepts
  • Identity types: users, devices, workloads, and agents
  • Applications, service principals, and managed identities
  • Authorization model: roles, permissions, and Microsoft Graph
  • Identity relationships, privilege paths, and attack surface

Labs

  • Explore identity types and relationships in Entra Portal
  • Manage applications and service principals
  • Using managed identities
  • Explore Graph API permissions and access paths

Overview

Day 1 establishes identity as the central control plane in modern environments. Students learn how different identity types interact, how permissions are assigned, and how applications and service principals operate within Entra ID. The day focuses on understanding how privilege is structured and where hidden attack paths emerge.

Students explore how group nesting, role assignments, and application relationships create indirect privilege escalation opportunities. Special attention is given to workload and agent identities, which are increasingly targeted due to weak ownership and credential management practices.

By the end of the day, students understand how attackers map identity environments, identify overprivileged accounts, and exploit ownership gaps. This foundational knowledge prepares students to analyze authentication, tokens, and session abuse in later sections.

Full Lab Details

  • Lab 1.1: Explore Identity Types and Relationships in Entra: Understand how users, groups, devices, and applications are structured and connected.
  • Lab 1.2: Manage Applications and Service Principals: Create and analyze app registrations and service principals, including permissions and ownership.
  • Lab 1.3: Using Managed Identities: Work with system-assigned and user-assigned managed identities and understand their security implications.
  • Lab 1.4: Explore Graph API Permissions and Access Paths: Analyze delegated and application permissions and map how access flows through Microsoft Graph.

Full Topic Details

  • Identity as the primary security control plane in modern environments
  • Zero Trust principles and identity-first security model
  • Control plane vs data plane in identity systems
  • Identity types: human, device, workload, and agent identities
  • Users, groups, devices, and ownership relationships
  • Application model: app registrations vs service principals
  • Enterprise applications and multi-tenant considerations
  • Managed identities: system-assigned vs user-assigned
  • Agent identity foundations and limitations of service principals
  • Authorization models: Entra roles vs Azure RBAC (introduction)
  • Delegated vs application permissions
  • Microsoft Graph as identity control and data plane
  • Role assignments, privilege boundaries, and Administrative Units
  • Delegated administration models
  • Group nesting, role chaining, and indirect privilege escalation
  • App-to-user and app-to-app privilege paths
  • Identity attack surface mapping: overprivileged identities
  • Ownership gaps and identity sprawl

Section 2Authentication, Tokens and Session Security

Day 2 focuses on how authentication and token issuance define access in modern environments, including how agent identities authenticate/leverage tokens and how it's different from human identities. Students analyze how tokens, sessions, and authentication methods work in Microsoft Entra ID, and how attackers abuse them to gain persistent, often invisible access.

Topics covered

  • Authentication flows and identity providers vs relying parties
  • Authentication strength: passwordless, FIDO2, and device binding
  • Token model: access, refresh, PRT, and token chaining
  • Token abuse: replay, persistence, device code, and session hijacking
  • Conditional Access, session control, and token protection

Labs

  • Implement phishing-resistant authentication
  • Investigate OAuth tokens and relationships
  • Simulate OAuth and token abuse scenarios
  • Protect access with Conditional Access policies

Overview

Day 2 dives into how authentication and tokens govern access in modern identity systems. Students explore how identities authenticate, how tokens are issued, and how session context is maintained across applications and services.

The day focuses on understanding token relationships, including access tokens, refresh tokens, and primary refresh tokens, and how these can be abused for persistence and lateral movement. Students analyze real attack techniques such as token replay, device code abuse, and session hijacking that allow attackers to bypass traditional defenses.

Students also explore how authentication strength and Conditional Access policies influence token issuance and session control. By the end of the day, they understand how to detect token-based attacks, enforce stronger authentication, and reduce the window of abuse through session controls and token protection mechanisms.

Full Labs Details

  • Lab 2.1: Implement Phishing-Resistant Authentication: Configure and validate strong authentication methods, including FIDO2 and Conditional Access enforcement.
  • Lab 2.2: Investigate OAuth Tokens and Relationships: Analyze access and refresh tokens, inspect claims, and understand token chaining behavior.
  • Lab 2.3: Simulate OAuth and Token Abuse Scenarios: Execute attack scenarios such as token replay, device code abuse, and consent abuse.
  • Lab 2.4: Protect Access with Conditional Access Policies: Design and test Conditional Access policies to enforce authentication strength and session control.
  • Full Topic Details
  • Identity providers and relying parties in authentication flows
  • Interactive vs non-interactive authentication models
  • Authentication methods: passwords, passwordless, and MFA
  • Authentication strength and enforcement concepts
  • FIDO2, WebAuthn, passkeys, and phishing-resistant authentication
  • Windows Hello for Business and device binding
  • Token types: access tokens (AT), refresh tokens (RT), and PRT
  • Family of Client IDs (FOCI) refresh tokens
  • Token chaining: PRT → RT → AT
  • Client vs resource model in token usage
  • Token issuance process and claims (audience, scopes, context)
  • Device, user, and application context in tokens
  • Continuous Access Evaluation (CAE) and its impact on tokens
  • Token abuse techniques: replay, persistence, and hijacking
  • Refresh token abuse and long-lived access
  • PRT abuse and device-bound session risks
  • Device code flow abuse scenarios
  • OAuth abuse: consent, delegated vs application permissions
  • Application and service principal takeover via credential addition
  • Conditional Access policy evaluation logic
  • Authentication strength enforcement via Conditional Access
  • Session control: sign-in frequency and session lifetime
  • Token protection and device-bound tokens

Section 3Hybrid Identity and Active Directory Security

Day 3 expands identity security into hybrid environments, where Active Directory and Microsoft Entra ID form a combined control plane. Students analyze how synchronization, trust, and Kerberos enable cross-plane attacks and privilege escalation.

Topics covered

  • Hybrid identity architecture and trust boundaries
  • Identity synchronization models and object matching
  • Sync infrastructure and connector identity risks
  • Hybrid privilege escalation and cross-plane attack paths
  • Kerberos, federation, and modern hybrid authentication models

Labs

  • Investigate hybrid domain configurations in Entra
  • Analyze Active Directory - Entra sync configuration
  • Simulate hybrid privilege escalation
  • Hybrid attack path analysis with AzureHound and BloodHound

Overview

Day 3 focuses on how identity extends across on-premises and cloud environments, creating a unified but complex control plane. Students explore how Active Directory and Entra ID interact through synchronization and federation, and how attackers exploit these connections to move between environments.

The day highlights how identity synchronization introduces new attack primitives, including object matching abuse, attribute manipulation, and connector account compromise. Students learn how attackers prepare and execute cross-plane privilege escalation, often starting on-premises and ending with full cloud compromise.

Kerberos and modern hybrid authentication models are examined to understand how authentication flows influence cloud access. By the end of the day, students can identify hybrid attack paths, detect abuse of synchronization and trust mechanisms, and understand how to secure the hybrid identity control plane.

Full Labs Details

  • Lab 3.1: Investigate Hybrid Domain Configurations in Entra: Analyze domain setup, trust relationships, and hybrid identity configuration in Entra ID.
  • Lab 3.2: Analyze Active Directory - Entra Sync Configuration: Inspect synchronization settings, connector accounts, and attribute flows between AD and Entra.
  • Lab 3.3: Simulate Hybrid Privilege Escalation: Execute scenarios that demonstrate cross-plane escalation from on-premises to cloud.
  • Lab 3.4: Hybrid Attack Path Analysis with AzureHound and BloodHound: Map and analyze hybrid identity attack paths spanning Active Directory and Entra ID.

Full Topic Details

  • Active Directory fundamentals relevant to hybrid identity
  • Source of authority: on-prem vs cloud identity control
  • Identity control plane expansion across hybrid environments
  • Trust relationships between Active Directory and Entra ID
  • Identity flows across hybrid authentication models
  • Identity synchronization: Entra Connect vs Cloud Sync
  • Synchronization components, flows, and architecture (high-level)
  • Sync vs federation models and trade-offs
  • Object matching: hard match vs soft match
  • Source-of-authority abuse and identity takeover via matching
  • Microsoft hard-match enforcement changes (2026)
  • Sync infrastructure and connector identities
  • Connector account privileges and access scope
  • Entra Connect as a high-value target
  • Sync abuse primitives: attribute manipulation (AD to Entra)
  • Group membership and nested group abuse via synchronization
  • Writeback mechanisms: password, group, and device risks
  • Preparing privilege escalation via synchronization
  • Active Directory attack path fundamentals (recap)
  • Extending attack paths across hybrid boundaries
  • Cross-plane privilege escalation scenarios (AD → Entra)
  • Domain Admin to Global Admin escalation paths
  • Sync account abuse scenarios
  • Attribute-based privilege escalation techniques
  • Group nesting leading to cloud privilege escalation
  • Kerberos fundamentals in hybrid identity
  • Seamless SSO and AZUREADSSOACC account risks
  • Kerberos abuse leading to cloud access
  • Modern hybrid authentication: PHS, PTA, and federation
  • Federation fundamentals and minimal configuration concepts
  • Federation attack surface and trust risks
  • Securing hybrid identity: Tiering model foundations
  • Extending Tier-0 to hybrid identity systems
  • Protecting synchronization infrastructure
  • Privileged access boundaries across AD and Entra ID
  • Enterprise Access Model (EAM) as evolution of tiering

Section 4Identity Governance, External Trust and Lifecycle Security

Day 4 focuses on identity governance and lifecycle security as critical controls for limiting attack persistence. Students analyze how weak ownership, excessive privileges, and external trust in Microsoft Entra ID enable long-term access, covering agent identity governance alongside workload identity with ownership models, credential management, and access reviews for AI workloads.

Topics covered

  • Identity lifecycle risks: joiner, mover, leaver and ownership gaps
  • Privileged access governance: PIM, JIT, and break-glass accounts
  • Access governance: reviews, entitlement management, and policies
  • External identities, cross-tenant access, and delegated administration
  • Governance failures enabling persistence and long-lived access

Labs

  • Identify risky roles and PIM misconfigurations
  • Analyze lifecycle and governance gaps
  • Explore cross-tenant access and risks
  • Identify persistence via external identities

Overview

Day 4 shifts focus from attack execution to the governance and lifecycle controls that determine whether attackers can maintain long-term access. Students explore how identity lifecycle processes, ownership models, and privilege management directly impact the security of the identity control plane.

The day examines how weak governance enables persistence through overprivileged accounts, orphaned access, and unmanaged application identities. Students also analyze how external identities and cross-tenant trust relationships expand the attack surface beyond organizational boundaries.

By the end of the day, students understand how to detect governance failures, reduce identity sprawl, and implement controls that limit persistence. This includes strengthening privileged access governance, improving lifecycle automation, and securing external identity relationships.

Full Labs Details

  • Lab 4.1: Identify Risky Roles and PIM Misconfigurations: Analyze privileged roles, identify excessive access, and evaluate PIM configurations.
  • Lab 4.2: Analyze Lifecycle and Governance Gaps: Investigate identity lifecycle processes to uncover orphaned access and ownership issues.
  • Lab 4.3: Explore Cross-Tenant Access and Risks: Examine cross-tenant configurations and identify potential abuse scenarios.
  • Lab 4.4: Identify Persistence via External Identities: Detect how external identities and governance gaps can be used for long-term access.

Full Topic Details

  • Identity lifecycle risks: joiner, mover, leaver processes
  • Orphaned access and ownership gaps
  • Identity sprawl and unmanaged identities
  • Lifecycle automation: workflows and task extensions
  • Privileged Identity Management (PIM) fundamentals
  • Just-in-Time (JIT) and Just-Enough Access (JEA) concepts
  • Break-glass accounts and emergency access considerations
  • Access governance: access reviews and decision processes
  • Recommendation-based access decisions
  • Entitlement management and access packages
  • Workload identity governance: service principal ownership
  • Credential management for applications and service principals
  • Access reviews for applications and workload identities
  • External identity models: B2B collaboration
  • Cross-tenant access settings and controls
  • Cross-tenant synchronization for users and groups
  • Delegated administration: GDAP and Azure Lighthouse
  • Third-party identity providers and federated credentials
  • Agent identity governance considerations
  • Governance failures leading to persistence
  • Long-lived access and privilege accumulation
  • External identity abuse scenarios

Section 5Hybrid Identity Threat Detection, Prevention and Response

Day 5 focuses on detecting and responding to identity-based attacks across hybrid environments. Students use telemetry from Microsoft Entra ID and Active Directory supported by AI-assisted and agentic response workflows, to investigate attacks, contain compromised identities, and restore trust. The day ends with a story-driven Capture the Flag (CTF) where students respond to an end-to-end hybrid identity breach putting everything from the week into practice.

Topics covered

  • Identity telemetry: sign-in, audit, and Graph activity logs
  • Identity attack patterns across the kill chain
  • Detecting token abuse, OAuth attacks, and session hijacking
  • Hybrid attack detection: sync, federation, and trust abuse
  • Incident response: containment, remediation, and validation

Labs

  • CTF:  Hybrid Identity Compromise Investigation

Overview

Day 5 brings together detection, prevention, and response across the full identity attack lifecycle. Students learn how to use identity telemetry to detect attacks that blend in as legitimate activity, including token abuse, application misuse, and hybrid escalation, supported by AI-assisted and agentic response workflows.

The day follows attacker techniques across initial access, persistence, privilege escalation, and lateral movement, with a focus on how these appear in logs and how to correlate signals across systems. Students analyze sign-in logs, audit logs, and Graph activity to uncover subtle indicators of compromise.

The day ends with a story-driven Capture the Flag where students take on the role of an incident responder and work an end-to-end hybrid identity breach. The exercise starts from a suspicious change on a sensitive Entra application object and following the attack chain across Microsoft Entra ID and on-premises Active Directory to full resolution.

Full Labs Details

  • CTF – Hybrid Identity Compromise Investigation
  • A story-driven Capture the Flag covering 13 challenge groups in sequence. Players investigate a full hybrid identity breach using Entra audit telemetry and KQL, Active Directory forensics, PIM review, sign-in baselining, and Conditional Access analysis. This game puts every concept from the week into practice in a single connected scenario.

Full Topic Details

  • Identity telemetry: Sign-in logs, Audit logs, Graph activity logs
  • Correlation concepts: user, application, session, and time
  • Visibility gaps and limitations in identity monitoring
  • Identity attack patterns: initial access, persistence, escalation
  • Lateral movement and hybrid attack scenarios
  • Initial access techniques: OAuth abuse and token theft
  • Session hijacking and non-interactive authentication abuse
  • Detection techniques: sign-in anomalies and consent events
  • Persistence techniques: service principal credentials and tokens
  • Cross-tenant persistence and long-lived access
  • Detection: credential additions and privilege changes
  • Privilege escalation: role changes and permission abuse
  • Detection: role assignments and permission grants
  • Hybrid attacks: synchronization abuse and federation attacks
  • Detection: correlated AD and Entra changes
  • Lateral movement: Graph API abuse and token-based access
  • Detection: API activity patterns and anomalies
  • Prevention: limiting permissions and enforcing least privilege
  • Response strategies: revoke vs rotate decisions
  • Token invalidation limitations and considerations
  • Hybrid containment challenges across AD and Entra
  • Validation and monitoring after remediation
  • Automation and AI-assisted response workflows

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer) or AMD equivalent, with a minimum 2.0+ GHz processor. (No Apple M devices.)
  • RAM: 16GB or more.
  • Storage: At least 150GB of free space.
  • Wireless Networking: 802.11 Wi-Fi is required as no wired internet access is available in the classroom.
  • Virtualization: Ensure your BIOS settings enable virtualization (e.g., Intel-VTx or AMD-V). Verify that you can access BIOS if password protected.
  • Critical Note: Apple Silicon devices (M chips) cannot support necessary virtualization and are not compatible with this course.

Mandatory Host Configuration and Software Requirements

  • Host OS: Latest version of Windows 11 or newer. Linux hosts are not supported in class.
  • Local Administrator Access: This is required. Ensure you have admin rights or make arrangements for a different laptop if your company restricts access.
  • VMware:
    • Download and install the latest version of VMware Workstation Pro.
    • "Pro" versions are required. "Player" versions are insufficient.
    • Ensure VMware runs smoothly and can boot a virtual machine. This may require disabling Hyper-V on Windows hosts.
  • Compression Tools: Install 7-Zip.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

This course is designed for technical professionals who secure, monitor, or respond to identity-related threats in Microsoft cloud and hybrid environments.

  • IAM engineers and architects
  • Security engineers and cloud security engineers
  • SOC analysts and incident responders
  • Microsoft 365 and Entra administrators with security responsibility
  • Cybersecurity consultants focused on Microsoft or hybrid identity environments
  • IT administrators moving into security or identity-focused roles

  • Electronic and printed courseware
  • SANS provisioned Entra ID account

  • Familiarity with Azure AD/Entra ID basics (users, apps, roles)
  • Some experience with identity protocols or authentication concepts
  • Comfort working with logs or Kusto queries (helpful but not required)

SEC559 is part of the SANS Cloud Security curriculum, designed to help practitioners build advanced skills for securing modern cloud and hybrid environments. The course complements cloud security, detection, and architecture training by focusing specifically on identity as the primary control plane.

It fits naturally for professionals who already work with cloud or enterprise environments and want to deepen their ability to detect and remediate identity-driven attacks across cloud and hybrid identity control planes.

The course is also part of the Cloud Security Analyst journey, designed for practitioners who needs to secure environments, detect threats, secure identity, and respond to breach. The Analyst Journey is built to develop all three. The other two courses in the journey are:

Identity security protects users, applications, and services that control access to modern environments, ensuring access is legitimate, authorized, and continuously validated across cloud and hybrid systems. As traditional network boundaries dissolve under cloud, remote work, automation, and AI, identity becomes the primary control plane and the primary target.

Attackers chain small identity failures together: compromised credentials, abused OAuth consent, leaked secrets, and manipulated federation trust let them operate with legitimate access that bypasses traditional defenses and escalates into tenant- or domain-wide compromise. But detection alone is not enough. Privilege sprawl, orphaned accounts, and ungoverned application access create the conditions attackers exploit long before a breach begins. Effective identity security means governing the full lifecycle of every identity in your environment so that when an attack occurs, the blast radius is contained, and the path to remediation is clear.

SEC559 builds expertise in one of the fastest-growing areas of cybersecurity: identity security. As organizations shift to cloud and hybrid environments, security teams urgently need practitioners who can detect, govern, and respond to identity-based attacks that bypass traditional defenses.

This course gives you hands-on experience across the full identity lifecycle, from detecting OAuth abuse and token theft to governing privilege and access, and executing safe, structured remediation. You will develop practical skills that align directly with roles in IAM, cloud security, SOC operations, incident response, and security architecture.

By completing SEC559, you position yourself as a cyber professional who understands how attackers operate today: abusing credentials, tokens, applications, and trust relationships rather than exploiting software vulnerabilities. You will also have the skills to govern identity at scale, closing the privilege and lifecycle gaps that attackers rely on before an incident ever begins.

Beta courses are part of the SANS course development process, designed to bring new training to market in collaboration with the practitioner community. These early-access runs allow students to engage with the course while providing feedback that helps refine content, labs, and delivery before full release.

For SEC559, the beta delivers fully developed course content with complete labs, expert instruction, and full student support. It is also offered at a 25% discount off full course cost, giving you the opportunity to take the course early while it is being finalized for general release.

  • Be among the first to take SEC559 before general release
  • Access the course at a reduced beta price (25% off full course cost)
  • Provide feedback that helps refine the final course

Relevant Job Roles

Cloud Security Analyst Training, Salary, and Career Path

Cloud Security

A Cloud Security Analyst monitors and analyzes activity across cloud environments, proactively detects and assesses threats, and implements preventive controls and targeted defenses to protect critical business systems and data.

Explore learning path

Cloud Threat Detection and Response

Cloud Security

Monitor, test, detect, and investigate threats to cloud environments.

Explore learning path

Course Schedule and Pricing

Looking for Group Purchasing Options?Contact Us
Showing 3 of 3

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources