Am I thinking about IAM/PAM correctly, or am I missing something?

Had a conversation with an architect today about IAM, and I think we were talking past each other.
My background is systems/infrastructure, so when I think IAM I think AD users/groups, RBAC, MFA, privileged accounts, service accounts, and mapping access/rights into application based roles.
The way they described it made IAM sound like a much more separate/specialized discipline than I’m used to thinking of it.

For those who actually work in IAM: is the job mostly administering and governing who gets access to what, or are you actually hands-on configuring the applications and identity integrations themselves with SSO, group/role mappings, MFA, provisioning.

I’m trying to understand where IAM stops being “access administration” and becomes actual identity engineering.

reddit.com
u/solslost — 1 day ago

Is the WGU Cybersecurity Master’s actually worth it, or is it as shallow as it looks?

TL;DR: I’ve been in IT for 20+ years, already have a pile of security/cloud certs, and I’m almost done with WGU’s Cloud Computing bachelor’s. Based on that experience, I’m worried the Cybersecurity Master’s is going to be shallow and mostly checking boxes.

For experienced people who’ve done it: did you actually learn anything substantial?
For those with IT/security experience who did WGU’s Cybersecurity Master’s: did you actually learn anything, or was it mostly checking boxes for the degree?

That’s really what I’m trying to figure out before I commit to it.

I’ve been in IT for 20+ years. I’m bringing in basically every cert WGU will accept—Security+, CySA+, CASP+/SecurityX, CCSP, etc.—so I think I’ll have around four classes knocked out. Failed the CISSP in 2016, thinking to technical.
I also went through the OSCP course about a decade ago and compromised six or seven boxes, although I never sat for the cert.

I’m almost done with WGU’s Cloud Computing bachelor’s, and that’s where most of my skepticism comes from. Some of it has been useful, but a lot of it has felt pretty half-assed. I honestly feel like I could spend $500 a year on a good technical training platform and learn more useful hands-on material.

Looking at the Cybersecurity Master’s curriculum, I’m getting the same feeling.
I’m not expecting a master’s degree to turn me into a malware reverse engineer or exploit developer. I just want to come out of a Master’s in Cybersecurity actually knowing substantially more cybersecurity than I did going in.

For those who already had experience before starting it: did the program actually make you better technically, or was it mostly a credential?

reddit.com
u/solslost — 12 days ago

How would you fix this

Thought this was 1x6 without pulling the trim. So I bought some 1x6 pvc trim.

Replace whole 2x6 with ground contact.

Cut out lower rotten sections. Use two 1x6s of PVC at bottom.

u/solslost — 2 months ago

Are theses tomatoes

Have a bunch of randoms popping up. Are they tomatoes?

u/solslost — 3 months ago