Skip to content

Repository files navigation

IAM Proof Portfolio — Microsoft Entra ID Governance

Hands-on identity governance evidence packs for Microsoft Entra ID aligned to CMMC Level 2 and NIST 800-53 regulated environments.

License: MIT NIST 800-53 CMMC Level 2 Zero Trust Status


What This Portfolio Is

Seven complete IAM and identity governance packs demonstrating practical governance workflows, operational controls, and audit-ready evidence aligned to regulated environments.

Every pack includes:

  • Policy documentation and governance standards
  • NIST 800-53 and CMMC Level 2 control mappings
  • Microsoft Entra ID configuration evidence
  • Operational workflow demonstrations
  • Interview preparation notes and governance explanations
  • Resume-ready impact statements tied to governance outcomes

This portfolio demonstrates practical IAM governance workflows with supporting evidence, control mappings, and operational documentation.


For IAM Hiring Managers

These packs answer the question many hiring managers ask:

“Can this person practically operate IAM governance workflows?”

Open any pack to review governance policies, Microsoft Entra ID configurations, lifecycle workflows, access governance processes, control mappings, and audit-ready evidence aligned to regulated environments.

Strongest packs for IAM and Identity Governance interviews:

  • JML Lifecycle — onboarding, transfers, deprovisioning, lifecycle governance
  • Privileged Access (PIM) — privileged access governance, approval workflows, JIT activation
  • Conditional Access — Zero Trust policy governance and Conditional Access enforcement
  • Automation Scripts — PowerShell and Microsoft Graph governance automation

For Governance & Compliance Operations

Each pack includes the types of governance documentation, evidence structures, control mappings, and operational workflows commonly associated with regulated IAM and compliance environments.

Topics include:

  • Identity lifecycle governance
  • Access reviews and certification campaigns
  • RBAC and least privilege enforcement
  • Conditional Access governance
  • Privileged Identity Management (PIM)
  • Segregation of Duties (SoD)
  • Audit-ready evidence preparation
  • Governance automation using PowerShell and Microsoft Graph

Pack Index

# Pack Domain Key Controls Evidence
01 JML Lifecycle Identity Lifecycle AC-2, AC-2(1), AC-3, AC-6, IA-2 6 screenshots
02 Access Reviews Access Governance AC-2, AC-6, AC-6(7), CA-7 6 screenshots
03 Privileged Access (PIM) PAM / Zero Trust AC-6(5), IA-2, AC-3 7 screenshots
04 Conditional Access Zero Trust IA-2, AC-3, AC-17 6 screenshots
05 SoD Matrix GRC / Compliance AC-5, AC-6, AU-2, AU-9, CA-7 15-conflict matrix
06 PowerShell Automation IAM Automation Cross-cutting governance automation 5-script control system
07 Sparks AI Operations Application Governance AC-2, AC-3, AC-4, AC-6, AU-2, AU-9, IA-2, SI-4 Governance platform demonstration

Standards & Governance Alignment

Every pack is aligned to:

  • NIST SP 800-53 Rev 5
  • NIST SP 800-171
  • CMMC Level 2
  • SOC 2 Type II (CC6)
  • CISA Zero Trust Maturity Model

Identity & Governance Stack

Identity & Access Management

Microsoft Entra ID · Microsoft Entra ID Governance · Microsoft Entra PIM · Conditional Access · Active Directory · Microsoft Graph · RBAC · CAC/PKI · SAML · OAuth · OIDC · SCIM

Governance & Compliance

NIST 800-53 Rev 5 · NIST 800-171 · CMMC 2.0 · Zero Trust (CISA ZTMM) · DFARS · Audit Readiness & Evidence Governance

Technical & Automation

PowerShell · Microsoft Graph · Azure Fundamentals · Python · Bash · SQL · Terraform Fundamentals


Certifications

Identity, Governance & Security

  • SailPoint Identity Security Leader
  • Okta Explore Identity Foundations
  • SC-900 — Security, Compliance & Identity Fundamentals
  • Security+
  • CCZT (Zero Trust)
  • CCSK v5
  • CMMC RP (CyberAB)

Cloud & Infrastructure

  • AZ-900
  • AWS Certified Cloud Practitioner
  • Network+
  • ISC2 Certified in Cybersecurity (CC)
  • ITIL 4 Foundation
  • FinOps Certified Practitioner

Currently Pursuing

  • SC-300
  • AZ-500
  • Okta Certified Professional
  • Okta Certified Administrator

Background

Robert J. Myers — Identity Governance & Access Management (IAM)

20 years U.S. Navy (2001–2021) supporting identity accountability, personnel security, audit readiness, credential governance, and access governance operations across regulated federal environments.

Operational experience includes:

  • 3,500+ identities governed
  • 2,200+ CAC/PKI credentials managed
  • Zero security incidents across four years in access governance leadership roles

Civilian experience includes aerospace manufacturing, regulated operational governance, DFARS/ITAR environments, procurement accountability, and compliance-driven operational workflows.

Education:

  • MBA — University of the Incarnate Word
  • BS Accounting — Colorado Technical University

Prior U.S. Government Secret Clearance | DOJ High-Risk Public Trust


Open To

  • IAM / IGA operations and governance roles
  • Identity governance and access management opportunities
  • Governance, compliance, and security operations roles
  • CMMC readiness and governance engagements

Contact


This portfolio is actively maintained. Each pack is versioned and updated independently.

Last updated: May 2026

About

Production-grade IAM governance evidence packs for Microsoft Entra ID — JML, Access Reviews, PIM, Conditional Access, SoD, PowerShell automation. NIST 800-53 + CMMC Level 2 aligned. Built by a Navy-trained IAM architect.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages