Advertisements

Non-Human Identity and AI Agent Security: IAM, SIEM, SOC

Advertisements
Find shadow AI agents, swap static API keys for short-lived tokens, detect rogue agents in the SIEM and stop them fast
1
1/5
(78) Ratings
0 students
Created by PapaHR ★ 170K students: Courses in Human Resources, HR, SHRM, AI Talent Analytics, HRMS, HRIS, CIPD, Claude, HRCI, PHR, Rewards
Advertisements

What you'll learn

  • Find every AI agent in your environment, including shadow agents, across 12 discovery sources and log each one in an agent registry
  • Replace a static agent API key with a short-lived token and grant permissions for one task at a time
  • Rotate agent credentials without downtime and prove with an 8-check revocation test that revoked access no longer works
  • Contain a compromised AI agent within minutes using an incident response playbook with tiered kill switch levels
  • Tell an AI agent apart from a service account and name the main risk and control for each non-human identity class
  • Give every agent an owner, a purpose, data boundaries and a lifetime before it gets any access
  • Build a behavioral baseline for an agent, set detection thresholds and score agent risk
  • Bring agent logs into the SIEM, correlate them with the agent registry and triage an agent alert in the SOC
  • Learn with Mike Pritula, the #1 HR instructor on Udemy, alongside 2,000,000+ of his Udemy students
This course includes:
6 total hours on-demand video
0 articles
24 downloadable resources
8 lessons
Full lifetime access
Access on mobile and TV
Certificate of completion
Advertisements

Course content

Requirements

  • Working knowledge of identity and access management for people: SSO, MFA and roles
  • Basic experience with SIEM alerts and with cloud IAM and secrets in AWS, Azure or GCP
  • No AI or machine learning background and no agent development skills are needed
  • Excel or Google Sheets and a web browser for the course tools
  • Access to your own company environment is helpful for the assignments, but not required

Description

This course contains the use of artificial intelligence

AI agents are getting access to email, code, cloud accounts and customer data faster than any IAM team can see them. Can you name every agent in your company, its owner and exactly what it is allowed to do?

You already run identity for people: SSO, MFA, roles, joiners and leavers. Agents do not follow that path. A vendor switches on a copilot, a developer ships an agent with a static API key, an employee connects a tool through an OAuth grant, and none of them goes through your onboarding. Nobody owns the agent, nobody wrote down its purpose, and the key it uses never expires. When an alert fires, the SOC cannot tell whether the agent is doing its job or has gone beyond it. When you revoke a key, you cannot be sure the agent has really lost access.

After this course you run AI agents as their own identity class. You know where agents live in your environment and keep them in a registry. Every agent gets an owner, a purpose, data boundaries and a lifetime before it gets access. Static keys give way to short-lived tokens issued for one task. You rotate credentials without downtime and prove with a test that revoked access is gone. Agent logs reach the SIEM and link back to the registry, the SOC has a triage playbook, and when an agent is compromised, you contain it in minutes with a kill switch your team has already rehearsed.

The course is taught by Mike Pritula, founder and head of strategy of Pritula Academy. He is not presented here as a security engineer: he brings the discipline of building processes, owners and rules for new systems, and the technical content is built on public identity standards, such as OAuth 2.0 token exchange, and on cloud provider documentation.

  • #1 HR instructor on Udemy, with 2,000,000+ students on Udemy

  • Founder and head of strategy of Pritula Academy, where 170,000+ students have trained

  • 20 years of experience at Wargaming, Preply, iDeals, Starlightmedia and Sense Bank, including the growth of the unicorn Preply

First you learn to see: how an agent differs from a service account and where agents hide in your identity provider, cloud, SaaS consoles, network and code. Then you take control of the agent lifecycle: owner and purpose, short-lived access for one task, and rotation and revocation you can prove. Finally you move into operations: behavioral baselines, agent telemetry in the SIEM and SOC, and incident response with a kill switch. The format is hands-on, built on real-world scenarios, and each lesson stands on its own. A SOC analyst who has to handle an agent alert tomorrow can watch lesson seven tonight and open the triage playbook in the morning.

The course does not cover model security, such as jailbreaks and red teaming of language models, agent development or vendor selection. It stays on identity and access, where your team can act right away.

What's included:

  • Lifetime access to all materials

  • Active instructor support in Q&A

  • Udemy Certificate of Completion

  • A practical assignment tied to your own company in every lesson

  • Ready-to-use tools: an identity class map, an agent registry, an agent card with an onboarding policy, a token and access design with a scope review checklist, a rotation runbook with a revocation test, a detection catalog with a risk score calculator, an agent telemetry schema with a SOC triage playbook and an incident response playbook with a tabletop scenario

Non-human identity is a new field, and the engineers who build agent inventories and response playbooks now will set the rules their companies follow for years. Every month an agent runs without an owner and with a key that never expires is a month of open access nobody watches.

Enroll now and start your first lesson today.

Who this course is for:

  • Security engineers responsible for identities, access and secrets in their company
  • IAM and identity engineers who now have to govern AI agents and machine identities
  • SOC analysts who need to triage alerts about AI agents and service accounts
  • Cloud security engineers working with workload identity in AWS, Azure or GCP
  • Systems administrators who manage API keys, OAuth apps and service accounts
  • DevSecOps engineers whose teams ship their own AI agents into production
Advertisements
PAPAHR_SEP_203734
Advertisements
Advertisements
Free Online Courses with Certificates
Logo
Register New Account