Training / PAM Foundation

Training

PAM Foundation

For engineers new to Idira (formerly CyberArk) who need to operate a deployment confidently.

Overview

PAM Foundation

Covers the core PAM components from first principles, with a working environment from day one. Ends with structured preparation for the Defender certification.

Duration10 days
AudienceEngineers, administrators and support staff new to Idira
FormatLive instructor-led · 2 to 8 hours per day · scheduled in your time zone
CommercialPer seat or per corporate batch
Syllabus

What the programme covers

Vault architecture and safesStorage model, safe design, permissions and the security layers that make the vault what it is.
Account onboarding at scaleDiscovery, bulk upload, onboarding rules and the practical failures that stall onboarding waves.
CPM rotation and reconciliationPlatform configuration, rotation policy, reconciliation accounts and diagnosing failed rotations.
PSM session managementSession isolation, recording, connection components and universal connectors.
PVWA administrationAccess control, request and approval workflows, reporting and hardening.
Defender exam preparationStructured revision against the exam objectives, with practice scenarios.
How it runs

Labs, not slides

Most Idira training teaches the interface. This teaches the model underneath it, because engineers who understand why the vault behaves as it does can troubleshoot problems the courseware never covered.

The lab

Every participant is provisioned an isolated environment containing a vault, a CPM, a PVWA, a PSM and a set of target systems. It stays live for the duration of the programme and two weeks afterwards. Break it deliberately — the failures are where the learning happens.

Ready to build the team you need?

Corporate batches are scoped to your deployment and scheduled in your time zone. Open cohorts run for individual engineers.

Request a syllabus
How we work

These principles guide every engagement

They define how we design, deliver and operate identity security for our customers.

Certified, not just familiar

Guardian-led, with CDE credentials across PAM, Privilege Cloud, EPM and Secrets Manager, kept current on every release.

Architect-led delivery

Design is reviewed and signed off before anything is built, so what goes live is what was agreed.

Written scope, fixed price

Deliverables, timeline and price in writing before work starts. No open-ended retainers.

Enablement built in

Your team is trained during delivery, so what we build does not depend on us to keep running.

Contact us

Need identity security you can trust?

Talk to a certified architect about protecting privileged access, identities and critical systems. The first call is technical, not a sales pitch.