Do you have a centralized view of all user identities (internal, external, contractors)?
Do you have a clear mapping of entitlements and access rights per application?
Is user onboarding automated?
How long does it take to remove all access after an employee leaves?
Have you already identified active accounts belonging to former employees?
Do you use any strong authentication method for daily accesses?
Strong authentication can be knowledge factors, possession factors, biometric factors, or a combination of some of them (Multifactor authentication-MFA)
Is MFA enabled for all sensitive access?
Do you perform periodic user access reviews?
How much visibility do you have into who has access to what?
Have you ever encountered difficulties during an audit (ISO, NIS2, HDS, GDPR) related to access management?
Does your IAM cover all your environments (on-prem, cloud, hybrid)?
How many applications are integrated with your IAM?
Is your IAM perceived internally as an enabler or a constraint?
Optional Question: You can indicate here anything you did not see in the quiz and would like to share with us, or anything else you would like to tell us.