Identity and access management (IAM) controls who accesses your assets and what they do. Most companies manage this with Windows Active Directory.
Identity and access management decides who gets into your systems, what they are allowed to do once inside, and how that permission is proven. Many organizations manage it through a central directory service.
Many damaging intrusions break nothing at all; the attacker simply logs in with credentials that still worked. Dormant accounts, shared logins, and forgotten admin rights are the gaps they look for first. Tight identity practices shrink what any single stolen password can reach, and checking whether those controls hold up in practice is what penetration testing is for.