This is the third part in the Identity series. Part 1 covered Foundation-stage controls: federated identity, MFA, directory sync, and audit logging. Part 2 covered Advanced identity: ABAC, dynamic policy evaluation, and continuous access enforcement.