All articles

Work Authorization

CPT Compliance for Master's Students in Information Security and IAM

Curricular practical training is the mechanism that lets a master's student in information security take a paid internship while still enrolled. It is also the mechanism most likely to be misunderstood, because its defining requirement is not the quality of the job but its relationship to the curriculum. An outstanding IAM internship that is not integral to the programme is a compliance problem; a modest one that is properly integrated is not.

Integral to the established curriculum

The training must be an integral part of the degree programme — a required practicum, a credit-bearing internship course, or work that directly feeds a thesis or capstone. Security programmes increasingly build these in deliberately, precisely because employers want candidates who have touched a real directory rather than a lab tenant.

Framing matters. An internship described as 'general IT support' is hard to tie to an information security curriculum. The same role described as 'access-request triage, joiner-mover-leaver workflow testing and access-certification support' maps cleanly onto identity governance coursework and is much easier for a school to authorise.

Authorization must precede the first day

Authorization is granted by the school before work begins, is employer-specific, and is bounded by explicit start and end dates. Working before the authorization is issued, continuing past the end date, or moving to a different employer without a new authorization are all violations — and none of them are cured retroactively.

Practically, this means the offer, the course registration and the authorization request need to be sequenced weeks ahead of the intended start. Employers who understand the sequence build it into their intern onboarding calendar; those who do not often create the delay themselves.

Part-time, full-time and the aggregation rule

Part-time training is capped at twenty hours per week while school is in session; anything above that is full-time. The aggregation rule is the one that catches people: twelve months or more of full-time curricular training eliminates eligibility for post-completion optional practical training in that degree level. Part-time training does not carry that consequence.

For a two-year security master's, the sensible pattern is part-time work during terms and full-time work over a single summer, keeping the cumulative full-time total well clear of the threshold and preserving the post-graduation runway.

What makes a security internship worth the paperwork

The strongest internships give a student something concrete to point at in interviews: a SCIM connector that was built and tested, a certification campaign that was run end to end, a set of stale entitlements that were identified and removed. Access to a real production identity platform, even in a read-only or lower-environment capacity, is worth more than a broader role with no platform exposure.

Students should also keep a private record of what they built. Two years later, in a hiring conversation, specificity about protocols, connectors and failure modes is what separates a candidate from the rest of the pile.

Key takeaways

  • The work must be integral to the curriculum — frame the role in identity-governance terms.
  • Authorization is employer-specific and must be issued before the first day of work.
  • Twelve months of full-time curricular training removes post-completion eligibility at that degree level.
  • Prioritise internships with real platform exposure over broader roles without it.

Hiring or being hired in IAM?

TagWin Recruiting places Okta, Ping, SailPoint and CyberArk specialists with enterprises that cannot afford an identity gap.

Start an intake

Related articles