Beyond the Login
Understanding identity, one piece at a time.
Beyond the Login is an educational playground that will grow into a fully featured service. Our aim is to help you learn identity from the ground up, piece by piece, while developing marketable, real-world skills.
- How people, applications, and services establish identity and trust
- How access is granted, enforced, reviewed, and removed
- How protocols, policies, and security controls work together in practice
Identity is more than just a login. #
Consider the world around you. Identity runs through so much of what we do: presenting a passport or identification card, entering a PIN or one-time password, badging into a workplace, or using biometrics to enter a secure area. Who you are, what you know, and what you possess can all play a part in how trust and access are established.
Every day, we rely on the way identity controls are implemented. For those of us designing, building, and securing these systems, understanding the decisions behind those controls is essential.
The identity landscape #
The Identity fundamentals introduce the whole landscape through one example. After them, the lessons are organized into these areas. They overlap: understanding how they connect matters as much as understanding each one on its own.
What makes an identity trustworthy?
How identities are established through proofing, and how credentials, keys, certificates, and public key infrastructure (PKI) support trust. Start with What proofing establishes.
How do people sign in, and how do applications act for them?
Authentication methods and multi-factor authentication (MFA), single sign-on (SSO), delegated access with OAuth 2.0, and sign-in with OpenID Connect. Lessons on SAML, Kerberos, and WS-Federation are planned. Start with Methods, credentials, and factors.
What should that identity be allowed to do?
Permissions and access decisions, role-based access control (RBAC), attribute-based access control (ABAC), relationship-based access control (ReBAC), and how policies are evaluated, enforced, tested, and changed. Start with Designing permissions.
How should access change over time?
Directories, joiners, movers, and leavers, provisioning with SCIM, access requests, roles, separation of duties, and access reviews. Follow identities from their creation through changing responsibilities to the removal of access. Start with Why access needs governance.
What about identities that aren’t people?
Applications, services, workloads, and AI agents need identities too. Lessons on how they authenticate, and how they act with their own permissions or with authority delegated by others, are planned.
How do we protect the trust we depend on?
Account takeover, stolen sessions and tokens, privilege escalation, and the footholds attackers leave behind. Understand what can go wrong and how to recognize, investigate, contain, and prevent it. Start with Why attackers go after identity.
From concepts to practice #
The goal is to make the details approachable without losing what makes them important. Each lesson connects a clear explanation to examples you can follow and inspect, and the Lab will let you try many of them yourself.
-
01
Understand the problem
Start with the question a technology or policy answers, the people and systems involved, and the trust between them.
-
02
See how it works
Follow a protocol exchange, inspect a credential, or trace an access decision. Connect each step to the concept behind it.
-
03
Put it into practice
Work through examples, change a configuration, and investigate failures. Learn both how to implement something and why it behaves the way it does.
A broad ambition, built one topic at a time
The menu shows the whole curriculum. Published lessons are links, and topics still in preparation are marked Planned. Each lesson ends with a short quiz, and the Lab pairs some lessons with hands-on exercises.