Learning outcomes
- Separate actors, subjects, principals, credentials, authenticators, and sessions.
- Select assurance, phishing resistance, federation, and recovery controls from risk.
- Operate joiner, mover, leaver, credential, and session lifecycles.
- Preserve distinct human, workload, device, and agent identity where policy needs them.
Scenario
Employees use one identity provider, contractors use another lifecycle, managed devices provide posture data, and deployment automation needs a separate workload identity. Each path needs a distinct credential and policy boundary.
Ordered learning units
Actor, Subject, and Principal
Separate the real-world actor, active subject, represented principal, digital identity, and account.
Identifier, Account, Record, and Person
Separate a label, system account, directory record, and real person before joining identity across systems.
Credential and Authenticator
Distinguish a bound credential, an authenticator, its secret or key, a factor type, and protocol output.
Identity Proofing and Enrollment
Resolve a claimed real-world identity, validate evidence, verify the applicant, and bind the result to an account.
Trace the digital identity lifecycle
Follow identity proofing, enrollment, authenticators, federation, sessions, account changes, recovery, and termination.
Authentication
Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.
Password Authentication
Evaluate password verification, storage, throttling, compromised values, phishing, reuse, and recovery as one control.
Multi-Factor Authentication (MFA)
Require authenticators from distinct factor types and evaluate phishing, enrollment, recovery, and session threats.
Evaluate WebAuthn and passkeys
Trace WebAuthn registration and authentication across relying party, browser, authenticator, origin, and user verification.
Validate an OpenID Connect sign-in
Trace OpenID Connect sign-in and validate issuer, client, redirect, state, nonce, ID token, and access-token boundaries.
Design multi-IdP routing and account linking
Route sign-in across identity providers without issuer confusion, account collision, unsafe linking, or recovery bypass.
Secure the session lifecycle
Design session creation, binding, renewal, expiry, reauthentication, revocation, and termination after sign-in.
Test common authentication attacks
Distinguish and test guessing, stuffing, spraying, phishing, MFA fatigue, recovery abuse, and session theft.
Account Recovery
Restore account access without giving attackers an easier path than the normal authentication and enrollment process.
Joiner, Mover, and Leaver Lifecycle
Create, change, and remove identity and access state when a person or workload enters, changes, or leaves a role.
Design human and non-human identity lifecycles
Give people, services, workloads, devices, and agents distinct identity, delegation, credential, and revocation models.
Evaluation questions
- Which authority issues each human, device, workload, and agent identity?
- Which authenticators, claims, assurance levels, and lifetimes does policy need?
- How do recovery, lifecycle, rotation, and revocation events reach every access path?
Completion conditions
- Trace one human and one workload from enrollment through access, recovery, and removal.
- Prove that a disabled identity, old session, wrong audience, and weak recovery path fail within stated bounds.
