Skip to main content

Identity lifecycle and authentication

Design proofing, enrollment, authenticators, sessions, recovery, federation, and non-human identity as one system.

Learning outcomes

  • Separate actors, subjects, principals, credentials, authenticators, and sessions.
  • Select assurance, phishing resistance, federation, and recovery controls from risk.
  • Operate joiner, mover, leaver, credential, and session lifecycles.
  • Preserve distinct human, workload, device, and agent identity where policy needs them.

Scenario

Employees use one identity provider, contractors use another lifecycle, managed devices provide posture data, and deployment automation needs a separate workload identity. Each path needs a distinct credential and policy boundary.

Ordered learning units

  1. Concept

    Authentication

    Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

  2. Concept

    Password Authentication

    Evaluate password verification, storage, throttling, compromised values, phishing, reuse, and recovery as one control.

  3. Guide

    Evaluate WebAuthn and passkeys

    Trace WebAuthn registration and authentication across relying party, browser, authenticator, origin, and user verification.

  4. Guide

    Secure the session lifecycle

    Design session creation, binding, renewal, expiry, reauthentication, revocation, and termination after sign-in.

  5. Concept

    Account Recovery

    Restore account access without giving attackers an easier path than the normal authentication and enrollment process.

Evaluation questions

  • Which authority issues each human, device, workload, and agent identity?
  • Which authenticators, claims, assurance levels, and lifetimes does policy need?
  • How do recovery, lifecycle, rotation, and revocation events reach every access path?

Completion conditions

  • Trace one human and one workload from enrollment through access, recovery, and removal.
  • Prove that a disabled identity, old session, wrong audience, and weak recovery path fail within stated bounds.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo