TrackIdentity Standards — 14 hands-on labs. Practise in a disposable environment.HomeFAQ
03 Track 03 · 14 labs

Identity Standards

Vendor-neutral fluency across the protocols and policy languages every identity system speaks.

# Track 03
Identity Standards
14 hands-on labs
# prepare → do → prove → explain
The labs

Work through Track 03

Each lab is standalone but builds on the last. Capture evidence as you go, and read the track FAQ for the concepts behind them.

03.01Lab
Hands-on

Lab 01 - OpenLDAP Enterprise Directory

Stand up an authoritative directory: schema, replication, ACLs.

03.02Lab
Hands-on

Lab 02 - Keycloak Realm and OIDC

Build a Keycloak realm, register clients, issue tokens with OIDC.

03.03Lab
Hands-on

Lab 03 - SAML Federation

Federate a service provider with a SAML IdP - metadata, signing, assertions.

03.04Lab
Hands-on

Lab 04 - OIDC with PKCE

Implement Authorization Code and PKCE - the modern SPA and mobile pattern.

03.05Lab
Hands-on

Lab 05 - MFA and Passwordless

WebAuthn, TOTP and step-up authentication end to end.

03.06Lab
Hands-on

Lab 06 - Keycloak High Availability

Cluster Keycloak, replicate caches, survive a node failure.

03.07Lab
Hands-on

Lab 07 - SCIM Provisioning Lifecycle

Automate joiner-mover-leaver across systems via SCIM 2.0.

03.08Lab
Hands-on

Lab 08 - Risk-Based Authentication

Score sign-in signals and act on the risk level.

03.09Lab
Hands-on

Lab 09 - JWT / JWS / JWE Deep Dive

Understand what is really inside a token - and what can go wrong.

03.10Lab
Hands-on

Lab 10 - OAuth 2.1 Hardening

DPoP, PAR, sender-constrained tokens and modern threat mitigations.

03.11Lab
Hands-on

Lab 11 - Token Exchange (RFC 8693)

Delegated and impersonated identity across service boundaries.

03.12Lab
Hands-on

Lab 12 - Session Management

Front-channel and back-channel logout, session revocation, refresh flows.

03.13Lab
Hands-on

Lab 13 - From RBAC to ABAC

Migrate role explosion to attribute-based decisions without a rewrite.

03.14Lab
Hands-on

Lab 14 - OPA and Rego

Externalise authorisation with Open Policy Agent, tested end to end.

Understand the theory first

New to Identity Standards? The knowledge-base article explains every concept in plain English before you touch a keyboard.