Background image

LEARNING RESOURCES

Teleport Academy - Page 7

Teleport Academy is your resource for understanding modern infrastructure security. Browse tutorials, how-to guides, and explainers covering topics from SSH and Kubernetes access to zero trust, compliance, and AI infrastructure.

Topics

What is Identity Threat Detection and Response (ITDR)?

Identity Threat Detection & Response (ITDR) focuses on protecting organizational assets through the vigilant monitoring of identity-related events.

Read article

What is MAC (Mandatory Access Control)?

Mandatory Access Control (MAC) is a type of access control that imposes a predefined set of security rules, or labels, to control which users or systems can access specific resources.

Read article

What is OAuth 2.0 (Open Authorization)?

OAuth 2.0 (Open Authorization) is a standard for authorization where a user allows an application to access their resources hosted on another application, on their behalf, without the sharing of their credentials.

Read article

What is Observability?

Observability is a critical capability in modern software engineering, enabling teams to monitor, diagnose, and optimize complex systems across various architectures, including cloud-native, microservices, and serverless

Read article

What is OIDC (Open ID Connect)?

OIDC, or OpenID Connect, is an authentication layer built on top of the authorization protocol OAuth 2.0 and provides a standardized way for users to authenticate themselves to web applications.

Read article

What is PCI Compliance?

PCI compliance embodies the commitment of organizations to protect cardholder data by adhering to the Payment Card Industry Data Security Standard (PCI DSS).

Read article

What Is SAML (Security Assertion Markup Language)?

Security Assertion Markup Language (SAML) is an XML-based open standard for exchanging authentication and authorization data between parties, and in particular, between an identity provider (IdP) and a service provider (SP). The Identity Provider will verify the identity of the user, verifying they are who they say they are.

Read article

What is Secretless (Passwordless) Authentication?

Passwordless authentication verifies a user's identity without a shared password. Instead, authentication relies on something the user has in their physical possession, such as a registered device or hardware security key, and something that identifies who the user is, such as a fingerprint or face. Because there is no password stored on a server or typed into a login form, there is nothing for an attacker to phish, steal in a breach, or guess. Secretless authentication takes the same idea one step further. It eliminates every shared secret, not only passwords, using verifiable identity elements such as biometrics, digital certificates, and hardware tokens. This article explains what passwordless authentication is, how it works under the hood, the methods and their trade-offs, and whether it is genuinely more secure than passwords plus multi-factor authentication. It then extends the idea from app logins to infrastructure access, where standing credentials are the real risk.

Read article

What is SOC2 compliance?

The SOC 2 framework is published by the American Institute of Certified Public Accountants (AICPA) and is a voluntary cybersecurity attestation.

Read article

What is Time-Based One-Time Password & How it Works

This article provides a deep dive into TOTP (Time-based One-Time Password), a popular multi-factor authentication method. It explains the inner workings of TOTP, its benefits, use cases, and compares it to other authentication methods like SMS and biometric authentication.

Read article

What is U2F (Universal 2nd Factor)?

U2F (Universal 2nd Factor) is a universal authentication standard that provides an additional layer of security for online accounts.

Read article

What is WebAuthn?

WebAuthn is a web standard for secure, passwordless authentication allowing web servers to authenticate users with asymmetric cryptography instead of passwords.

Read article

What is zero trust security for applications and workloads?

Most ZTNA technologies, although adept at securing zero trust access to networks, do not embed the identity and protocol-level information necessary to apply zero trust principles for application access or workload access in modern computing infrastructure.

Read article

Workload Identity

What is workload identity? A clear guide to how workloads authenticate with cryptographic identity, SPIFFE and SPIRE, workload identity federation, and AI pipelines.

Read article

Zero Trust Architecture

What is zero trust architecture? A clear guide to the zero trust principles, the NIST SP 800-207 tenets, how it works, and how to implement it. Read on.

Read article