
LEARNING RESOURCES
Teleport Academy - Page 7
Teleport Academy is your resource for understanding modern infrastructure security. Browse tutorials, how-to guides, and explainers covering topics from SSH and Kubernetes access to zero trust, compliance, and AI infrastructure.
Topics
What is Identity Threat Detection and Response (ITDR)?
Identity Threat Detection & Response (ITDR) focuses on protecting organizational assets through the vigilant monitoring of identity-related events.
What is MAC (Mandatory Access Control)?
Mandatory Access Control (MAC) is a type of access control that imposes a predefined set of security rules, or labels, to control which users or systems can access specific resources.
What is OAuth 2.0 (Open Authorization)?
OAuth 2.0 (Open Authorization) is a standard for authorization where a user allows an application to access their resources hosted on another application, on their behalf, without the sharing of their credentials.
What is Observability?
Observability is a critical capability in modern software engineering, enabling teams to monitor, diagnose, and optimize complex systems across various architectures, including cloud-native, microservices, and serverless
What is OIDC (Open ID Connect)?
OIDC, or OpenID Connect, is an authentication layer built on top of the authorization protocol OAuth 2.0 and provides a standardized way for users to authenticate themselves to web applications.
What is PCI Compliance?
PCI compliance embodies the commitment of organizations to protect cardholder data by adhering to the Payment Card Industry Data Security Standard (PCI DSS).
What Is SAML (Security Assertion Markup Language)?
Security Assertion Markup Language (SAML) is an XML-based open standard for exchanging authentication and authorization data between parties, and in particular, between an identity provider (IdP) and a service provider (SP). The Identity Provider will verify the identity of the user, verifying they are who they say they are.
What is Secretless (Passwordless) Authentication?
Passwordless authentication verifies a user's identity without a shared password. Instead, authentication relies on something the user has in their physical possession, such as a registered device or hardware security key, and something that identifies who the user is, such as a fingerprint or face. Because there is no password stored on a server or typed into a login form, there is nothing for an attacker to phish, steal in a breach, or guess. Secretless authentication takes the same idea one step further. It eliminates every shared secret, not only passwords, using verifiable identity elements such as biometrics, digital certificates, and hardware tokens. This article explains what passwordless authentication is, how it works under the hood, the methods and their trade-offs, and whether it is genuinely more secure than passwords plus multi-factor authentication. It then extends the idea from app logins to infrastructure access, where standing credentials are the real risk.
What is SOC2 compliance?
The SOC 2 framework is published by the American Institute of Certified Public Accountants (AICPA) and is a voluntary cybersecurity attestation.
What is Time-Based One-Time Password & How it Works
This article provides a deep dive into TOTP (Time-based One-Time Password), a popular multi-factor authentication method. It explains the inner workings of TOTP, its benefits, use cases, and compares it to other authentication methods like SMS and biometric authentication.
What is U2F (Universal 2nd Factor)?
U2F (Universal 2nd Factor) is a universal authentication standard that provides an additional layer of security for online accounts.
What is WebAuthn?
WebAuthn is a web standard for secure, passwordless authentication allowing web servers to authenticate users with asymmetric cryptography instead of passwords.
What is zero trust security for applications and workloads?
Most ZTNA technologies, although adept at securing zero trust access to networks, do not embed the identity and protocol-level information necessary to apply zero trust principles for application access or workload access in modern computing infrastructure.
Workload Identity
What is workload identity? A clear guide to how workloads authenticate with cryptographic identity, SPIFFE and SPIRE, workload identity federation, and AI pipelines.
Zero Trust Architecture
What is zero trust architecture? A clear guide to the zero trust principles, the NIST SP 800-207 tenets, how it works, and how to implement it. Read on.