Beginner · Lessons: 4
Identity and access management
Who are you, and what may you do? Authentication and authorization, the access control models behind them, MFA and passkeys, and the zero trust approach that checks every request.
- 1 Authentication vs authorization: who you are, and what you may do
Two words that sound alike and fail in different ways. Learn what each one answers, where each one breaks, and how systems implement them properly.
8 min - 2 Access control models: RBAC, DAC and MAC
Three classic ways to decide who may touch what: by role, by owner, or by label. Learn how each works, where you meet it every day, and which risks it leaves open.
8 min - 3 Proving it’s really you: MFA, passkeys, biometrics and single sign-on
Passwords alone are the weakest link. Learn how multifactor authentication, passkeys, fingerprints and single sign-on make logins stronger, and which options actually resist phishing.
9 min - 4 Zero trust: never trust, always verify
The old model trusted everything inside the network. Zero trust checks every request, every time. Learn the principles behind NIST SP 800-207 and what they look like on a single Mac.
9 min
Free, no account, nothing tracked. Your progress stays in this browser.