Lab
Do for real what the lessons explain. Each lab guides you through a short task on Beyond the Login, and the server checks the result.
You can read every lab. Completing one requires a Beyond the Login account, because the server decides from what actually happened to your account, never from a box you tick. Some labs will use your test tenant, the tenant created for your account, so you can review their events in its Audit and Logs.
Sign in to track your progress. Log in or create an account.
IN PROGRESS
Identity fundamentals
Create an account, prove control of it, and follow requests, sessions, trust and delegated access.
LessonEstablishing an identity
- L1Prove an email is yoursAvailable
LessonProving control of an account
- L2Come back to your accountAvailable
LessonHow applications communicate
- L5Send a request by handPlanned
LessonStaying signed in
- L6Anatomy of your sessionPlanned
LessonDeciding what someone can do
- L7Grant one thing, deny anotherPlanned
LessonTrust across systems
- L8Sign in somewhere elsePlanned
LessonProtecting credentials and messages
- L9Reading is not validatingPlanned
Identity and trust
Check identity evidence, prove possession of keys, and read and validate certificates.
LessonWhat a certificate says
- L4Read a real certificateGuided exercise
LessonWhat proofing establishes
- L11Check the evidencePlannedSimulation
LessonProofing methods
- L12Pick a proofing routePlannedSimulation
LessonSecrets and key pairs
- L13Prove you hold a keyPlanned
LessonDigital signatures
- L14Sign it, then break itPlanned
LessonStoring and using keys
- L15Rotate a signing keyPlanned
LessonValidating a certificate
- L16Watch validation failPlanned
Authentication methods and MFA
Recover a password, add stronger methods, and see authentication policy take effect.
LessonPasswords and PINs
- L3Recover a forgotten passwordAvailable
LessonCodes, links, and approval prompts
- L18Sign in with a code or a linkPlanned
LessonSecurity keys, passkeys, and biometrics
- L19Go passwordlessPlanned
LessonMethods, credentials, and factors
- L20Add a second factorPlanned
LessonAuthentication policy and SSO
- L22Make the policy bitePlanned
OAuth 2.0
Run the authorization code flow yourself, then break its protections on purpose.
LessonFollowing the complete exchange
- L23Run the code flow by handPlanned
LessonGrants, scopes, and consent
- L24Consent, then say noPlanned
LessonPublic and confidential clients
- L25Two kinds of clientPlanned
LessonProof Key for Code Exchange (PKCE)
- L26Break PKCE on purposePlanned
LessonCorrelating requests and responses
- L27Catch a forged responsePlanned
LessonErrors and denied access
- L28Read the error, not just the screenPlanned
LessonClient credentials
- L29Get a token as the clientPlanned
LessonThe refresh token grant
- L30Refresh, then replayPlanned
LessonDevice authorization
- L31Approve a device from your phonePlanned
LessonClient authentication methods
- L32One method per clientPlanned
LessonSecrets and signed assertions
- L33Sign a client assertionPlanned
LessonRotating client credentials
- L34Rotate a client secretPlanned
COMPLETED