Sign up to one of our scheduled trainings or book your own custom delivery.
Goals
This workshop is your chance to dive into all these security-related technologies. Learn how to securely connect native and browser-based applications to your back-ends and integrate them with enterprise identity management systems as well as social identity providers and services.
After attending this workshop you will have a good understanding of the concepts and will be ready to start implementing a modern identity and access management solution tailored to your organization’s needs.
You will learn:
- The ASP.NET Core Authentication and Authorization System Design Principles.
- How to use external authentication and offer single sign-on and single logout.
- How to securely call APIs on behalf of the authenticated user.
- The principles of the OpenID Connect and OAuth 2.0 Protocols.
- What advanced concepts are available for high security environments, multi-tenancy SAAS offerings, etc.
- How to configure, customize, and deploy Duende IdentityServer.
Two or Three Days of Lectures, Demos and Labs
The full workshop is three days long, so that we can cover all the topics in depth. We also offer the first two days at select conferences (where the workshops are only two days).
Each workshop block starts with lectures explaining the concepts, mixed with extensive live demos and live coding that show how to set up working solutions. At the end of each block, detailed step-by-step labs offer an excellent chance to try it out yourself.
Technologies covered
.NET, ASP.NET Core, MVC, Web APIs, Claims, Authentication, Authorization, OpenID Connect, OAuth 2.0, JSON Web Tokens, Single Sign-on and off, Federation, Home Realm Discovery, Single Page Applications (SPA), Backend for Frontend Pattern (BFF), Mobile/Native Client Applications, Machine-to-Machine API calls, Token Lifetimes and Management, API/Resource Design, Resource Isolation, Token Exchange, Impersonation, Delegation, mTLS, DPOP, Pushed Authorization Requests (PAR), CIBA Device Code Flow.
1 Authentication
- Asp.Net Core Fundamentals
- Claims
- Authentication
- Cookie-Based Sessions
- Data Protection
- Authorization
- Tokens
- External Authentication in Asp.Net Core
- Identities and Identifiers
- Account and Identity Linking
- External Login Callback Pattern
2 OIDC & OAuth 2.0
- OpenID Connect
- Clients
- Scopes
- Web Application Patterns
- Single Sign On / Single Sign Off
- Federation Gateway
- Home Realm Discovery
- Protecting APIs with OAuth 2.0
- Machine-to-Machine
- Interactive Applications
- Authorization Code Flow
- Proof Key Code Exchange
- Token Lifetime Management & Refresh Tokens
- Client Application Types
- Server-Side Web Apps
- Single Page Applications
- Backend-for-Frontend (BFF) Pattern
- Mobile/Native Apps
3 Advanced
- Advanced OAuth 2.0
- Resource Design
- Parameterized Scopes
- Resource Isolation
- Token Exchange Impersonation/Delegation
- High-security Overview: DPoP, mTLS, PAR and FAPI
- Client Initiated Back Channel Authentication (CIBA)
- Device Code Flow
- Pushed Authorization Requests
- Duende IdentityServer
- Architecture
- UI Customizations
- Extensibility
- Deployment
- Multi Tenancy
Sign up to one of our scheduled trainings or book your own custom delivery.