> For the complete documentation index, see [llms.txt](https://academy.pentaho.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://academy.pentaho.com/administrator-path-sandbox/administrator.md).

# Administrator

{% hint style="warning" %}
**🧪 SANDBOX — draft learning path page**

For review only. **Level 1**, **Level 2**, **Level 3** and the **Speciality course** are all built as lesson-based curricula with estimated times (REPLACE-ME throughout).
{% endhint %}

<p align="center"><i class="fa-shield-halved">:shield-halved:</i></p>

<h2 align="center">Pentaho Administrator</h2>

<p align="center">Install, harden, configure and maintain the Pentaho Suite — from a secured Tomcat deployment to managing users, connections and the repository in production.</p>

{% columns %}
{% column %}

<p align="center"><i class="fa-layer-group" style="color:blue;">:layer-group:</i><br><strong>3 levels</strong><br><em>plus Speciality</em></p>
{% endcolumn %}

{% column %}

<p align="center"><i class="fa-list-check" style="color:green;">:list-check:</i><br><strong>39 lessons</strong><br><em>across 5 modules at Level 1</em></p>
{% endcolumn %}

{% column %}

<p align="center"><i class="fa-cloud" style="color:cyan;">:cloud:</i><br><strong>Hosted labs</strong><br><em>nothing to install</em></p>
{% endcolumn %}
{% endcolumns %}

{% hint style="success" icon="cloud-arrow-up" %}
**The labs come with the course.**

Every workshop runs on Pentaho's hosting platform. When you purchase, you're sent a URL and a voucher code — that's your access. Each lab has its Lab Guide embedded, and it starts automatically when you open the lab. Nothing to download, install or configure.
{% endhint %}

{% hint style="warning" icon="circle-question" %}
**REPLACE-ME** — Level 1 is adapted from the "Administration of Pentaho Suite" lab guide plus the "Support & Troubleshooting" course. Levels 2–3 and the Speciality course are adapted from docs.pentaho.com's security documentation, the troubleshooting course, and (for Level 3's awareness module) Jp's existing SA\_1000 security course. Confirm target Pentaho version and review all estimated lesson times before this goes live.
{% endhint %}

***

<h3 align="center">Choose your level</h3>

<p align="center">Everything about a level — outline, task count and skills — in one place. Level 1 shown by default.</p>

{% tabs %}
{% tab title="🌱 Level 1 — Practitioner" %}
No prior Pentaho experience needed. Five modules take you from a fresh install to a hardened, production-ready, supportable server with users, connections and the repository configured, ending in a capstone project.

<p align="center"><strong>39 lessons · 5 modules · ~8h 30m</strong></p>

<p align="center"><a class="button primary" data-icon="arrow-right">See the full Level 1 outline</a></p>

**Skills you'll gain**

<table data-view="cards"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><i class="fa-server" style="color:blue;">:server:</i> <strong>Tomcat hardening</strong></td><td>Context path &#x26; port changes · removing the server banner · SSL/TLS · enforcing HTTPS · secure cookies · changing the SHUTDOWN port · memory limits · removing default apps</td></tr><tr><td><i class="fa-sliders" style="color:blue;">:sliders:</i> <strong>Server configuration</strong></td><td>Disabling the evaluator login hint · login autocomplete · Home perspective widgets · removing sample &#x26; Geo data · log file rotation with log4j2</td></tr><tr><td><i class="fa-database" style="color:blue;">:database:</i> <strong>Repository management</strong></td><td>Users &#x26; roles · upload/download content · authentication method · mail server · licenses · data sources</td></tr><tr><td><i class="fa-diagram-project" style="color:blue;">:diagram-project:</i> <strong>PDI/Spoon administration</strong></td><td>JDBC drivers · database connections · repository connection · kettle.properties · PDI logging · purging · version control</td></tr><tr><td><i class="fa-life-ring" style="color:blue;">:life-ring:</i> <strong>Support &#x26; upgrades</strong></td><td>Support Portal &#x26; tickets · the logging framework · Operations Mart · planning and running a server upgrade</td></tr></tbody></table>
{% endtab %}

{% tab title="🍂 Level 2 — Associate" %}
Builds on Level 1 with directory-based authentication. Four modules connect your server to LDAP or Active Directory, harden the security fundamentals around it, and teach you to diagnose login failures from the logs — ending in a capstone project.

<p align="center"><strong>16 lessons · 4 modules · ~3h 20m</strong></p>

<p align="center"><a class="button primary" data-icon="arrow-right">See the full Level 2 outline</a></p>

**Skills you'll gain**

<table data-view="cards"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><i class="fa-lock" style="color:blue;">:lock:</i> <strong>Security fundamentals</strong></td><td>ACLs on files and folders · credentials in URL parameters · disabling security · hiding user folders</td></tr><tr><td><i class="fa-diagram-project" style="color:blue;">:diagram-project:</i> <strong>LDAP integration</strong></td><td>Connection settings, bind credentials, testing the connection, user &#x26; role mapping</td></tr><tr><td><i class="fa-windows" style="color:blue;">:windows:</i> <strong>Active Directory integration</strong></td><td>AD-specific connection quirks, mapping users, security groups and OUs to roles</td></tr><tr><td><i class="fa-magnifying-glass" style="color:blue;">:magnifying-glass:</i> <strong>Troubleshooting logins</strong></td><td>Spring Security debug logging · reading "bad credentials" vs. "user not found" · confirming successful logins</td></tr></tbody></table>
{% endtab %}

{% tab title="🌳 Level 3 — Professional" %}
The rest of Pentaho's security surface. Four modules cover SSO, transport/data security, big data security, and awareness of enterprise patterns that need custom development — ending in a peer-reviewed capstone as part of the proctored certification exam.

<p align="center"><strong>20 lessons · 4 modules · ~4h 45m</strong></p>

<p align="center"><a class="button primary" data-icon="arrow-right">See the full Level 3 outline</a></p>

**Skills you'll gain**

<table data-view="cards"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><i class="fa-right-to-bracket" style="color:blue;">:right-to-bracket:</i> <strong>Single sign-on</strong></td><td>CAS · OIDC/OAuth 2.0 (also covers Keycloak, Okta) · Kerberos-based IWA for silent domain login</td></tr><tr><td><i class="fa-lock" style="color:blue;">:lock:</i> <strong>Transport &#x26; data security</strong></td><td>SSL · AES-encrypted credentials · JDBC-backed security · SSRF prevention · how Spring Security chains providers</td></tr><tr><td><i class="fa-database" style="color:blue;">:database:</i> <strong>Big data security</strong></td><td>Kerberos vs. secure impersonation · Kerberos with MongoDB &#x26; Spark · Knox &#x26; CDP access</td></tr><tr><td><i class="fa-eye" style="color:blue;">:eye:</i> <strong>Enterprise security awareness</strong></td><td>Pre-authenticated gateways · custom auth providers · multi-tenant isolation · custom access voters — recognizing when to bring in a developer</td></tr></tbody></table>
{% endtab %}
{% endtabs %}

***

<h3 align="center">Speciality course</h3>

<p align="center">The advanced tier, for experienced administrators who want to push beyond standard operations.</p>

{% columns %}
{% column %}
{% hint style="success" icon="cube" %}
**Stands alone**

Take the speciality on its own. You don't need to work through the levels first — just the hands-on experience to keep up.
{% endhint %}
{% endcolumn %}

{% column %}
{% hint style="info" icon="award" %}
**Counts towards Level 3**

This speciality forms part of the **Level 3 — Professional** certification, since it covers the same authentication ground in more depth.
{% endhint %}
{% endcolumn %}
{% endcolumns %}

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-key" style="color:blue;">:key:</i> <strong>Integrating Authentication Mechanisms</strong></td><td>SAML, OIDC/Keycloak and Kerberos/IWA in 12 lessons across 3 modules (~2h 50m), ending in a capstone — the enterprise authentication mechanisms beyond Level 2's LDAP and Active Directory</td><td><em>12 lessons · 3 modules</em></td><td></td></tr></tbody></table>

{% hint style="warning" icon="circle-question" %}
**REPLACE-ME** — confirm whether a second or third Speciality course is planned for this path, or whether Integrating Authentication Mechanisms stands alone.
{% endhint %}

***

<h3 align="center">Is this path for you?</h3>

{% columns %}
{% column %}
{% hint style="success" icon="circle-check" %}
**Yes — if you**

* Install, configure or upgrade the Pentaho Server
* Harden a Tomcat/Pentaho deployment for production
* Manage users, roles and the repository
* Keep the platform running so ETL specialists and business analysts can create, publish and share content
  {% endhint %}
  {% endcolumn %}

{% column %}
{% hint style="info" icon="signs-post" %}
**Try another path if you**

* Build and run pipelines day-to-day — **PDI Developer**
* Design the wider architecture rather than operate the platform — **Solution Architect**
* Consume the output in reports and dashboards — **Business Analyst**
  {% endhint %}
  {% endcolumn %}
  {% endcolumns %}

{% hint style="info" icon="circle-info" %}
**Two administrator roles, one path**

The course distinguishes **IT Administrators** (install, configure and upgrade the server; know where data is stored and how to use the command line) from **Pentaho Administrators** (manage users, roles and workstations so ETL specialists and business analysts can work). Level 1 covers tasks for both.
{% endhint %}

***

<h3 align="center">How to get access</h3>

{% stepper %}
{% step %}
**Read the course outlines**

Open the level or speciality you're considering and check the modules cover the work you actually do.
{% endstep %}

{% step %}
**Talk to your Account Executive**

Courses and subscriptions are purchased through your AE — a single seat or the whole team. They'll size it with you and get the order placed.
{% endstep %}

{% step %}
**Receive your URL and voucher code**

You'll be sent a URL to our hosting platform and a voucher code giving access to the course or courses you bought.
{% endstep %}

{% step %}
**Open a lab and start**

Redeem your voucher and open the first lab. The Lab Guide is embedded and starts automatically — work through it at your own pace.
{% endstep %}
{% endstepper %}

***

### At a glance

<table><thead><tr><th width="200"></th><th></th></tr></thead><tbody><tr><td><i class="fa-layer-group" style="color:blue;">:layer-group:</i> <strong>Levels</strong></td><td>3 — Practitioner, Associate and Professional, plus the Integrating Authentication Mechanisms speciality</td></tr><tr><td><i class="fa-chalkboard-user">:chalkboard-user:</i> <strong>Format</strong></td><td>A mix of hands-on workshops and short reading pages, self-paced, ending each level with a capstone project</td></tr><tr><td><i class="fa-cloud" style="color:cyan;">:cloud:</i> <strong>Delivery</strong></td><td>On Pentaho's hosting platform — Lab Guide embedded in every lab</td></tr><tr><td><i class="fa-door-open">:door-open:</i> <strong>Entry requirements</strong></td><td>No prior Pentaho experience for Level 1. Comfort with the command line and basic networking (ports, certificates) helps.</td></tr><tr><td><i class="fa-tag" style="color:$primary;">:tag:</i> <strong>Built against</strong></td><td>REPLACE-ME — confirm target version for this path (other paths are built against 11.0.0.3-310)</td></tr><tr><td><i class="fa-globe" style="color:purple;">:globe:</i> <strong>Language</strong></td><td>English</td></tr><tr><td><i class="fa-award" style="color:orange;">:award:</i> <strong>Certification</strong></td><td>Level 1 &#x26; 2 — course completion. Level 3 — proctored Certification with a peer-reviewed capstone</td></tr><tr><td><i class="fa-clock-rotate-left" style="color:cyan;">:clock-rotate-left:</i> <strong>Last updated</strong></td><td>REPLACE-ME</td></tr></tbody></table>

***

### Common questions

<details>

<summary>Do I need my own Pentaho environment?</summary>

No. The labs are hosted for you — your voucher gives you access to a ready-made environment on our hosting platform, with the Lab Guide embedded in each lab. There's nothing to download, install or configure.

</details>

<details>

<summary>Do I need to start at Level 1?</summary>

Level 1 assumes no prior Pentaho experience, so it's the right entry point for most people. If you already administer Pentaho servers daily, talk to your AE about starting higher.

</details>

<details>

<summary>Is this path for IT Administrators or Pentaho Administrators?</summary>

Both. Level 1 covers server installation and hardening tasks (typically IT Administrator work) alongside users, roles and repository management (typically Pentaho Administrator work), since many teams have one person doing both.

</details>

<details>

<summary>Can my whole team take this path?</summary>

Yes. Your Account Executive can size the order for the team and have vouchers issued for each learner.

</details>

<details>

<summary>How long do I have access to the labs?</summary>

REPLACE-ME — confirm the access period a voucher grants, and what happens when it ends.

</details>

<details>

<summary>Do I buy the whole path, or one course at a time?</summary>

REPLACE-ME — confirm whether levels and specialities are sold individually, as a bundle, or under a subscription.

</details>

<details>

<summary>Can I see a lab before I buy?</summary>

REPLACE-ME — confirm whether a sample lab is available as a preview.

</details>

***

<h3 align="center">Still have questions?</h3>

{% columns %}
{% column %}
{% hint style="info" icon="gitbook-assistant" %}
**Quick answers about the content**

Which tools a module covers, whether a system is included, how the levels differ. Press <kbd>Ctrl</kbd> + <kbd>K</kbd> and click **Ask** for an instant answer from these pages.

<button type="button" class="button primary" data-action="ask" data-icon="gitbook-assistant">Ask about this path...</button>
{% endhint %}
{% endcolumn %}

{% column %}
{% hint style="info" icon="envelope" %}
**Talk to the Academy team**

For anything the assistant can't answer — pricing, licensing, access periods, or sizing a programme for your team — email us at <academy@pentaho.com>.

We read every message and reply as soon as we can. If it's easier to talk it through, we'll set up a call from there.
{% endhint %}
{% endcolumn %}
{% endcolumns %}

***

<p align="center"><a href="https://academy.pentaho.com/academy-landing-v2-sandbox/" class="button secondary" data-icon="arrow-left">Back to all learning paths</a></p>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://academy.pentaho.com/administrator-path-sandbox/administrator.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
