> For the complete documentation index, see [llms.txt](https://academy.pentaho.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://academy.pentaho.com/administrator-path-sandbox/administrator/level-3-professional.md).

# Level 3 — Professional

The rest of Pentaho's security surface. 20 lessons across 4 modules, ending in a peer-reviewed capstone and a proctored certification exam — SSO, transport/data security, big data security, and awaren

{% hint style="warning" %}
**🧪 SANDBOX — draft content, no hands-on lab content yet.** Sourced from docs.pentaho.com's "Secure the Pentaho system" section, plus Jp's existing SA\_1000 security course (reconciled — see note below). Lesson times are estimates — REPLACE-ME throughout.
{% endhint %}

{% hint style="info" icon="circle-info" %}
**Reconciliation note:** Jp's existing SA\_1000 course turned out to be Solution Architect-level material — hands-on labs writing custom Spring Security extensions (custom `AuthenticationProvider`, `UserDetailsService`, `DelegatingRole`, `SQLGenerator`, Access Voter classes) for multi-tenant architectures, not admin configuration. Rather than teach the coding here, Module 4 below gives Administrators conceptual awareness of these patterns — what they're for and when you'd need a developer to build one. The hands-on labs are earmarked to become Solution Architect content once that path is built.
{% endhint %}

Where Level 2 covers Pentaho's two out-of-the-box directory integrations, Level 3 is the rest of the security surface — single sign-on, transport security, encryption, securing Pentaho's own access into other systems, and recognizing when a security requirement needs custom development rather than configuration.

{% columns %}
{% column %}

<p align="center"><i class="fa-file-lines" style="color:green;">:file-lines:</i><br><strong>20 lessons</strong><br><em>across 4 modules</em></p>
{% endcolumn %}

{% column %}

<p align="center"><i class="fa-flask" style="color:orange;">:flask:</i><br><strong>10 workshops</strong><br><em>hands-on labs</em></p>
{% endcolumn %}

{% column %}

<p align="center"><i class="fa-clock" style="color:cyan;">:clock:</i><br><strong>~4h 45m</strong><br><em>REPLACE-ME — estimated</em></p>
{% endcolumn %}
{% endcolumns %}

{% hint style="success" icon="cloud-arrow-up" %}
Every workshop is hands-on and runs on Pentaho's hosting platform. The Lab Guide is embedded in each lab and loads automatically when you open it — nothing to install.
{% endhint %}

***

<h3 align="center">Before you start</h3>

{% columns %}
{% column %}
{% hint style="success" icon="circle-check" %}
**What you'll need**

Level 2 course completion, or equivalent experience with directory-based authentication. This level assumes you're comfortable editing Pentaho's Spring Security configuration files directly.
{% endhint %}
{% endcolumn %}

{% column %}
{% hint style="info" icon="tag" %}
**Built against**

REPLACE-ME — confirm target Pentaho version for this level (other paths are built against 11.0.0.3-310).
{% endhint %}
{% endcolumn %}
{% endcolumns %}

***

{% hint style="info" icon="trophy" %}

#### What you'll build

The level ends in a capstone project: harden a Pentaho Server for enterprise deployment — SSO authentication, encrypted credentials and transport, and secure access to a Hadoop cluster — submitted for peer review as part of the proctored Level 3 certification exam.
{% endhint %}

***

<h3 align="center">What you'll learn</h3>

{% columns %}
{% column %}

* Integrate Pentaho with SSO frameworks: CAS, OIDC/OAuth 2.0, and Kerberos-based IWA for silent domain login
* Secure transport and stored credentials with SSL, AES encryption, JDBC-backed security and SSRF prevention
  {% endcolumn %}

{% column %}

* Secure Pentaho's own access into a Hadoop cluster with Kerberos, secure impersonation and Knox
* Recognize enterprise security patterns — pre-authenticated gateways, custom providers, multi-tenant isolation — that require custom development rather than configuration
  {% endcolumn %}
  {% endcolumns %}

***

<h3 align="center">Course Outline</h3>

<p align="center"><i class="fa-file-lines" style="color:green;">:file-lines:</i> reading · <i class="fa-flask" style="color:orange;">:flask:</i> hands-on workshop</p>

{% hint style="info" icon="circle-info" %}
Full lessons unlock once you're enrolled — this is the outline only. All times are estimates — REPLACE-ME.
{% endhint %}

<table><thead><tr><th width="306">Module</th><th width="114" align="center">Reading</th><th width="139" align="center">Workshops</th><th width="100" align="right">Time</th><th>Videos</th></tr></thead><tbody><tr><td>Single Sign-On</td><td align="center">1</td><td align="center">3</td><td align="right">~1h 10m</td><td></td></tr><tr><td>Transport &#x26; Data Security</td><td align="center">2</td><td align="center">4</td><td align="right">~1h 20m</td><td></td></tr><tr><td>Big Data Security</td><td align="center">2</td><td align="center">3</td><td align="right">~1h 25m</td><td></td></tr><tr><td>Enterprise Security Patterns (Awareness)</td><td align="center">5</td><td align="center">—</td><td align="right">~50m</td><td></td></tr><tr><td>Capstone Project</td><td align="center">—</td><td align="center">1 project</td><td align="right">—</td><td></td></tr><tr><td><strong>Total</strong></td><td align="center"><strong>10</strong></td><td align="center"><strong>10</strong></td><td align="right"><strong>~4h 45m</strong></td><td></td></tr></tbody></table>

{% stepper %}
{% step %}

### <i class="fa-right-to-bracket" style="color:blue;">:right-to-bracket:</i> Single Sign-On

`1 reading · 3 workshops · ~1h 10m`

Integrate Pentaho with the SSO framework your organization already runs — or Kerberos-based silent login for domain-joined users.

<details>

<summary>See the full breakdown</summary>

<table><thead><tr><th width="78"></th><th>Lesson</th><th width="90">Time</th></tr></thead><tbody><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Overview</td><td>~10m</td></tr><tr><td></td><td></td><td></td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Configure CAS (Central Authentication Service)</td><td>~20m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Configure OIDC / OAuth 2.0 — also the path for Keycloak, Okta and similar IdPs</td><td>~20m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Configure IWA (Integrated Windows Authentication) — Kerberos/SPNEGO silent login</td><td>~20m</td></tr></tbody></table>

</details>
{% endstep %}

{% step %}

### <i class="fa-lock" style="color:blue;">:lock:</i> Transport & Data Security

`2 reading · 4 workshops · ~1h 20m`

Certificates, encrypted credentials, database-backed security, and hardening against SSRF-class attacks.

<details>

<summary>See the full breakdown</summary>

<table><thead><tr><th width="78"></th><th>Lesson</th><th width="90">Time</th></tr></thead><tbody><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Overview</td><td>~10m</td></tr><tr><td></td><td></td><td></td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Enable SSL Security</td><td>~20m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>AES Security — Encrypting Stored Credentials</td><td>~15m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>JDBC Security — Database-Backed Authentication</td><td>~15m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Server-Side Request Forgery (SSRF) Prevention</td><td>~10m</td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>How Pentaho Chains Authentication Providers (Spring Security)</td><td>~10m</td></tr></tbody></table>

</details>
{% endstep %}

{% step %}

### <i class="fa-database" style="color:blue;">:database:</i> Big Data Security

`2 reading · 3 workshops · ~1h 25m`

Secure Pentaho's own access into a Hadoop cluster on a user's behalf.

<details>

<summary>See the full breakdown</summary>

<table><thead><tr><th width="78"></th><th>Lesson</th><th width="90">Time</th></tr></thead><tbody><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Overview</td><td>~10m</td></tr><tr><td></td><td></td><td></td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Kerberos Authentication vs. Secure Impersonation — two models compared</td><td>~10m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Set Up Kerberos for Pentaho — prerequisites and supported components</td><td>~25m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Kerberos with MongoDB &#x26; Spark Submit</td><td>~20m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Knox &#x26; CDP Security — accessing Cloudera Data Platform clusters</td><td>~20m</td></tr></tbody></table>

</details>
{% endstep %}

{% step %}

### <i class="fa-eye" style="color:blue;">:eye:</i> Enterprise Security Patterns (Awareness)

`5 reading · ~50m`

Conceptual only — no hands-on labs. Implementing any of these requires custom development, typically Solution Architect-level work. As an Administrator, the goal is to recognize the pattern and know when to bring in that expertise.

<details>

<summary>See the full breakdown</summary>

<table><thead><tr><th width="78"></th><th>Lesson</th><th width="90">Time</th></tr></thead><tbody><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Overview</td><td>~10m</td></tr><tr><td></td><td></td><td></td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Pre-Authenticated SSO Gateways — SiteMinder, WebGate, WebSeal-style header trust</td><td>~10m</td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Custom Authentication &#x26; Role Providers</td><td>~10m</td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Multi-Tenant Data Isolation Patterns — sharded sources, DSP, metadata security, SQL generators</td><td>~10m</td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Custom Role Delegation &#x26; Access Voters</td><td>~10m</td></tr></tbody></table>

</details>

{% hint style="warning" icon="circle-question" %}
**REPLACE-ME** — confirm this module's framing (awareness-only, no code) is right for Level 3 — Professional, and revisit once the Solution Architect path exists to cross-link "go deeper here" for learners who want the hands-on version.
{% endhint %}
{% endstep %}

{% step %}

### <i class="fa-trophy" style="color:red;">:trophy:</i> Capstone Project

`1 project · peer reviewed`

Bring it all together: harden a Pentaho Server to enterprise standard — SSO, encrypted credentials and transport, and secure big data access — as part of the proctored Level 3 certification exam.

<details>

<summary>See the project brief</summary>

Your client is preparing for a security audit ahead of a major compliance certification. Configure enterprise SSO for platform login, encrypt stored credentials and enforce SSL across the server, and secure the platform's access into their Hadoop cluster with Kerberos or secure impersonation. Document which of the awareness-level patterns from Module 4 apply to their environment and would need custom development to implement. Your submission is peer reviewed by the Pentaho team as part of the proctored certification exam.

</details>
{% endstep %}
{% endstepper %}

***

{% hint style="warning" icon="award" %}
**Certification**

Unlike Levels 1 and 2, Level 3 doesn't offer a self-paced course-completion exam — it leads directly to **Certification**, a separate, proctored credential that organisations look for when engaging Pentaho consultants. The Speciality course and this level's capstone (peer reviewed by the Pentaho team) feed into it, and the exam itself is proctored.
{% endhint %}

***

<p align="center"><a href="/administrator-path-sandbox/administrator.md" class="button secondary" data-icon="arrow-left">Back to Administrator path</a></p>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://academy.pentaho.com/administrator-path-sandbox/administrator/level-3-professional.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
