For Kerberos, here:
I founds this YouTube very informative as to how [all these things hang together](https://youtu.be/cUQcNi_obIc?si=HtZ9iLc76KF2iB2L). [This is perhaps relevant for passkeys](https://fedoramagazine.org/fido2-for-centrally-managed-users...)
Alternatively you can go down the OIDC or SAML paths (generally the path of a developer)
While I've worked with keycloak I've always found the [Curity's resources](https://curity.io/resources/openid-connect/) for understanding OIDC core and extensions very good.
The order in which you learn these things isn't really important but they're both important (but really depends on your problem domain)