• Home
  • Contact Cloud Identity Architect
  • Privacy Policy for AdverSite Web Holdings, Inc.

Cloud Identity Architect

Identity Solutions for the Public and Hybrid Cloud

  • Active Directory (On Premises)
  • API Authentication
  • Azure AD
  • Browser Security
  • Entra ID
  • Graph API
  • JWT
  • MFA
  • OAuth 2.0
  • Office 365
  • SAML
  • SCIM
  • Securing Identity
  • SSO
  • Transport Layer
  • Troubleshooting – network and identity
  • Uncategorized

Security concerns around SSO and Account Opening Flows

anuj August 29, 2025 Security concerns around SSO and Account Opening Flows2025-08-29T18:57:18+00:00 SAML No Comment
SAML Security Concerns: A → B → back to A SAML Security Concerns Threat Model User starts at Web App A → triggers SAML SSO to Web App B (SP)…
Continue Reading

OAuth for Individual Users vs. Service Accounts — Q&A

anuj August 21, 2025 OAuth for Individual Users vs. Service Accounts — Q&A2025-08-21T18:52:05+00:00 OAuth 2.0 No Comment
OAuth vs. Service Accounts — Q&A Q. Is OAuth used for individual users or service accounts? A. OAuth is primarily used for individual users to authenticate and grant delegated access…
Continue Reading

SSO with MFA – SaaS Service

anuj July 24, 2025 SSO with MFA – SaaS Service2025-07-24T20:45:13+00:00 SSO
SSO with MFA  - for SaaS Services Q1: If a SaaS service supports SSO, does that automatically mean it supports MFA? Answer: No, it does not automatically mean MFA is…
Continue Reading

Isolating Browser Sessions – In the Cloud and Locally

anuj July 17, 2025 Isolating Browser Sessions – In the Cloud and Locally2025-07-17T18:47:25+00:00 Browser Security
  Browser Isolation Options for Whitelisted Site Access To isolate browsers so they only allow access to whitelisted sites, organizations can choose from several architectural options. Below are three major…
Continue Reading

SAML-Based SSO: Source IP for IdP and SP Initiated Flows

anuj July 11, 2025 SAML-Based SSO: Source IP for IdP and SP Initiated Flows2025-07-11T04:57:42+00:00 SAML
SAML-Based SSO: Source IP for IdP and SP Initiated Flows SP-Initiated SSO Flow Summary: The user starts at the Service Provider (SP), which redirects them to the Identity Provider (IdP)…
Continue Reading

Capturing a Second Factor Before Full Trust

anuj May 21, 2025 Capturing a Second Factor Before Full Trust2025-05-21T00:33:59+00:00 Entra ID
Capturing a Second Factor Before Full Trust: A Smarter Onboarding Flow In most traditional account creation flows, users are granted full access right after setting up a username and password.…
Continue Reading

Enforcing a Second Factor in Entra ID: How to Secure Users Who Never Had One

anuj May 21, 2025 Enforcing a Second Factor in Entra ID: How to Secure Users Who Never Had One2025-05-21T00:11:32+00:00 Azure AD
Enforcing a Second Factor in Entra ID: How to Secure Users Who Never Had One If a user isn’t using a second factor, they’re a risk. Many organizations still have…
Continue Reading

Inbound versus Outbound SSO

anuj May 9, 2025 Inbound versus Outbound SSO2025-05-09T15:25:05+00:00 SSO
🔐 Inbound SSO (Single Sign-On) Definition:Inbound SSO means users from an external identity provider (IdP) can sign into your application or service using their existing credentials. Your application becomes the…
Continue Reading

OAuth – a primer

anuj April 25, 2025 OAuth – a primer2025-04-25T20:24:06+00:00 OAuth 2.0
Understanding OAuth: Client Types, Flows, and Key Concepts OAuth is the backbone of modern API security, enabling controlled access to resources without sharing user credentials. At its core, OAuth is…
Continue Reading

Two OAuth Flows – Public and Private

anuj March 14, 2025 Two OAuth Flows – Public and Private2025-03-14T14:59:27+00:00 OAuth 2.0
  Public Flow - Through the Browser, Token returned to the browser. Implicit Grant Flow Private/Confidential Clients (Backend OAuth Flow), Client Credentials Flow  Public clients use different authorization flows, like…
Continue Reading
123›»

Recent Posts

  • Security concerns around SSO and Account Opening Flows
  • OAuth for Individual Users vs. Service Accounts — Q&A
  • SSO with MFA – SaaS Service
  • Isolating Browser Sessions – In the Cloud and Locally
  • SAML-Based SSO: Source IP for IdP and SP Initiated Flows

Recent Comments

  • WFH and Remote Access Security Risks - Cloud Identity Architect on Work from Home – Laptop Options

Archives

  • August 2025
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • January 2025
  • November 2024
  • October 2024
  • October 2022
  • January 2022
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • September 2020

Categories

  • Active Directory (On Premises)
  • API Authentication
  • Azure AD
  • Browser Security
  • Entra ID
  • Graph API
  • JWT
  • MFA
  • OAuth 2.0
  • Office 365
  • SAML
  • SCIM
  • Securing Identity
  • SSO
  • Transport Layer
  • Troubleshooting – network and identity
  • Uncategorized

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Search

Recent Posts

  • Security concerns around SSO and Account Opening Flows
  • OAuth for Individual Users vs. Service Accounts — Q&A
  • SSO with MFA – SaaS Service
  • Isolating Browser Sessions – In the Cloud and Locally
  • SAML-Based SSO: Source IP for IdP and SP Initiated Flows

Pages

  • Contact Cloud Identity Architect
  • Privacy Policy for AdverSite Web Holdings, Inc.

Tags

    aad as an IdP for B2C aad idp Active Directory Groups and Memberships Active Directory Groups basics ad connect health adfs ad connect health agent add user roles powershell enteprise apps adfs applications to azure ad adfs to aad adfs to aad migration ad groups basics ad to aad ad to adds AD to Azure AD Migration azure ad b2c differences Azure AD versus Subscriptions b2b guest users aad b2c and aad b2c tenant versus AAD b2c vs aad Common AAD Powershell Commands custom role gcp enterprise apps aad powershell guest users AAD Migrate ADFS Apps using Usage and Insights migrate ad to azure Powershell for Managing O365's AAD powershell user assignment aad ps script add users azure ad why AAD B2C
Copyright ©2025. Cloud Identity Architect
Mesocolumn Theme by Dezzain