Author Archives: anuj - Page 2
Isolating Browser Sessions – In the Cloud and Locally
Browser Isolation Options for Whitelisted Site Access
SAML-Based SSO: Source IP for IdP and SP Initiated Flows
SAML-Based SSO: Source IP for IdP and SP Initiated Flows SP-Initiated SSO Flow Summary: The user starts at the Service Provider (SP), which redirects them to the Identity Provider (IdP)…
Capturing a Second Factor Before Full Trust
MFA Before Full Access: A Secure User Onboarding Flow Capturing a Second Factor Before Full Trust: A Smarter Onboarding Flow In most traditional account creation flows, users are granted full…
Enforcing a Second Factor in Entra ID: How to Secure Users Who Never Had One
Enforcing a Second Factor in Entra ID: How to Secure Users Who Never Had One If a user isn’t using a second factor, they’re a risk. Many organizations still have…
Inbound versus Outbound SSO
? Inbound SSO (Single Sign-On) Definition:Inbound SSO means users from an external identity provider (IdP) can sign into your application or service using their existing credentials. Your application becomes the…
OAuth – a primer
Understanding OAuth: Client Types, Flows, and Key Concepts OAuth is the backbone of modern API security, enabling controlled access to resources without sharing user credentials. At its core, OAuth is…
Two OAuth Flows – Public and Private
Public vs. Confidential OAuth Clients and Flows Public Flow - Through the Browser, Token returned to the browser. Implicit Grant Flow Private/Confidential Clients (Backend OAuth Flow), Client Credentials Flow Public…
Bearer Tokens Based Authentication
Bearer Token–Based API Authentication and Authorization Bearer tokens are widely used to protect APIs. After a client obtains an access token from an authorization server, it presents that token whenever…
Private Key JWT Authentication
Private Key JWT Authentication Private Key JWT—usually identified by the OAuth client-authentication method name private_key_jwt—allows an application to authenticate using asymmetric cryptography instead of sending a shared client secret. The…
WFH and Remote Access Security Risks
Mitigation - Important multi-factor authentication automatic session timeouts and access monitoring Unauthorized access to devices Any machine that is capable of connecting to your network should be protected using multi-factor…