Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Field notes

Longer reads, from the field.

14 articles. Each has a TL;DR and a five-minute version.

14 articles
Merging two directories after an acquisitionMerging two directories safely means matching people on verified keys, never on names alone, and migrating in stages with a way back.Identity & access Provisioning6 minDeepAccess reviews that auditors acceptAn access review is a process, and the evidence matters as much as the decisions. Scope it, assign named reviewers, record decisions and keep the proof in one folder.Compliance Security operations5 minPracticalImplementing OpenID Connect with PKCE correctlyAuthorization code with PKCE is the recommended flow for web, mobile and single-page apps. Generate a verifier, send its hash, and check state, nonce, signature, issuer, audience and expiry on return.Engineering6 minDeepA 30-day pilot plan for an identity platformA 30-day pilot proves sign-in, passkeys and provisioning with a small group. Set up in week one, test in two and three, then decide in week four with numbers.Identity & access5 minPracticalChoosing MFA factors: TOTP, push, hardware keysPick factors by the attacks you face. Passkeys and security keys resist phishing, authenticator apps avoid the phone network, and SMS codes are the weakest. Use stronger factors for administrators first.Passwordless & passkeys Identity & access5 minPracticalService accounts and API keys: the identities nobody ownsService accounts and API keys are identities for software. They are powerful, often forgotten and rarely rotated. Give each an owner, narrow scope and an expiry.Identity & access Security operations5 minPracticalStreaming identity logs to your SIEMStream identity events to your SIEM by signed webhook or Splunk HEC. Verify the signature, reject old timestamps, parse the fields and alert on the events that matter.Security operations6 minDeepStep-up authentication: asking again only when it mattersStep-up asks a signed-in person to prove themselves again before a sensitive action. Be selective, choose how fresh the proof should be, and avoid prompt fatigue.Identity & access Security operations5 minPracticalWhat the DPDP Act means for employee dataThe DPDP Act affects the personal data your identity systems hold about employees. Map the data, state the purpose, keep consent records where you rely on consent, and prepare grievance routines. Ask counsel how it applies.Compliance5 minPracticalSCIM 2.0 in plain EnglishSCIM is a standard REST API for keeping users and groups in step across systems. HR changes flow to AuthMantra, and outbound provisioning carries them on to apps.Provisioning Engineering5 minPracticalJoiner, mover, leaver: the offboarding checklistAccess that outlives employment is a common audit finding. Start every change from the HR record, remove old access when roles change, and use one checklist for leavers.Identity & access Provisioning5 minPracticalWhy SMS one-time codes are not enoughText-message codes can be phished, intercepted through SIM swaps and delayed by carriers. They are better than nothing, but an authenticator app or a passkey is a clear step up.Passwordless & passkeys Identity & access5 minIntroPasskeys explained: FIDO2, WebAuthn, Face ID and security keysA passkey is a key pair: the private key stays on your device, the service keeps the public key. The site name is part of the signature, so fake pages get nothing usable.Passwordless & passkeys5 minIntroWhat is single sign-on, and why do both SAML and OIDC exist?Single sign-on lets one trusted provider vouch for you to many apps. SAML and OpenID Connect are the two standards. Choose by what each app supports, and prefer OIDC with PKCE for new apps.Identity & access Engineering5 minIntro