Field notes
Longer reads, from the field.
14 articles. Each has a TL;DR and a five-minute version.
Merging two directories after an acquisitionMerging two directories safely means matching people on verified keys, never on names alone, and migrating in stages with a way back.Access reviews that auditors acceptAn access review is a process, and the evidence matters as much as the decisions. Scope it, assign named reviewers, record decisions and keep the proof in one folder.Implementing OpenID Connect with PKCE correctlyAuthorization code with PKCE is the recommended flow for web, mobile and single-page apps. Generate a verifier, send its hash, and check state, nonce, signature, issuer, audience and expiry on return.A 30-day pilot plan for an identity platformA 30-day pilot proves sign-in, passkeys and provisioning with a small group. Set up in week one, test in two and three, then decide in week four with numbers.Choosing MFA factors: TOTP, push, hardware keysPick factors by the attacks you face. Passkeys and security keys resist phishing, authenticator apps avoid the phone network, and SMS codes are the weakest. Use stronger factors for administrators first.Service accounts and API keys: the identities nobody ownsService accounts and API keys are identities for software. They are powerful, often forgotten and rarely rotated. Give each an owner, narrow scope and an expiry.Streaming identity logs to your SIEMStream identity events to your SIEM by signed webhook or Splunk HEC. Verify the signature, reject old timestamps, parse the fields and alert on the events that matter.Step-up authentication: asking again only when it mattersStep-up asks a signed-in person to prove themselves again before a sensitive action. Be selective, choose how fresh the proof should be, and avoid prompt fatigue.What the DPDP Act means for employee dataThe DPDP Act affects the personal data your identity systems hold about employees. Map the data, state the purpose, keep consent records where you rely on consent, and prepare grievance routines. Ask counsel how it applies.SCIM 2.0 in plain EnglishSCIM is a standard REST API for keeping users and groups in step across systems. HR changes flow to AuthMantra, and outbound provisioning carries them on to apps.Joiner, mover, leaver: the offboarding checklistAccess that outlives employment is a common audit finding. Start every change from the HR record, remove old access when roles change, and use one checklist for leavers.Why SMS one-time codes are not enoughText-message codes can be phished, intercepted through SIM swaps and delayed by carriers. They are better than nothing, but an authenticator app or a passkey is a clear step up.Passkeys explained: FIDO2, WebAuthn, Face ID and security keysA passkey is a key pair: the private key stays on your device, the service keeps the public key. The site name is part of the signature, so fake pages get nothing usable.What is single sign-on, and why do both SAML and OIDC exist?Single sign-on lets one trusted provider vouch for you to many apps. SAML and OpenID Connect are the two standards. Choose by what each app supports, and prefer OIDC with PKCE for new apps.
No articles match.