zlacker

[parent] [thread] 2 comments
1. mjg59+(OP)[view] [source] 2022-01-28 07:01:27
Most SSO solutions don't verify device identity or state, so you're not ensuring that the connection is coming from a computer you trust running software you trust.
replies(1): >>xyzzy_+9b
2. xyzzy_+9b[view] [source] 2022-01-28 08:42:11
>>mjg59+(OP)
I guess it's a matter of what the IdP attests. It's definitely possible for an IdP like Okta to include a ton of client details as part of the attestation payload. Stuff like GeoIP, client certificate fields, MDM status, etc.
replies(1): >>tptace+c91
◧◩
3. tptace+c91[view] [source] [discussion] 2022-01-28 15:36:46
>>xyzzy_+9b
Right, but you have to individually set up all of your apps to work with it; the proxy can be mandatory for all apps by dint of network controls.
[go to top]