D7';display:inline-block}#ez-toc-container p.ez-toc-title{text-align:left;line-height:1.45;margin:0;padding:0}.ez-toc-title{display:table-cell;text-align:left;vertical-align:middle}#ez-toc-container a{color:#444;box-shadow:none;text-decoration:none;text-shadow:none}#ez-toc-container a:visited{color:#9f9f9f}#ez-toc-container a.ez-toc-toggle{color:#444}.ez-toc-btn{display:inline-block;padding:6px 12px;margin-bottom:0;font-size:14px;font-weight:400;line-height:1.428571429;text-align:center;white-space:nowrap;vertical-align:middle;background-image:none;border:1px solid transparent;border-radius:4px}.ez-toc-btn-default{color:#333;background-color:#fff;border-color:#ccc}.ez-toc-btn-xs{padding:5px 10px;font-size:12px;line-height:1.5;border-radius:3px}.ez-toc-btn-xs{padding:1px 5px}.ez-toc-btn-default{text-shadow:0 -1px 0 rgba(0,0,0,.2);-webkit-box-shadow:inset 0 1px 0 rgba(255,255,255,.15),0 1px 1px rgba(0,0,0,.075);box-shadow:inset 0 1px 0 rgba(255,255,255,.15),0 1px 1px rgba(0,0,0,.075)}.ez-toc-btn-default{text-shadow:0 1px 0 #fff;background-image:-webkit-gradient(linear,left 0,left 100%,from(#fff),to(#e0e0e0));background-image:-webkit-linear-gradient(top,#fff 0,#e0e0e0 100%);background-image:-moz-linear-gradient(top,#fff 0,#e0e0e0 100%);background-image:linear-gradient(to bottom,#fff 0,#e0e0e0 100%);background-repeat:repeat-x;border-color:#dbdbdb;border-color:#ccc;filter:progid:DXImageTransform.Microsoft.gradient(startColorstr='#ffffffff',endColorstr='#ffe0e0e0',GradientType=0);filter:progid:DXImageTransform.Microsoft.gradient(enabled=false)}.ez-toc-pull-right{float:right!important;margin-left:10px}.ez-toc-glyphicon{position:relative;top:1px;display:inline-block;font-family:'Glyphicons Halflings';-webkit-font-smoothing:antialiased;font-style:normal;font-weight:400;line-height:1;-moz-osx-font-smoothing:grayscale}.ez-toc-glyphicon:empty{width:1em}.ez-toc-toggle i.ez-toc-glyphicon{font-size:16px;margin-left:2px}[class*=ez-toc-icon-]{font-family:'ez-toc-icomoon'!important;speak:none;font-style:normal;font-weight:400;font-variant:normal;text-transform:none;line-height:1;-webkit-font-smoothing:antialiased;-moz-osx-font-smoothing:grayscale}.ez-toc-icon-toggle:before{content:"\e87a"}div#ez-toc-container p.ez-toc-title{display:contents}div#ez-toc-container p.ez-toc-title{font-size:120%}div#ez-toc-container p.ez-toc-title{font-weight:500}button,input[type=submit]{box-sizing:border-box;border-color:currentColor;text-align:center;font-family:var(--bodyfontfamily),var(--nv-fallback-ff)}button,input[type=submit]{box-sizing:border-box;background:var(--primarybtnbg);color:var(--primarybtncolor);border-style:solid;border-color:currentColor;fill:currentColor;border-width:var(--primarybtnborderwidth,0);border-radius:var(--primarybtnborderradius,3px);padding:var(--primarybtnpadding,13px 15px);font-weight:var(--btnfontweight,700);font-size:var(--btnfs,var(--bodyfontsize));line-height:var(--btnlineheight,1.6);letter-spacing:var(--btnletterspacing,var(--bodyletterspacing));text-transform:var(--btntexttransform,none)}form input:read-write{border-style:solid;border-color:var(--formfieldbordercolor);border-width:var(--formfieldborderwidth);border-radius:var(--formfieldborderradius,3px);background:var(--formfieldbgcolor);color:var(--formfieldcolor);padding:var(--formfieldpadding);text-transform:var(--formfieldtexttransform);font-weight:var(--formfieldfontweight);font-family:var(--bodyfontfamily);font-size:var(--formfieldfontsize);letter-spacing:var(--formfieldletterspacing);line-height:var(--formfieldlineheight)}form label{font-weight:var(--formlabelfontweight,var(--bodyfontweight));text-transform:var(--formlabeltexttransform);letter-spacing:var(--formlabelletterspacing);line-height:var(--formlabellineheight);font-size:var(--formlabelfontsize,var(--bodyfontsize))}.nv-meta-list li{font-weight:var(--fontweight);text-transform:var(--texttransform);letter-spacing:var(--letterspacing);line-height:var(--lineheight);font-size:var(--fontsize)}.title.entry-title{font-size:var(--fontsize,var(--h1fontsize));font-weight:var(--fontweight,var(--h1fontweight));line-height:var(--lineheight,var(--h1lineheight));letter-spacing:var(--letterspacing,var(--h1letterspacing));text-transform:var(--texttransform,var(--h1texttransform))}body,h1,h2,html,li,p,ul{margin:0;padding:0}h1,h2{font-size:100%;font-weight:400}ul{list-style:none}button,input{margin:0}html{box-sizing:border-box;-ms-overflow-style:scrollbar}*,:after,:before{box-sizing:border-box}img{height:auto;max-width:100%}.container{width:100%;padding-right:15px;padding-left:15px;margin:0 auto;max-width:var(--container)}.row{display:flex;flex-wrap:wrap;margin:0 -15px}.col{padding:0 15px;margin:0 auto;flex-grow:1;max-width:100%}html{font-size:100%}body{background-color:var(--nv-site-bg);color:var(--nv-text-color);font-size:var(--bodyfontsize);line-height:var(--bodylineheight);letter-spacing:var(--bodyletterspacing);font-family:var(--bodyfontfamily),var(--nv-fallback-ff);text-transform:var(--bodytexttransform);font-weight:var(--bodyfontweight);overflow-x:hidden;direction:ltr;-webkit-font-smoothing:antialiased;-moz-osx-font-smoothing:grayscale}h1,h2{margin-bottom:30px;font-family:var(--headingsfontfamily),var(--nv-fallback-ff)}p{margin-bottom:30px}a{--linkdeco:none;color:var(--nv-primary-accent);text-decoration:var(--linkdeco)}h1{font-size:var(--h1fontsize);font-weight:var(--h1fontweight);line-height:var(--h1lineheight);letter-spacing:var(--h1letterspacing);text-transform:var(--h1texttransform)}h2{font-size:var(--h2fontsize);font-weight:var(--h2fontweight);line-height:var(--h2lineheight);letter-spacing:var(--h2letterspacing);text-transform:var(--h2texttransform)}ul{padding-left:var(--listpad,0)}ul{list-style:var(--liststyle,none)}.show-on-focus{position:absolute;width:1px;height:1px;clip:rect(1px,1px,1px,1px);top:32px;background:var(--nv-site-bg);padding:10px 15px}.screen-reader-text{position:absolute;left:-10000px;top:auto;width:1px;height:1px;overflow:hidden}.nv-icon{fill:currentColor}.nv-search{display:flex}.site-logo{align-items:center;display:flex}.site-logo img{max-width:var(--maxwidth);display:block;margin:0 auto}.nav-ul{display:flex;flex-wrap:wrap;margin-right:calc(var(--spacing)/2*-1);margin-left:calc(var(--spacing)/2*-1)}.nav-ul li>a{display:flex;align-items:center;min-height:var(--height);color:var(--color);position:relative}.nav-ul>li{margin:0 calc(var(--spacing)/2)}.nav-ul li{display:block;position:relative}.header-menu-sidebar .nv-nav-wrap{width:100%}.header-menu-sidebar .nav-ul{flex-direction:column;width:100%}.header-menu-sidebar .nav-ul li{width:100%}.header-menu-sidebar .nav-ul li:not([class*=block])>a{padding:15px 0;white-space:unset}.nv-nav-search{position:absolute;visibility:hidden;opacity:0;right:0;width:auto;padding:10px;z-index:100;background-color:var(--nv-site-bg);box-shadow:rgba(149,157,165,.2) 0 8px 24px;display:flex;align-items:center}.nv-nav-search .container{padding:0}.menu-item-nav-search{outline:0}.menu-item-nav-search svg{width:var(--iconsize);height:var(--iconsize)}.menu-item-nav-search.floating .form-wrap{flex-grow:1}.menu-item-nav-search.floating .nv-nav-search{align-items:unset;position:fixed;top:-100%;left:0}.menu-item-nav-search.floating .close-container{display:flex}.menu-item-nav-search.floating .close-responsive-search{display:flex;align-items:center;--primarybtnpadding:0 20px}.header-menu-sidebar .menu-item-nav-search.floating .nv-nav-search{position:absolute}.menu-item-nav-search.canvas .nv-nav-search{position:fixed;top:0;bottom:0;width:100%;display:flex;justify-content:center;align-items:center}.menu-item-nav-search.canvas .nv-nav-search .close-container{position:absolute;top:30px;text-align:right}.close-responsive-search{background:0;border:0;--primarybtnhoverbg:0}.close-responsive-search>svg{fill:var(--nv-text-color);width:var(--formfieldfontsize);min-width:25px;min-height:25px}.navbar-toggle-wrapper{align-items:center}.navbar-toggle{--primarybtncolor:var(--color);--primarybtnhovercolor:var(--color);--primarybtnbg:var(--bgcolor,transparent);--primarybtnhoverbg:var(--bgcolor,transparent);--primarybtnborderwidth:var(--borderwidth,1px);--primarybtnborderradius:var(--borderradius,0);padding:var(--padding,10px 15px);box-shadow:none;display:flex;align-items:center}.icon-bar{background-color:currentColor;position:relative;display:block;width:15px;height:2px}.icon-bar:nth-child(2){margin:3px 0}.wrapper{display:flex;min-height:100vh;flex-direction:column;position:relative}body>.wrapper:not(.et-fb-iframe-ancestor){overflow:hidden}.neve-main{flex:1 auto}input[type=email],input[type=password],input[type=search],input[type=submit],input[type=text]{display:inline-block;-webkit-appearance:none;-moz-appearance:none;appearance:none;outline:0;resize:vertical}button,input{line-height:inherit;box-sizing:border-box}::placeholder{color:inherit;opacity:.5}label{display:inline-block}.search-form{display:flex;max-width:100%;line-height:1;--primarybtnbg:var(--formfieldbgcolor);--primarybtnhoverbg:var(--formfieldbgcolor);--primarybtncolor:var(--formfieldbordercolor);--primarybtnhovercolor:var(--formfieldbordercolor)}.search-form svg{fill:var(--formfieldcolor);width:var(--formfieldfontsize);opacity:.5;height:auto}.search-form .search-submit{display:flex;justify-content:center;align-items:center;min-width:45px;z-index:1;--primarybtnborderwidth:var(--formfieldborderwidth);--primarybtnbordercolor:var(--formfieldbordercolor);--primarybtnborderradius:var(--formfieldborderradius);--primarybtnpadding:var(--formfieldpadding);border-bottom-left-radius:0;border-top-left-radius:0;border-left:0;position:relative;height:var(--height);overflow:hidden}.search-form .search-submit:before{content:"";display:block;width:3px;height:100%;background-color:var(--formfieldbgcolor);left:-3px;top:0;bottom:0;position:absolute}.search-form .search-field{overflow:hidden;text-overflow:ellipsis;height:var(--height);border-right:0;flex-grow:1;border-top-right-radius:0;border-bottom-right-radius:0;width:calc(100% - 45px);max-width:100%}.nv-meta-list{margin-bottom:20px;font-size:.9em}.nv-meta-list li,.nv-meta-list span{display:inline-block}.nv-meta-list li:not(:last-child):after{content:"/";padding:0 8px}.nv-meta-list .photo{width:var(--avatarsize);height:var(--avatarsize);border-radius:50%;transform:translateY(30%);margin-right:3px}.entry-title{word-wrap:break-word}article{word-break:break-word}.nv-single-post-wrap>div:first-child{margin-top:60px}.nv-single-post-wrap>div:not(:last-child){margin-bottom:var(--spacing,60px)}.entry-header{text-align:var(--textalign,center)}.entry-header .title{margin-bottom:10px}.nv-is-boxed a{color:var(--color,var(--nv-text-color))}#comments input:not([type=submit]):not([type=checkbox]){width:100%}.nv-single-post-wrap{margin-bottom:60px}.nv-title-meta-wrap .neve-breadcrumbs-wrapper{margin-bottom:30px;display:block}.neve-breadcrumbs-wrapper{font-size:14px}.item--inner,.menu-item-nav-search,.nav-ul a,.site-logo{justify-content:var(--justify,flex-start);text-align:var(--textalign,left)}@media (min-width:960px){.neve-main>.container .col{max-width:70%}.neve-main>.container>.row{flex-wrap:nowrap}}.header-menu-sidebar{padding:0;position:fixed;max-width:100%;top:0;z-index:999900;visibility:hidden;display:flex;height:100vh}.header-menu-sidebar .navbar-toggle-wrapper{display:flex;justify-content:flex-end;padding:8px 10px}.header-menu-sidebar .navbar-toggle-wrapper button.navbar-toggle{position:relative}.header-menu-sidebar-bg{background-color:var(--bgcolor);color:var(--color);position:relative;display:flex;flex-direction:column;word-wrap:break-word;width:100%}.header-menu-sidebar-inner{padding:20px 0;overflow-x:hidden;height:100%;display:none;opacity:0}.header-menu-sidebar-inner .item--inner{width:100%}.menu_sidebar_slide_left .header-menu-sidebar{left:0;transform:translateX(-100%)}.header-menu-sidebar .menu-item-nav-search{display:flex;align-items:center}.hfg-ov{top:0;bottom:0;right:0;left:0;background:rgba(0,0,0,.5);position:fixed;transform:translate3d(0,0,0);z-index:999899;visibility:hidden;opacity:0}.site-header{position:relative}.site-header .header--row-inner{align-items:center;display:flex}.builder-item{margin:4px 0;position:relative;min-height:1px;padding-right:15px;padding-left:15px}@media (min-width:960px){.builder-item{margin:8px 0}}.hfg-slot{display:flex;align-items:center}.hfg-slot.right{justify-content:flex-end}.hfg-slot.center{justify-content:center}.header-menu-sidebar-bg,[class*=row-inner]{position:relative;background-image:var(--bgimage,none);background-position:var(--bgposition,center);background-repeat:no-repeat;background-size:cover;background-attachment:var(--bgattachment)}.header-menu-sidebar-bg:before,[class*=row-inner]:before{display:block;width:100%;top:0;bottom:0;position:absolute;content:"";background-color:var(--overlaycolor);opacity:var(--bgoverlayopacity)}[class*=row-inner]:not(.footer--row-inner){border-bottom:var(--rowbwidth,0) solid var(--rowbcolor)}[data-row-id]{color:var(--color);background:var(--bgcolor)}[data-row-id] a{color:var(--color)}[data-row-id] .row{display:grid;grid-template-columns:auto auto;min-height:var(--height,auto)}.has-center .row--wrapper{grid-template-columns:1fr auto 1fr}.hfg_header.site-header{box-shadow:0 -1px 3px rgba(0,0,0,.1)}.header .builder-item .item--inner[class*=nav-icon]{padding:0!important}@media (min-width:960px){.hide-on-desktop{display:none}}@media (max-width:959px){.hide-on-tablet{display:none}}@media (max-width:576px){.hide-on-mobile{display:none}}.builder-item .item--inner{color:var(--color);font-family:var(--fontfamily,var(--bodyfontfamily));font-size:var(--fontsize,var(--bodyfontsize));line-height:var(--lineheight,var(--bodylineheight));letter-spacing:var(--letterspacing,var(--bodyletterspacing));font-weight:var(--fontweight,var(--bodyfontweight));text-transform:var(--texttransform,var(--bodytexttransform));padding:var(--padding,0);margin:var(--margin,0);position:relative}.builder-item .item--inner.has_menu{position:unset}.nv-meta-list li.meta:not(:last-child):after{content:"/"}.nv-meta-list li.last:after{content:""!important}:root{--container:748px;--postwidth:100%;--primarybtnbg:var(--nv-primary-accent);--primarybtnhoverbg:var(--nv-primary-accent);--primarybtncolor:#fff;--secondarybtncolor:var(--nv-primary-accent);--primarybtnhovercolor:#fff;--secondarybtnhovercolor:var(--nv-primary-accent);--primarybtnborderradius:3px;--secondarybtnborderradius:3px;--secondarybtnborderwidth:3px;--btnpadding:13px 15px;--primarybtnpadding:13px 15px;--secondarybtnpadding:10px 12px;--bodyfontfamily:Arial,Helvetica,sans-serif;--bodyfontsize:15px;--bodylineheight:1.6;--bodyletterspacing:0px;--bodyfontweight:400;--h1fontsize:36px;--h1fontweight:700;--h1lineheight:1.2;--h1letterspacing:0px;--h1texttransform:none;--h2fontsize:28px;--h2fontweight:700;--h2lineheight:1.3;--h2letterspacing:0px;--h2texttransform:none;--h3fontsize:24px;--h3fontweight:700;--h3lineheight:1.4;--h3letterspacing:0px;--h3texttransform:none;--h4fontsize:20px;--h4fontweight:700;--h4lineheight:1.6;--h4letterspacing:0px;--h4texttransform:none;--h5fontsize:16px;--h5fontweight:700;--h5lineheight:1.6;--h5letterspacing:0px;--h5texttransform:none;--h6fontsize:14px;--h6fontweight:700;--h6lineheight:1.6;--h6letterspacing:0px;--h6texttransform:none;--formfieldborderwidth:2px;--formfieldborderradius:3px;--formfieldbgcolor:var(--nv-site-bg);--formfieldbordercolor:#ddd;--formfieldcolor:var(--nv-text-color);--formfieldpadding:10px 12px}.nv-meta-list{--avatarsize:20px}.single .nv-meta-list{--avatarsize:20px}.entry-header{--textalign:left}.header-main{--rowbwidth:0px;--rowbcolor:var(--nv-light-bg);--color:var(--nv-text-color);--bgcolor:var(--nv-site-bg)}.header-menu-sidebar-bg{--justify:flex-start;--textalign:left;--flexg:1;--wrapdropdownwidth:auto;--color:var(--nv-text-color);--bgcolor:var(--nv-site-bg)}.header-menu-sidebar{width:360px}.builder-item--logo{--maxwidth:120px;--padding:10px 0;--margin:0;--textalign:left;--justify:flex-start}.builder-item--nav-icon,.header-menu-sidebar .close-sidebar-panel .navbar-toggle{--borderradius:0}.builder-item--nav-icon{--label-margin:0 5px 0 0;--padding:10px 15px;--margin:0}.builder-item--primary-menu{--hovercolor:var(--nv-secondary-accent);--activecolor:var(--nv-primary-accent);--spacing:20px;--height:25px;--padding:0;--margin:0;--fontsize:1em;--lineheight:1.6;--letterspacing:0px;--fontweight:500;--texttransform:none;--iconsize:1em}.builder-item--header_search_responsive{--iconsize:15px;--formfieldfontsize:14px;--formfieldborderwidth:2px;--formfieldborderradius:2px;--height:40px;--padding:0 10px;--margin:0}@media (min-width:576px){:root{--container:992px;--postwidth:50%;--btnpadding:13px 15px;--primarybtnpadding:13px 15px;--secondarybtnpadding:10px 12px;--bodyfontsize:16px;--bodylineheight:1.6;--bodyletterspacing:0px;--h1fontsize:38px;--h1lineheight:1.2;--h1letterspacing:0px;--h2fontsize:30px;--h2lineheight:1.2;--h2letterspacing:0px;--h3fontsize:26px;--h3lineheight:1.4;--h3letterspacing:0px;--h4fontsize:22px;--h4lineheight:1.5;--h4letterspacing:0px;--h5fontsize:18px;--h5lineheight:1.6;--h5letterspacing:0px;--h6fontsize:14px;--h6lineheight:1.6;--h6letterspacing:0px}.nv-meta-list{--avatarsize:20px}.single .nv-meta-list{--avatarsize:20px}.entry-header{--textalign:left}.header-main{--rowbwidth:0px}.header-menu-sidebar-bg{--justify:flex-start;--textalign:left;--flexg:1;--wrapdropdownwidth:auto}.header-menu-sidebar{width:360px}.builder-item--logo{--maxwidth:120px;--padding:10px 0;--margin:0;--textalign:left;--justify:flex-start}.builder-item--nav-icon{--label-margin:0 5px 0 0;--padding:10px 15px;--margin:0}.builder-item--primary-menu{--spacing:20px;--height:25px;--padding:0;--margin:0;--fontsize:1em;--lineheight:1.6;--letterspacing:0px;--iconsize:1em}.builder-item--header_search_responsive{--formfieldfontsize:14px;--formfieldborderwidth:2px;--formfieldborderradius:2px;--height:40px;--padding:0 10px;--margin:0}}@media (min-width:960px){:root{--container:1170px;--postwidth:50%;--btnpadding:13px 15px;--primarybtnpadding:13px 15px;--secondarybtnpadding:10px 12px;--bodyfontsize:16px;--bodylineheight:1.7;--bodyletterspacing:0px;--h1fontsize:40px;--h1lineheight:1.1;--h1letterspacing:0px;--h2fontsize:32px;--h2lineheight:1.2;--h2letterspacing:0px;--h3fontsize:28px;--h3lineheight:1.4;--h3letterspacing:0px;--h4fontsize:24px;--h4lineheight:1.5;--h4letterspacing:0px;--h5fontsize:20px;--h5lineheight:1.6;--h5letterspacing:0px;--h6fontsize:16px;--h6lineheight:1.6;--h6letterspacing:0px}.neve-main>.single-post-container .nv-single-post-wrap.col{max-width:70%}.nv-meta-list{--avatarsize:20px}.single .nv-meta-list{--avatarsize:20px}.entry-header{--textalign:left}.header-main{--rowbwidth:3px}.header-menu-sidebar-bg{--justify:flex-start;--textalign:left;--flexg:1;--wrapdropdownwidth:auto}.header-menu-sidebar{width:360px}.builder-item--logo{--maxwidth:218px;--padding:10px 0;--margin:0;--textalign:center;--justify:center}.builder-item--nav-icon{--label-margin:0 5px 0 0;--padding:10px 15px;--margin:0}.builder-item--primary-menu{--spacing:20px;--height:25px;--padding:0;--margin:0;--fontsize:1em;--lineheight:1.6;--letterspacing:0px;--iconsize:1em}.builder-item--header_search_responsive{--formfieldfontsize:14px;--formfieldborderwidth:2px;--formfieldborderradius:2px;--height:40px;--padding:0 10px;--margin:0}}:root{--nv-primary-accent:#2f5aae;--nv-secondary-accent:#2f5aae;--nv-site-bg:#fff;--nv-light-bg:#f4f5f7;--nv-dark-bg:#121212;--nv-text-color:#272626;--nv-text-dark-bg:#fff;--nv-c-1:#9463ae;--nv-c-2:#be574b;--nv-fallback-ff:Arial,Helvetica,sans-serif}div.the_champ_sharing_ul a:link{text-decoration:none;background:transparent!important}.the_champ_vertical_sharing{-webkit-box-sizing:content-box!important;-moz-box-sizing:content-box!important}div.the_champ_sharing_ul a{text-decoration:none!important;margin:2px;float:left;padding:0;list-style:none;border:none;clear:none}.the_champ_vertical_sharing{background:0 0;-webkit-box-shadow:0 1px 4px 1px rgba(0,0,0,.1);box-shadow:0 1px 4px 1px rgba(0,0,0,.1);position:fixed;overflow:visible;z-index:10000000;display:block;padding:10px;border-radius:4px;opacity:1;box-sizing:content-box!important}.the_champ_sharing_container a{padding:0!important;box-shadow:none!important;border:none!important}div.the_champ_bottom_sharing{margin-bottom:0}@media screen and (max-width:783px){.the_champ_hide_sharing{display:none}}
"Okta Parses Passwords In Clear Text", What Does That Mean To Me? - Kick Cyber Security Into Gear Tel: (+61) 422 933 319
Email: michael@kicksec.io
“Okta parses passwords in clear text”, What does that mean to me?
This is really NOT an Okta problem but an industry problem – my industry, cloud SSO authentication should always and only be against known “good” Authenticators such as Microsoft, Google, Apple and others for all cloud based SSO. Passwords should never be out in the open, just the same as the Serengeti, which I previously wrote about here , don’t be out in the open, because someone/thing is always watching you 👀.
The OKTA article is here on Dark reading and is interesting for a number of reasons, none of which are problems with OKTA, they are problems with interoperability between platform players, as well as our desire to avoid “Agents” in all cases.
The cyber attack use case proposed in the linked article is more ‘likely than is it unlikely’ as many organisations still are not thinking in a Zero Trust Least privilege architecture model for application access.
I want to repeat my opinion, that OKTA is not the problem here, their platform is just an indication of a bigger industry problem with Single Sign on. All application developers and vendors must start living and breathing secure by design into their products.
Looking to the future and one very important aspect that all organisations looking to implement new platforms should be adding as a critical decision point is: Does the vendor application I am purchasing support Single Sign on through SAML or another federation provider, where the answer is no then a serious discussion needs to be had around whether that vendor solution is the right one for your organisation.
If you have on premise applications that need the protection of Single Sign On and secure access from the internet and non domain joined machines then review Azure Application proxy here , Azure Application proxy is a part of M365 Business Premium and the E3 and above licenses and a great way to secure legacy on premise applications behind Azure Active Directory.
Single sign on will improve your organisations security and help with the cyber security maturity by:
Centralising the identity store (no forgotten passwords) Making Multi factor authentication easy to implement via the identity provider Allowing many forms of risk based conditional access policies to be implemented Provide an easy route for 3rd parties to be able to access your platform if desired Allow for access to be reviewed regularly and therefore minimising privilege creep Ensuring that the credentials are safe My summary The Zero trust Network architecture requires least privileged access to be enforced and identities to be verified every time (I dislike “explicitly” as I am not at school anymore being told off by the headmaster!) they are used.
Ensuring that your software vendors can use these identity stores enables your business to leverage your single source of identity truth to provide the right access, “Just in time” for privileged users as well as full audit of all activities.
The Australian Cyber Security Centre is still catching up to this in their 38 mitigations, do not wait and start looking to how you can secure your apps today.
If you are still here… As a side topic this article I came across recently is quite interesting in regards to who charges for Single Sign On, vendors needs to make money as without cash there is no product.
My question is, wouldn’t Single Sign On reduce password resets, role changes, Helpdesk tickets to the provider, make the application cheaper to develop (dropping the bespoke authenticator) make their application more secure, giving their users a better experience overall? Personally I think it would be a step forward for everyone to integrate third party Single Sign on at no cost.
Related Posts 27/03/2025
Gen AI – doing what you are not good at! Generative AI like Microsoft CoPilot will not make you better at what you are already good at, when first I tried using Copilot to draft answers to emails for me, it failed and therefore I failed – the results were not what I would write,…
Read more: Gen AI – doing what you are not good at! 14/01/2025
If you do not know about cyber crime in 2025 then I am not sure where you are living but Cyber crime affects everyone including those of us on the Limestone coast in South Australia, just because we are in a low population area doesn’t mean that you and I are not being targeted by…
Read more: Think security – protect yourselves from cyber criminals 18/11/2024
Microsoft Defender for Endpoint Intro video, I have started to create some shortform video content to help Managed Service providers and customers with what various cyber security capabilities are and tools that can help. These are not flashy and are simple and quickly created to cover the basics in a short timeframe.
Read more: Microsoft Defender for Endpoint Intro video 15/11/2024
Kasaya CEO says MSP’s will benefit by Vendor Consolidation? Interesting comments by Kasaya’s CEO, 10% profit margin is certainly dangerously low and I would hope that there are not many MSP’s operating here. BTW, if you are #Crayon can help you, this is what we like doing most and it is what we do best,…
Read more: Kasaya CEO says MSP’s will benefit by Vendor Consolidation?
Leave a Reply