Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Discuss/Define: User Authentication via Workforce IdP #19

Open
jischr opened this issue Dec 16, 2024 · 5 comments
Open

Discuss/Define: User Authentication via Workforce IdP #19

jischr opened this issue Dec 16, 2024 · 5 comments

Comments

@jischr
Copy link

jischr commented Dec 16, 2024

topic should cover

  • set up user authentication via federated relationship with a customer's workforce IdP
@jischr jischr changed the title Create Section: User Authentication via Workforce IdP Discuss/Define User Authentication via Workforce IdP Dec 16, 2024
@jischr jischr changed the title Discuss/Define User Authentication via Workforce IdP Discuss/Define: User Authentication via Workforce IdP Dec 16, 2024
@joninusa
Copy link

joninusa commented Dec 17, 2024

This could include sharing MFA timeout or retry settings.e.g. For automated authentications, when MFA is required, don't exceed the retries to prevent account lockouts from a trusted source
Examples:
https://help.zscaler.com/zscaler-client-connector/configuring-automatic-zpa-reauthentication
https://www.reddit.com/r/fortinet/comments/1c822np/issues_with_forticlient_causing_duo_mfa_causing/
https://pages.nist.gov/800-63-4/sp800-63b.html (3.2.2 Rate Limiting (Throttling) {The goal of this would be to prevent excessive retries}

@joninusa
Copy link

Add Location sharing which can include the real client IP address

@dhs-BI
Copy link
Contributor

dhs-BI commented Dec 17, 2024

@joninusa can you describe more about "automated authentications" and the use cases that would require them?

@joninusa
Copy link

@joninusa can you describe more about "automated authentications" and the use cases that would require them?

I updated my original comment, does this answer your question?

@dhs-BI
Copy link
Contributor

dhs-BI commented Dec 23, 2024

Yes, that helps. My perspective is that the user should be involved in the authentication ceremony, e.g. NIST S800-63B and the concept of activation secrets for multifactor cryptographic authenticators. However, we should collect the relevant use cases for silent/automated authentication of the user and determine whether they are in/out of scope for IPSIE.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants