Step-up authentication protects sensitive moments
Step-up authentication asks for more proof at the moment something important happens, rather than only at the door.
You log in once to browse. Changing the payment details, adding a new administrator or exporting the customer list asks again. It puts the check where the consequence is, which is also where a stolen session is most dangerous, because that session already sailed past the login. It is far less annoying than tightening everything, and it covers the moments that actually matter.
More on Identity and authentication
- Session lifetime is a security decisionSomebody chose how long it burns
- Machine identities need owners tooWhose is this one? Machine identities are somebody's responsibility, or nobody's
- MFATwo things to hand over, one that will not go
- PAMSign it out, do not keep it
- Account recoveryThe other lane
- AuthenticationIt only answers the first question
