Administrative access to the identity provider is gained
Through phishing of an identity administrator or reuse of a privileged credential, the attacker gains administrative access to the identity provider that federates access to the organisation's applications.
Reach an administrative role in the SSO / identity provider.
- Phishing-resistant MFA and dedicated admin accounts for the IdP
- Strictly limited, monitored set of IdP administrators
- Privileged access management for identity administration
- Admin sign-ins to the IdP from unusual locations
- Risky sign-ins on identity-administration accounts
- Administrative actions outside normal hours
- Assess exposure and protection of IdP administrators
- Test MFA strength on identity administration
- Review who holds IdP admin and how it is monitored
The attacker controls the system that vouches for identity across the estate.