Open table of contents
Conclusion
Separate login decisions from ongoing sessions and identify the state each product observes.
Context
An IdP and an access proxy may evaluate state at different times. Distinguish responsibility and reevaluation timing for login and ongoing sessions.
Design and verification scope
Assess the following responsibilities and boundaries when designing and verifying a configuration.
- Identity provider
- Device posture
- Conditional Access
- Session lifetime
- Revocation
- Logs
Decision rationale
Use the relationship between Identity provider and Logs to compare the responsibilities of the selected approach and alternatives. Separate retained constraints from what the new boundary can change.
Trade-offs
Compare the implementation, maintenance and review work introduced by Device posture with the control it provides. Include failure paths, operator effort and conditions in which the approach should not be adopted.
Limitations
Review authentication flows, policies, revocation timing and logs. Combining products alone does not guarantee continuous evaluation.
Related case context
These cases provide attributed design context. They do not establish that the proposed experiments or configurations were delivered in those engagements.