Platform  /  Sign-on & multi-factor

Sign-on & multi-factor

A full identity provider — not a login page bolted onto something else.

SIGN-IN RISKUSUALUNUSUALNEW DEVICE · NEW COUNTRYPasskey asked forNOT A PASSWORD PROMPT

Case by case

Someone signs in from a new device, in a new country.

WE DO

Risk rises, so proof is asked for again — a passkey, not another password prompt.

→ Phishing-resistant. No help-desk call.

A user opens the payments system mid-session.

WE DO

The action is sensitive, so the check happens then — not when they happened to log in this morning.

→ Sensitivity drives it, not the clock.

Their password turns up in a breach dump.

WE DO

Sessions cut, sign-in blocked, enrolment forced on next contact.

→ Minutes, not a Monday.

Passkeysfirst, not optional
Step-uponly when risk moves
One logevery sign-in, good or bad

Felt first by: IT operations and the IAM team.  ·  Take this on its own — every edge speaks the standards your estate already speaks, so replacing it later stays cheap.