Platform / Sign-on & multi-factor
Sign-on & multi-factor
A full identity provider — not a login page bolted onto something else.
Case by case
Someone signs in from a new device, in a new country.
Risk rises, so proof is asked for again — a passkey, not another password prompt.
→ Phishing-resistant. No help-desk call.
A user opens the payments system mid-session.
The action is sensitive, so the check happens then — not when they happened to log in this morning.
→ Sensitivity drives it, not the clock.
Their password turns up in a breach dump.
Sessions cut, sign-in blocked, enrolment forced on next contact.
→ Minutes, not a Monday.
Felt first by: IT operations and the IAM team. · Take this on its own — every edge speaks the standards your estate already speaks, so replacing it later stays cheap.