You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I disagree with the hard assertion that you should not let an agent login as user. “Login As” has its place if it is balanced with appropriate controls. This depends, in some cases, whether the agent is external or internal facing.
The text was updated successfully, but these errors were encountered:
@iglazer, do you have any specific examples where "login as" is more appropriate than "on behalf of", and or what controls you think would offset the risk of not having a means to audit the true actor in a case where they are logging in as?
I think we might have a terminological collision. In my mind, anything that enables a user to login as/on behalf of requires additional logging. The “upstream” user clearly needs to be clearly identified in durable logs.
I disagree with the hard assertion that you should not let an agent login as user. “Login As” has its place if it is balanced with appropriate controls. This depends, in some cases, whether the agent is external or internal facing.
The text was updated successfully, but these errors were encountered: