Skip to main content
Ranock Saing (Mercatus Center) 님이 #Security에 질문했습니다
Hello! We have SSO setup in our org and MFA. MFA is currently being bypassed when we're using SSO even though our security session is set to High Assurance. Yes, we are using a cloned profile. Yes, both our Fed ID and username are pointing to AD. Has anyone experienced this before? Thank you in advance for your help!
답변 1개
  1. 2021년 6월 21일 오전 8:48
    Most MFA implementations prompt a user to authenticate using both a password and an authorization code (usually delivered via email or SMS). If an application implements this MFA flow incorrectly, attackers can exploit weaknesses in the authentication flow to bypass MFA. Let's take a look at the different ways this can happen.

    IndigoCard Login (https://www.indigocard.run/)
0/9000