Home / Continuous / Identity

Identity

Identity is the control that decides whether everything else holds. This module tests the flows, and measures where coverage is missing.

What it covers

  • Single sign-on configuration and the trust relationships behind it
  • OAuth and OIDC flow handling, including redirect and token handling
  • SAML assertion handling and signature validation
  • MFA coverage: which accounts and which paths are not actually covered
  • Conditional access policy, and the gaps between what the policy says and what it enforces

How the work is carried out

A consultant directs this module and does the work that needs judgement, with automation carrying the continuous load between their passes. Your intervals are set during onboarding and recorded in the service agreement, because a schedule that suits one application would be wrong for a large, sprawling estate. What is fixed is the shape: a scheduled layer that runs the same checks on fixed intervals so change is visible, and an exploratory layer that a consultant directs based on what turns up. Reporting is monthly.

What the tooling handles

  • Keeps coverage checks running across accounts and policies
  • Flags new accounts, new applications and changed policy
  • Analyses flows non-destructively only

What our consultants do

  • Attempt bypass against the flows by hand, which needs judgement rather than pattern matching
  • Assess which coverage gaps matter given who holds the account
  • Confirm every finding before it is reported

Every finding in this module is reproduced or confirmed by a consultant before it reaches you.

What you receive

  • Validated findings, each reproduced or confirmed by a consultant
  • A monthly written report, including what changed since the last one
  • Critical and high findings notified within one business day of validation
  • A current view of MFA and policy coverage across your identities
  • Verification of fixes once you have applied them

What is out of scope

  • Physical access control and building security
  • Social engineering of your help desk or staff, which is the People module
  • Large-scale password cracking or credential stuffing, which is blocked by default
  • Denial-of-service testing against your identity provider

Prerequisites

Nothing runs until these are in place. We pause rather than proceed against an unconfirmed register.

  • Test identities in each role we are asked to assess
  • Read access to the identity provider tenant, or a configuration export
  • Signed authorisation from someone entitled to grant that access
  • A confirmed asset register listing the applications in scope

Next module: People