Discussion
Open questionLast verified: 2026-08-13
- AuthorPosts
- 28th August 2026 at 7:41 am #3441
Some products charge extra for single sign-on, or only support MFA for administrators. How should a buyer define this requirement?
28th August 2026 at 11:39 am #3442Accepted answerBase the requirement on account impact, data sensitivity, privileged access, remote access, and the organization’s identity architecture. Require supported protocols, MFA methods, emergency access, lifecycle provisioning, session controls, logging, and enforcement for every relevant role. Test the controls before acceptance. NIST SP 800-207 states that trust should not depend on network location and that authentication and authorization must occur before access to a resource.
- AuthorPosts
- You must be logged in to reply to this topic.