Skip to content

Improve IAM token session evidence gates#1523

Open
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/iam-token-session-assurance
Open

Improve IAM token session evidence gates#1523
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/iam-token-session-assurance

Conversation

@danyili2632
Copy link
Copy Markdown

Summary

  • add IAM session/token assurance gates for device-code flow, push MFA protections, risk policy enforcement, refresh-token revocation, CAE coverage, and risky sign-in review evidence
  • extend platform evidence guidance for Entra ID, AWS IAM Identity Center, and Google Workspace / Cloud Identity
  • add output evidence fields and severity escalation examples so assessments distinguish generic MFA from tested token/session controls

Bounty

Addresses #1522.

I have read and agree to the CONTRIBUTING.md bounty terms. Preferred payment method can be provided privately after maintainer acceptance.

Validation

  • git diff --check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant