How to add 1Kosmos passwordless step-up authentication | Strata.io
How to add 1Kosmos passwordless step-up authentication and user registration with Strata's Identity Orchestration recipes.
Ingredients
- No-code PMFA deployment quickly secures sensitive app resources without refactoring
- Reduce friction by enrolling users to PMFA within existing access workflows
- Support low-risk phased rollout and concurrent PFMA options for recovery
- What the user sees
- What the admin does
- The user navigates to the app through their existing access workflow, in this case Azure AD SSO
- They then attempt to access a sensitive resource within the app, the “Executive Reports” tab
- Maverics intercepts the request and directs them to 1Kosmos to check whether or not they are enrolled in PMFA
- If the user is not enrolled in 1Kosmos, Maverics automates the Azure AD lookup to determine if they have the appropriate role and group attributes to access the data
- The user is then routed to an inline 1Kosmos registration page that guides them through enrollment
- If the user was already enrolled in 1Kosmos or the next time the newly enrolled user returns to the protected resource
- Maverics automatically checks their permission attributes in Azure AD and then presents them with 1Kosmos PMFA
- Upon successful authentication via the 1Kosmos app, the user is granted access to the “Executive Reports” tab
- Admin opens their YAML file for Maverics which is a simple top-down approach using a declarative model
- Under the Connectors section, the Admin specifies that they will be using Azure and 1Kosmos
- Admin then specifies 1Kosmos as the PMFA authenticator under their desired appgateway and/or authentication provider configuration
- Once the URL is specified, the Admin then simply selects 1Kosmos in the configuration for PMFA step-up authentication
- Upon users next visit the application and the “Executive Reports” tab, Maverics then orchestrates the 1Kosmos PMFA workflow
More Like This
How to add HYPR passwordless authentication | Strata.io
strata.io
How to extend Okta to any on-prem, legacy app | Strata.io
strata.io
How to add modern authentication to apps using NTLM over LDAP | Strata.io
strata.io
Identity Orchestration Recipes - Strata.io
strata.io
Failover from Okta to on-prem Active Directory (AD) | Strata.io
strata.io
Claims Transformation - SAML and OIDC | Recipes | Strata.io
strata.io
Secure & control cross-border access to a global resource | Strata.io
strata.io
How to replace Keycloak with Amazon Cognito | Recipes | Strata.io
strata.io