Security · Security Architecture
Identity Security
Protecting the identity control plane itself, credentials, tokens, directories, privilege and the policies that govern them.
IntermediateUpdated 2026-09-01
Overview
Identity is now the primary attack surface. Attacks target credentials, session tokens, MFA registration, application consent and directory privilege rather than network perimeters.
Identity security therefore combines strong authentication, privileged access control, directory hardening, and detection focused on identity telemetry such as sign in logs, audit logs and directory changes.
Security considerations
- Monitor MFA registration changes, new federation trusts, consent grants and privileged role activation.
- Harden the directory itself: no standing privilege, tiered administration, and protected break glass accounts.
