Topic87 problems· 6 reviewed

Identity and Access Management

87 incident problems about Identity and Access Management. Start with the reviewed ones.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

SECURITY-001The SSH management path is blocked after an overly narrow allowlist changeA situation where the access-control policy looks correct, but one jump-host range is missing, so the actual operations management path is blocked.ReviewedSecurityBeginner16 minFreeSECURITY-005IAM role rotation leaves one batch worker using stale credentialsMost services refresh correctly, but one worker process keeps using cached credentials and starts failing scheduled jobs.ReviewedSecurityIntermediate20 minProSECURITY-016MFA enforcement skipped for legacy admin endpointMFA enforcement skipped for legacy admin endpoint is a hands-on troubleshooting drill. The main login path correctly enforces MFA, but a secondary admin route still accepts a weaker path. Identity and Access Management needs to be checked by narrowing scope, recent change, and...ReviewedSecurityBeginner14 minFreeSECURITY-025Locked-down file permission hides SSH authorized_keys from user sessionLocked-down file permission hides SSH authorized_keys from user session is a hands-on troubleshooting drill. The authorized key exists, but the home directory ownership or mode makes the SSH daemon ignore it. Identity and Access Management needs to be checked by narrowing scop...ReviewedSecurityBeginner14 minFreeSECURITY-056Secrets Manager rotation updates the writer credential but read replicas still use the old secretRotation completes successfully on the primary path, yet one read-side workload keeps failing because its secret retrieval or cache path was never included in the rotation design.ReviewedSecurityIntermediate21 minFreeSECURITY-058OAuth device code session remains active after user offboardingThe user account is disabled, but a previously authorized device code flow keeps working because token revocation and downstream session invalidation were not linked tightly enough.ReviewedSecurityIntermediate20 minFree

All problems (87)

SECURITY-058OAuth device code session remains active after user offboardingThe user account is disabled, but a previously authorized device code flow keeps working because token revocation and downstream session invalidation were not linked tightly enough.ReviewedSecurityIntermediate20 minFreeSECURITY-056Secrets Manager rotation updates the writer credential but read replicas still use the old secretRotation completes successfully on the primary path, yet one read-side workload keeps failing because its secret retrieval or cache path was never included in the rotation design.ReviewedSecurityIntermediate21 minFreeSECURITY-001The SSH management path is blocked after an overly narrow allowlist changeA situation where the access-control policy looks correct, but one jump-host range is missing, so the actual operations management path is blocked.ReviewedSecurityBeginner16 minFreeSECURITY-025Locked-down file permission hides SSH authorized_keys from user sessionLocked-down file permission hides SSH authorized_keys from user session is a hands-on troubleshooting drill. The authorized key exists, but the home directory ownership or mode makes the SSH daemon ignore it. Identity and Access Management needs to be checked by narrowing scop...ReviewedSecurityBeginner14 minFreeSECURITY-016MFA enforcement skipped for legacy admin endpointMFA enforcement skipped for legacy admin endpoint is a hands-on troubleshooting drill. The main login path correctly enforces MFA, but a secondary admin route still accepts a weaker path. Identity and Access Management needs to be checked by narrowing scope, recent change, and...ReviewedSecurityBeginner14 minFreeSECURITY-039S3 server access log archive fails after object ownership policy changedCentral logging was working until bucket ownership controls changed, and now write attempts fail even though the destination bucket still exists and the prefix is correct.SecurityIntermediate19 minFreeSECURITY-097Conditional access trusts the compliant device claim but the token was minted before the device fell out of complianceThe policy is sound, yet a risky session survives because token lifetime outlasts the compliance state transition the team expected to revoke it instantly.SecurityIntermediate15 minFreeSECURITY-086Federated logout succeeds in the IdP but leaves the local admin session alive on the legacy appThe user appears signed out globally, but the legacy admin panel still accepts requests because its local session invalidation is not coupled to federation logout.SecurityIntermediate16 minFreeSECURITY-068MFA-enforced sudo flow breaks non-interactive automation on one hostThe stronger policy is correct for humans, but the service account path now fails because the exempt automation group was never applied consistently.SecurityIntermediate16 minFreeSECURITY-071OAuth login fails after a vanity-domain cutoverThe app and IdP are healthy, but authentication loops because the new branded callback path does not exactly match the registered redirect URI set.SecurityIntermediate16 minFreeSECURITY-076EKS IRSA token file becomes unreadable after a sidecar changes the shared volume ownershipThe role mapping is correct, but the application cannot assume it because the projected token path no longer matches the runtime user permissions after a sidecar update.SecurityIntermediate17 minFreeSECURITY-059Conditional access blocks the break-glass admin path during a device compliance incidentThe stronger policy makes sense normally, but the emergency access route now fails because it was never carved out from the same device compliance requirements.SecurityIntermediate18 minFreeSECURITY-036IMDSv1 remains reachable on a standby node after hardening rolloutPrimary instances were hardened correctly, but a rarely used standby or replacement path still exposes the older metadata service behavior.SecurityIntermediate18 minFreeSECURITY-010Password policy update breaks automation account loginA stronger policy is applied broadly, but one unattended account still uses the old credential pattern and starts failing.SecurityBeginner13 minFreeSECURITY-007Fail2ban blocks internal health checks after noisy auth failuresA brute-force defense rule works, but its source grouping catches internal monitoring traffic by mistake.SecurityBeginner15 minFreeSECURITY-035Identity provider session expires before a long-running admin workflow finishesThe user signs in successfully and starts a privileged operation, but the background confirmation step fails because the IdP session duration is shorter than the workflow window.SecurityBeginner17 minFreeSECURITY-061SAML login fails after an IdP migrationThe IdP is reachable and the assertion is signed, but the application still rejects login because the expected identity field changed during the migration.SecurityIntermediate18 minFreeSECURITY-028CSP header blocks internal admin tool script after hardeningCSP header blocks internal admin tool script is a hands-on troubleshooting drill. A new browser security policy helps overall, but one internal tool script source was never added and breaks the page. Azure Identity and Access Management needs to be checked by narrowing scope,...SecurityBeginner13 minFreeSECURITY-019Nginx basic auth protects one path but leaves upload endpoint openNginx basic auth protects one path but leaves upload endpoint open is a hands-on troubleshooting drill. The visible admin page is protected, but an adjacent upload route bypasses the same security control. NGINX Identity and Access Management needs to be checked by narrowing s...SecurityBeginner13 minFreeSECURITY-004Sudo policy grants command access but denies required shell pathThe command is technically allowed, yet execution still fails because the wrapper path differs from the approved binary.SecurityBeginner14 minFree