Identity and Access Management
87 incident problems about Identity and Access Management. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (87)
SECURITY-005IAM role rotation leaves one batch worker using stale credentialsMost services refresh correctly, but one worker process keeps using cached credentials and starts failing scheduled jobs.ReviewedSecurityIntermediate20 minProSECURITY-121An OAuth token exchange succeeds, but the resource server clock skew rejects the just-issued JWT as not yet validIdentity is correct, yet token freshness assumptions differ across the two systems.SecurityAdvanced16 minProSECURITY-098CloudFront signed cookie scope excludes the websocket upgrade host and only the browser terminal loses authStatic pages load normally, but the interactive browser tool fails because the signed cookie domain or path does not cover the upgraded endpoint host.SecurityAdvanced16 minProSECURITY-393A break-glass access role bypasses MFA (Auth and Session Failure)A break-glass access role bypasses MFA (Auth and Session Failure) focuses on Identity and Access Management and asks the reader to isolate Auth and Session Failure in Azure. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로...SecurityAdvanced17 minProSECURITY-345A federated login trust points at the correct issuer while the downstream application still enforces the old audience or group claim mapping during a staged decommissionAuthentication succeeds at the identity edge and authorization fails where claims are interpreted differently. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced17 minProSECURITY-118A hardware token step-up is required on paper, but the mobile fallback policy silently downgrades privileged actions to SMSAdministrators believe strong authentication protects the action, yet one fallback rule lets the mobile app satisfy the control with a weaker factor.SecurityAdvanced17 minProSECURITY-135An AWS IAM permissions boundary copied from a template blocks kms:Decrypt in the break-glass role and recovery automation fails during an incidentThe emergency role exists, yet one inherited boundary quietly removes the exact permission the runbook requires.SecurityAdvanced17 minProSECURITY-154An IAM role trust policy is updated for the new OIDC issuer, but the condition key still references the old provider path and federated deploys failThe identity provider appears swapped successfully, yet the claim-matching logic is still anchored to the previous issuer structure.SecurityAdvanced17 minProSECURITY-150An incident containment playbook revokes the VM role, but the host's metadata proxy cache keeps serving old credentials for several minutesThe control plane moved fast, yet runtime revocation lag created a dangerous grace period.SecurityAdvanced17 minProSECURITY-096AWS IAM role session policy shrinks access below the base role and only one Lambda path fails decryptThe role seems correct, yet decryption still fails because the assumed session adds a restrictive inline policy at invocation time.SecurityAdvanced17 minProSECURITY-102Just-in-time admin approval succeeds, but the bastion PAM cache still enforces the previous group membershipOperators receive the right entitlement in the identity plane, yet the bastion keeps denying access until its local authorization cache expires.SecurityAdvanced17 minProSECURITY-109SCIM deprovision disables the SaaS account, but a long-lived personal token still lets the former admin call the APIIdentity offboarding appears complete in the UI, yet API access remains because one token type was never linked to account lifecycle enforcement.SecurityAdvanced17 minProSECURITY-330A break-glass or emergency path bypasses one identity control while another session or device rule still revokes it before the task finishes during a failover rehearsalThe emergency door opens and another control closes it before recovery is done. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-104A rotated KMS key policy omits the legacy alias and historical backup decrypt operations fail during recoveryNew encrypt operations work, but restore testing fails because the recovery path still references an alias that the new policy no longer permits.SecurityAdvanced18 minProSECURITY-282A trust policy validates the new OIDC issuer while one condition key still matches the old claim path during a failover rehearsalThe provider migration is half-complete and federated access still fails on the detail that matters. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-168An emergency account bypasses the first control while a downstream session rule still revokes it too early during a failover rehearsalThe break-glass path escapes one identity gate and remains constrained by another. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-078JIT provisioning creates duplicate accounts after the immutable identity key changesFederation remains healthy, but every login now spawns another local account because the stable identity key changed from email to a new immutable identifier.SecurityAdvanced18 minProSECURITY-107mTLS client identity maps to the wrong tenantCertificates are valid, yet authorization fails because the parser extracts a different identity field than the policy engine expects.SecurityAdvanced18 minProSECURITY-216Runtime credential caches keep serving access long after central revocation completed during a failover rehearsalThe security team acts quickly and the runtime still lives in the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-079Secrets Manager rotation succeeds but the application keeps reading the old current version stageThe rotation Lambda finishes, yet the service still fails login because the stage labels and the consumer refresh path are out of sync.SecurityAdvanced18 minPro