Topic87 problems· 6 reviewed

Identity and Access Management

87 incident problems about Identity and Access Management. Start with the reviewed ones.

All problems (87)

SECURITY-085Session revocation works centrally but one edge node continues accepting the old JWT until its cache expiresThe revoke event is recorded correctly, yet some requests still succeed because one verifier node has not refreshed its token or key cache.SecurityAdvanced18 minProSECURITY-091SSO works but step-up MFA never triggersPrimary authentication succeeds, yet privileged actions remain exposed because the application is still reading an outdated assurance claim.SecurityAdvanced18 minProSECURITY-081Conditional Access excludes the break-glass user but not the device-registration prerequisiteThe emergency account is excluded from the main policy, yet login still fails because an upstream prerequisite step is governed by a different device rule set.SecurityAdvanced19 minProSECURITY-093Secrets rotation updates the database user but leaves a cached connection pool authenticating with the old passwordThe new credential is valid, yet outages continue because the application pool never discarded existing sessions that still reuse the previous password flow.SecurityAdvanced19 minProSECURITY-072IAM permission boundary blocks emergency admin role assumption despite the attached allow policyThe incident role seems fully privileged, but assumption still fails because the boundary silently caps effective access below the attached policy intent.SecurityAdvanced20 minProSECURITY-066JWKS cache on the API gateway stays stale after OIDC signing key rotationThe identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.SecurityAdvanced20 minProSECURITY-083KMS grant allows encrypt but one rotated alias points the application to a key without decrypt permissionThe secret path still looks valid, yet runtime failures begin because the alias now resolves to a different key than the policy and grants were built for.SecurityAdvanced20 minProSECURITY-100Vault seal migration completes on the leader but one standby still advertises stale recovery key requirementsThe cluster seems healthy, yet operational confusion persists because one standby node still reflects the previous seal-state assumptions after migration.SecurityAdvanced20 minProSECURITY-075An SCP allows the recovery service but blocks the dependent KMS decrypt call during restoreThe incident playbook launches correctly, but restore still fails because the organization policy forgot the downstream KMS permission the service actually needs.SecurityAdvanced22 minProSECURITY-087CloudTrail organization trail exists but one delegated admin account writes to an unmonitored bucket in another regionAudit coverage seems complete, yet one privileged path is effectively invisible because the delegated admin is using a destination outside the monitored collection pattern.SecurityAdvanced22 minProSECURITY-031IAM role trust policy rejects GitHub OIDC tokenThe workflow reaches the cloud provider, but the trust policy denies the token because the expected audience or subject does not match the actual issuer claims.SecurityIntermediate22 minProSECURITY-065Vault periodic token stops renewingThe workload starts normally, but long-lived sessions fail hours later because the renewal path assumed a parent-child token chain that no longer exists.SecurityAdvanced22 minProSECURITY-063KMS policy lets backup jobs encrypt but restore jobs cannot decrypt in the recovery accountBackups complete successfully, yet every restore attempt fails because the disaster-recovery account was never granted the full decrypt path for the same key.SecurityAdvanced23 minProSECURITY-090Vault unseal succeeds but one performance standby still serves stale auth configuration after leader failoverThe cluster looks healthy again, yet some login paths still fail because a standby node continues using old auth backend settings after control-plane leadership changed.SecurityAdvanced23 minProSECURITY-051JWKS key rotation reaches the web tier but one API pod still caches the old signerLogin works on some paths, yet token validation fails intermittently because one long-lived process never refreshed the current signing keys.SecurityAdvanced24 minProSECURITY-069Organization-wide CloudTrail is enabled but one region never uses the expected KMS keyAudit logging exists everywhere, yet one region violates the encryption standard because replication and key policy assumptions drifted apart over time.SecurityAdvanced24 minProSECURITY-060GuardDuty member onboarding failsThe delegated admin path looks correct, but one child account never enables the detector because organizational guardrails deny the role creation needed by the service.SecurityAdvanced26 minProSECURITY-032KMS alias resolves correctly but decrypt still fails for the app roleThe application can discover the key alias and reach KMS, yet decrypt operations fail because the key policy and IAM policy do not grant the same effective path.SecurityAdvanced26 minProSECURITY-037Least-privilege refactor breaks cross-account accessA role assumption path worked before the permission cleanup, but third-party or cross-account access now fails because the new trust conditions no longer align with the expected external ID flow.SecurityAdvanced27 minProSECURITY-009Mutual TLS works on primary path but fails after east-west failoverCertificates and policies look valid, but the fallback service path presents a different trust context and breaks authentication.SecurityAdvanced29 minPro