Topic87 problems· 6 reviewed

Identity and Access Management

87 incident problems about Identity and Access Management. Start with the reviewed ones.

All problems (87)

SECURITY-141A SAML assertion signs correctly, but the audience URI casing changed during the domain move and one service provider rejects only mixed-case callbacksIdentity proof is valid, yet string normalization assumptions differ between the two ends.SecurityAdvanced16 minProSECURITY-142A break-glass account is excluded from conditional access, but the session lifetime policy still revokes it before the maintenance task finishesThe account bypasses the main gate, yet another identity control still constrains the operation.SecurityAdvanced17 minProSECURITY-132A GitHub App remains installed after a repository transfer, but the new organization grant was never approved and installation tokens lose repository scopeAutomation still exists, yet the trust boundary around the repo changed in a way the app permissions did not follow.SecurityAdvanced17 minProSECURITY-123A named location in conditional access misses the new SD-WAN egress IP range, and compliant users are suddenly blocked after failoverIdentity posture is good, but network identity changed underneath the access policy.SecurityAdvanced17 minProSECURITY-162A signed identity response is valid while one relying party rejects its audience string under different normalization rules during a failover rehearsalTrust succeeds cryptographically and string semantics still break the session. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced17 minProSECURITY-363An app registration is disabled while device code or brokered sessions on managed endpoints still rehydrate delegated access from existing trust state during a staged decommissionNew logins are blocked and managed-session reuse keeps access alive. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced17 minProSECURITY-145An OAuth consent app was disabled, but an existing refresh token continues minting new access tokensInteractive login is blocked, yet delegated API access survives through a token lifecycle gap.SecurityAdvanced17 minProSECURITY-133Passwordless FIDO works on the web portal, but the legacy VPN RADIUS mapping still expects the old UPN suffix and rejects the sessionModern identity succeeds in one channel while a legacy gateway still anchors on an outdated identity format.SecurityAdvanced17 minProSECURITY-130SCIM soft-delete disables the account in the app, but a nested group from a secondary directory sync still grants access through another routeOffboarding looks complete in the primary system, yet effective authorization still arrives from a parallel identity feed.SecurityAdvanced17 minProSECURITY-115The OAuth device flow trusted-client list still includes a test app and users can bypass the normal consent reviewThe production app is locked down, yet the device flow stays open because an old trusted client registration survived the environment cleanup.SecurityAdvanced17 minProSECURITY-119A CASB session rule blocks downloads in the browser, but the desktop client uses a direct API token path that bypasses the web controlThe browser looks governed, yet data still leaves the tenant because another client channel was never put behind the same session controls.SecurityAdvanced18 minProSECURITY-222A conditional access policy requires compliant devices while cross-tenant claims are minted by the wrong tenant context during a failover rehearsalThe rule is correct in principle and one federated identity path never carries the expected compliance signal. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-264A Vault policy grants transit encryption while the wrapped response workflow strips the unwrap capability from operators during a failover rehearsalThe crypto permission exists and the operational path to use it is incomplete. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-300An OAuth client is disabled while previously issued refresh tokens continue minting delegated access for mobile or desktop clients during a failover rehearsalInteractive sign-in is gone and token lifecycle gaps keep API access alive. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-246An OAuth logout clears browser state while mobile refresh tokens remain active for the same account during a failover rehearsalThe user appears signed out and another client class keeps working as before. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-106An OPA policy package rename leaves the fallback allow rule active in one cluster after a partial config rolloutMost clusters enforce the new package, but one environment silently drops into the default allow behavior because its bundle path never updated.SecurityAdvanced18 minProSECURITY-186Interactive login is disabled while refresh tokens already issued still mint delegated access during a failover rehearsalThe application is gone for humans while API access remains alive through token lifecycle gaps. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-101SAML audience matches, but ACS URL normalization drops the trailing slash and the login flow loops between the app and IdPAuthentication succeeds at the identity provider, yet the application rejects the response because the callback URL comparison is stricter than the team expected.SecurityAdvanced18 minProSECURITY-126Vault dynamic database credentials expire before a long-running transaction completes, and the application reports random commit failuresSecrets are rotated safely, but workload runtime exceeds the lease model the security design assumed.SecurityAdvanced18 minProSECURITY-011Reverse proxy strips security header needed for SSO callbackThe identity provider finishes correctly, but the application rejects the callback because a forwarded security header never arrives.SecurityIntermediate22 minPro