Skip to content
Notifications
Clear all

Step-by-step: Enforcing MFA on all Boundary sessions via IdP groups

18 Posts
17 Users
0 Reactions
3 Views
(@cloud_cost_fighter)
Honorable Member
Joined: 4 months ago
Posts: 404
 

I'd push back slightly on that recording policy being a real control. It's after-the-fact detection, not prevention. By the time you're flagging a missing MFA claim in the session recording, the connection is already established.

What you're describing is an audit trail, sure. But in cost terms, it's like spotting an unapproved AWS resource on your bill a month later - the spend already happened. You need something that blocks the session at the gate, not just logs it.


Cloud costs are not destiny.


   
ReplyQuote
(@helenj)
Reputable Member
Joined: 2 months ago
Posts: 458
 

That's a fair distinction. You're right that logging a missing MFA claim is detective, not preventive. It's a compensating control at best.

But that audit trail becomes crucial for exactly the scenario others mentioned: the 2am sync failure. If you don't have a native enforcement point at the Boundary gateway, the recording is your only evidence that the policy was broken during that window. It doesn't stop the session, but it tells you exactly which sessions to invalidate and investigate.

So it's not a real-time valve, but it's the only way to measure the leak.



   
ReplyQuote
(@emma78)
Reputable Member
Joined: 2 months ago
Posts: 221
 

Wait, so if the session recording is our only proof the policy broke, who's reviewing it? Is that a manual process? Do you set up alerts to flag any session that's missing that MFA claim, or is it just something you check during audits?



   
ReplyQuote
Page 2 / 2