Implementing Multifactor Authentication: Protect your applications from cyberattacks with the help of MFA
Book information
Description
Avoid MFA pitfalls—learn how to choose, implement, and troubleshoot MFA in your company Purchase of the print or Kindle book includes a free PDF eBook Key FeaturesGain proficiency in using solutions like Okta, Ping Identity, and ForgeRock within the IAM domainThwart authentication breaches using pragmatic strategies and lessons derived from real-world scenariosChoose the right MFA solutions to enhance your organization's securityBook Description In the realm of global cybersecurity, multifactor authentication (MFA) has become the key strategy; however, choosing the wrong MFA solution can do more harm than good. This book serves as a comprehensive guide, helping you choose, deploy, and troubleshoot multiple authentication methods to enhance application security without compromising user experience. You'll start with the fundamentals of authentication and the significance of MFA to gradually familiarize yourself with how MFA works and the various types of MFA solutions currently available. As you progress through the chapters, you'll learn how to choose the right MFA setup to keep the user experience as friendly as possible. The book then takes you through the different methods hackers use to bypass MFA and measures to safeguard your applications. Next, with the help of best practices and real-world scenarios, you'll explore how MFA effectively mitigates cyber threats. Once you've learned how to enable and manage MFA models in public clouds such as AWS, Azure, and GCP, you'll discover the role of biometrics in the MFA landscape and gain insights into the upcoming wave of innovations in this field. By the end of this MFA book, you'll have the knowledge required to secure your workforce and customers using MFA solutions, empowering your organization to combat authentication fraud. What you will learnEvaluate the advantages and limitations of MFA methods in use todayChoose the best MFA product or solution for your security needsDeploy and configure the chosen solution for maximum effectivenessIdentify and mitigate problems associated with different MFA solutionsReduce UX friction with ForgeRock and behavioral biometricsStay informed about technologies and future trends in the fieldWho this book is for This book is for developers, system administrators, security professionals, white-hat hackers, CISOs, and anyone interested in understanding and enhancing their access management infrastructure. While basic knowledge of authentication and IAM is helpful, it is not a prerequisite. Table of ContentsOn the Internet, Nobody Knows You're a DogWhen to Use Different Types of MFAPreventing 99.9% of Attacks – MFA with Azure AD and DuoImplementing Workforce and Customer Authentication Using OktaAccess Management with ForgeRock and Behavioral BiometricsFederated SSO with PingFederate and 1KosmosMFA and the Cloud – Using MFA with Amazon Web ServicesGoogle Cloud Platform and MFAMFA without Commercial Products – Doing it All Yourself with KeycloakImplementing MFA in the Real WorldThe Future of (Multi-Factor) Authentication Cover Title Page Copyright and Credit Dedicated Contributors Table of Contents Preface Part 1: Introduction Chapter 1: On the Internet, Nobody Knows You’re a Dog Identity and digital identity Workforce identity Customer identity Additional authentication and security controls What are authentication factors? Summary Chapter 2: When to Use Different Types of MFA Not all MFA is created equal – when to use different types of MFA Why use MFA then? Different types of MFA SIM swap and why SMSs and voice messages are the weakest authenticator factor types to use What can the service provider do? What can the user do? MFA fatigue – also known as MFA push spam What can the service provider do? Phishing-resistant MFA Keeping up with bad actors – good sources for up-to-date information on MFA and related topics Cybersecurity and Infrastructure Security Agency National Institute of Standards and Technology National Security Agency Summary Part 2: Implementing Multifactor Authentication Chapter 3: Preventing 99.9% of Attacks – MFA with Azure AD and Duo Technical requirements Azure AD setup Enabling SAML-based SSO for enterprise applications Adding an enterprise application Assigning a user account to the Acme’s Azure AD SAML Toolkit application Enabling SAML-based SSO for the Acme’s Azure AD SAML Toolkit application Configuring SSO for the Acme’s Azure AD SAML Toolkit application Testing SSO in the Acme’s Azure AD SAML Toolkit application MFA on Azure AD Disabling default security CA policies Configuring the conditions for MFA Testing Azure AD MFA Enabling combined security information registration in Azure AD What is Duo and why use it? Integrating Duo and Microsoft Azure AD Using the Duo custom control Testing Duo Summary Chapter 4: Implementing Workforce and Customer Authentication Using Okta Technical requirements Workforce Identity with Okta Creating a Workforce Identity account Signing into your Workforce Identity account for the first time Configuring Okta The essentials Configuring authenticators Requiring MFA to access Okta Workforce Identity apps Customer Identity with Okta Customer Identity administration Testing Okta’s Customer Identity solution Requiring MFA to access Okta Customer Identity apps Summary Chapter 5: Access Management with ForgeRock and Behavioral Biometrics Technical requirements Experiencing ForgeRock Creating a ForgeRock software platform account Signing into your backstage account for the first time Installing ForgeRock Access Manager Configuring ForgeRock’s Access Manager (openam) Using openam Protecting a Java application using openam Installing the Tomcat Java Agent Protecting a web application Testing the Java Agent Introducing Authentication Trees Installing a Duo authentication node Configuring authentication with a Duo authentication node Configuring self-registration in openam Testing self-registration and MFA What are behavioral biometrics? Installing BehavioSec Configuring authentication with BehavioSec Testing authentication with BehavioSec and Duo Summary Chapter 6: Federated SSO with PingFederate and 1Kosmos Technical requirements Experiencing Ping Identity’s PingFederate Installing PingFederate Configuring Ping Identity’s PingFederate Deploying sample applications in PingFederate What is passwordless MFA? Integrating BlockID and PingFederate Testing authentication with BlockID Summary Chapter 7: MFA and the Cloud – Using MFA with Amazon Web Services Technical requirements AWS IAM An AWS account is not a user account Workforce identities on AWS AWS IAM Identity Center (successor to AWS Single Sign-on) Customer Identity and Access Management on AWS AWS Cognito Summary Chapter 8: Google Cloud Platform and MFA Technical requirements Google Cloud Identity Setting up Cloud Identity Managing user accounts and administrative functions Setting up MFA in Cloud Identity Testing MFA enforcement in Cloud Identity Google Cloud Identity Platform BeyondCorp Summary Chapter 9: MFA without Commercial Products – Doing it All Yourself with Keycloak Technical requirements What is Keycloak? Running Keycloak using Docker Running Keycloak using Java Keycloak administration Using Keycloak for SSO Creating and deploying sample applications in Keycloak Keycloak and MFA MFA with required OTP MFA with OTP or passwordless WebAuthn Summary Part 3: Proven Implementation Strategies and Deploying Cutting-Edge Technologies Chapter 10: Implementing MFA in the Real World Technical requirements Understanding the business side of cybersecurity Cybersecurity policy Strengthening cybersecurity Cybersecurity is a never-ending process Are password managers a solution for password risks? Identifying alternatives to passwords Strategies for implementing MFA Eliminating passwords should be the goal Get the right people Focus on three use cases Summary Chapter 11: The Future of (Multi-Factor) Authentication Technical requirements Introducing the Web3 ecosystem Exploring digital identity in Web3 Understanding login mechanisms Implementing decentralized solutions Product trends Verifiable Credentials and Microsoft Entra Verified ID Identity management convergence in ForgeRock Identity Cloud Are passkeys (almost) the perfect phishing-resistant MFA? Passkey management Continuous authentication What lies ahead Summary Appendix A – Installing the Java Software Development Kit Installing the Java SDK on Windows Using the installer on Windows Installing the Java SDK manually on Windows Installing the Java SDK on a Mac Using Homebrew to install OpenJDK 11 on a Mac Installing the Java SDK manually on a Mac (or Linux) Testing the install of the Java JDK Summary Appendix B – Custom App Integration with Azure AD Technical requirements Enabling SSO for custom web applications Add a non-gallery enterprise application Assign a user account to the SAML Springtest application Enabling SSO for Acme’s Azure AD SAML Toolkit application Configure SSO in the SAML Springtest app Testing the new custom app Testing SSO with Acme’s Azure AD SAML Toolkit application and the Springtest app Summary Appendix C – Installing Apache Tomcat Software Installing Apache Tomcat Installing Apache Tomcat on Windows using the installer Installing Apache Tomcat 9 on a Mac Using Homebrew to install Apache Tomcat 9 on a Mac Installing Apache Tomcat 9 manually on a Mac (or a Linux server) Summary Index Other Books You May Enjoy
Similar books
Implementing Multifactor Authentication
2023 · EPUB
Implementing Multifactor Authentication: Protect your applications from cyberattacks with the help of MFA
2023 · RAR
Implementing Multifactor Authentication: Protect your applications from cyberattacks with the help of MFA
2023 · PDF
EXCEL 2023 CRASH COURSE: Master Excel 2023 With This Complete Crash Course In 7 Days
2022 · EPUB
The arraignment and tryall with a declaration of the Ranters also, several sentences proceedings at the sessions in the Old-Baily, and Councel of War: their protestations and the hanging of one up by the thumbs; with divers penalties to be inflicted upon others. The dancing and revelling of Dr. Buckeridge and his wife, and other gent. dancing all in white, in Berkshire, and their Christmas carol. A dispute between a Ranter in Bridewel, and one that came to see him; with his creed and pater noster: and the names of the false gods they worship. As also, a list of many of the Ranters, from whence they are derived: and of many hundreds of them in England
2019 · EPUB
The discoverer; vvherein is set forth (to undeceive the nation) the reall plots and stratagems of Lievt. Col. John Lilburn, Mr. William Walwyn, Mr. Thomas Prince, Mr. Richard Overton, and that partie ... Namely, under the pretence and colour of libertie ... a most dangerous and destructive designe is carried on to deprive the nation of their religion, rights, liberties, proprieties, lawes, government, &c. and to bring a totall and universall ruine upon the land. And so much is here clearely proved. The first part
2019 · EPUB
An act to impower Sir John Molesworth: Baronet, and Joseph Moyle, Esquire, Two of the surviving Trustees, in an Indenture, dated the Twenty-Fifth Day of December One thousand Seven hundred and Forty-Three, to raise the several Sums in the said Indenture mentioned, or such of them as are still unsatisfied, and pay the same, as well as the rest of the personal Estate of Hugh Gregor, deceased, to such Person as Jane Gregor, an Infant, shall marry during her Infancy, with the Consent of the surviving Trustees, and of her Guardians
EPUB
Case Histories
2008 · EPUB