Skip to main content
Identity provider

Identity provider

Search complete. 10 mentions across 5 episodes found for "Identity provider".

Oct 9, 2026

William SmithGUEST
51:05
I saw Mark there.
William SmithGUEST
51:06
Uh, he asked, "Can rings be based on intra IDP group, intra ID or IDP groups, like an identity provider?" Good question.
William SmithGUEST
51:15
I have no idea.
William SmithGUEST
51:17
Um, I haven't heard that one.
Tom BridgeHOST
63:35
I actually think that that's a smart thing to add to the platform because it opens things up.
Tom BridgeHOST
63:39
But it also means that Apple has to maintain developer relations with its IDP partners.
Tom BridgeHOST
63:45
And my hope is that we start to see those things roll out as we come into the future here.
Tom BridgeHOST
63:50
Um, I certainly know that, you know, friend of the pod, Joel Renick was talking about it this summer a lot in the, you know, the various beta, you know, forums for this kind of stuff.
Tom BridgeHOST
65:23
mean, this is what's holding me back from doing
Marcus RansomHOST
65:24
it,
Tom BridgeHOST
65:25
right? Like, I mean, I don't have an IDP.
Tom BridgeHOST
65:27
My IDP is Google Workspace because that's all we need right now.
Martin RaeppleGUEST
19:04
Later on, I as a user logging or I as an approver in that workflow in IG, I log into the IG tenant that always goes via the Cloud Identity Services.
Martin RaeppleGUEST
19:15
As you can see here on this diagram, In my demo environment, the Cloud Identity Services tenant is configured as a corporate proxy or an IDP proxy that proxies via the OIDC protocol to the Entra tenant.
Martin RaeppleGUEST
19:34
So when I later on log in as the approver, I'm silently forwarded here through the proxy to Entra and log in as a user here with my credentials.
Martin RaeppleGUEST
19:47
So provisioning then finally, once the user has successfully or has been approved access in IAG, provisioning then also takes place from IAG all the way through the connectivity service by using a destination that goes all the way to the cloud connector and then finally to the backend system and will assign the the technical role or the PFCG role, in this case, SAP BC EPM demo, which is contained in that business role.

13 MINS LATER

speaker_2UNKNOWN
33:27
All right.
speaker_2UNKNOWN
33:28
And again, I'm logging
Martin RaeppleGUEST
33:30
in through the corporate IDP proxy in IIS.
Martin RaeppleGUEST
33:35
And I'm always using my credentials in the Android tenant for any user.
Howard TingGUEST
27:10
So we have to do the best we can.
Howard TingGUEST
27:13
And in some cases, we'll... piggyback off of the IDP, whether it's Okta or Entra or something like that, and we'll manage the groups.
Howard TingGUEST
27:22
And ultimately, that's what's managing access into the target systems.
Howard TingGUEST
27:26
But the best scenario is always where we have a direct connector.

7 MINS LATER

Howard TingGUEST
34:33
I need access to this customer's database because I'm working on this ticket or incident for them.
Howard TingGUEST
34:40
The AI will go and look to see, is there a ticket, active ticket for that customer? Is this the engineer that's assigned? Does this level of access that's requested match the incident and, you know, what the incident needs to resolve? And so the AI can go do all that research, you know, fetch all of the context from the ticketing system, messaging apps, everything.
Howard TingGUEST
35:03
Obviously, look inside the IDP and it will evaluate all that.
Howard TingGUEST
35:08
So it shows all that reasoning that we do and brings all that context and packages in a very simple to digest format and presents it all in a very consumable manner to the human.
Marc LaliberteHOST
23:35
And basically how the attackers got in is they created their own Brevo account and set up single sign-on to a SAML identity provider.
Marc LaliberteHOST
23:43
They then invited legitimate Brevo users in other accounts into their tenant.
Marc LaliberteHOST
23:50
If those Brevo users accepted the invite, the, uh, the attacker could use SAML single sign-on from their IDP that they controlled to log in as that other user.
Marc LaliberteHOST
24:01
Where the issue was is that should have let them log in as that user in their tenant, the attacker's tenant.
Marc LaliberteHOST
24:07
But due to some scoping issues, it allowed them to log in as that user in any tenant that that user had access to.
Marc LaliberteHOST
24:21
Yep, exactly.
Marc LaliberteHOST
24:22
Says Uh, it makes sense.
Marc LaliberteHOST
24:24
If you control the IDP, you control being able to log in as that user in the IDP.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.