Air-gapped MFA under §30 BSIG: how a German public body authenticates without the cloud
Some environments are built to have no way out. No outbound path to the internet, no cloud callback, no dependency a network operator cannot see and control. For the teams who run them, that isolation is the security control, and anything added inside has to …
Before and after: how a French local authority brought MFA and SSO to every access path, without leaving its on-premise Active Directory
A French local authority runs its identity infrastructure the way a great many public bodies do: an on-premise Active Directory at the centre, and a workforce of more than a thousand staff authenticating against it. What sat on top of that directory, however, had grown …
Combining Smartcard and FIDO2 at Windows logon, even offline
A regional public-sector organisation in Europe came to us with a Windows estate that was already secured by smartcard logon. Its users carry smartcards, and some of them log in where there is no network: laptops that leave the building and spend hours with no …
VPN, bastions, servers: how a European data center applies MFA for every client
A provider that hosts other companies’ infrastructure does not have one set of users to protect. It has dozens, each belonging to a different organization, and each expecting that its identities, its policies and its administrators stay strictly separate from everyone else’s. Adding multi-factor authentication …