Identity & Access Security Operations

Articles about identity & access security operations from security operations practitioners.

Identity & Access Security Operations

MFA fatigue: what the SOC actually sees before the click

In my evaluations, the teams that catch MFA fatigue early aren't watching the push flood. They've already seen the infostealer hit, the credential-validation spike, the login from an unfamiliar IP days before the first prompt. The flood is the last stage worth catching, not the first.

DCDaniel C. · Sep 12, 2026
Identity & Access Security Operations

Ping SSO logs the SOC can't afford to skip

I stopped treating Ping as one SSO log source after watching a PingOne feed look healthy while missing the one field a detection needed. PingOne and PingFederate use different collection paths, schemas, and defaults. Before I build any identity detection now, I validate the raw fields the rule depends on, starting with source IP.

DCDaniel C. · Aug 28, 2026
Identity & Access Security Operations

Privileged access in 2026: from the investigation seat

I've led the review after every serious incident my teams handled in a decade. The board always asks how it got this bad, and the answer is rarely the initial phish; it's the next step, when the attacker gains the authority to reset MFA, change roles, and export data.

DCDaniel C. · Aug 22, 2026
Identity & Access Security Operations

Identity security posture management (ISPM): a working field guide

I inherited an identity attack surface last year that nobody could describe in a single sentence: an Entra tenant, a still-syncing AD forest, Okta for legacy SaaS, 60 unreviewed OAuth grants, and a service-account inventory in a stale spreadsheet. I now ask every ISPM vendor the same thing: which of my standing exposures do you find, and which one do you actually fix?

DCDaniel C. · Aug 8, 2026
Identity & Access Security Operations

MFA fatigue attacks: what the security SOC sees, what the user clicks

The case hit my queue at 2:40 am: an Okta identity with a string of push denials two minutes apart, then a single success from the same IP. My detection only counted failures, so it nearly slid past me. An MFA fatigue attack is really two attacks at once, one in the identity logs where the SOC can see it and one on a phone at 1 am where nobody can. Here is how I detect both.

MKMarta K. · Jul 17, 2026
Identity & Access Security Operations

Privileged access management from the SOC seat

I inherited a CyberArk rollout eighteen months in, vault live and compliance satisfied. When I asked what detection rules the team had built against the PAM logs in the SIEM, the answer was zero.

DCDaniel C. · Jun 5, 2026
Identity & Access Security Operations

Identity threat detection and response in plain English

ITDR isn't a new product category. It's the detection layer your EDR, SIEM, and NDR each see pieces of, and the gap is narrower than vendors imply.

DCDaniel C. · May 25, 2026

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Identity & Access Security Operations | Future of SecOps