
π Cybersecurity Β· Sequence
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
Drawing diagramβ¦
SAML SSO sequence: the employee opens the SaaS app, which sees an unauthenticated user from the company domain and redirects the browser to the identity provider with a SAML AuthnRequest. The IdP checks for an existing session; if none, it asks for password and MFA and applies conditional access (managed device). The IdP posts a signed SAML assertion back to the app's assertion consumer service, the app validates the signature and creates a session.
sequenceDiagram actor E as Employee participant B as Browser participant SP as SaaS App participant IdP as Identity Provider E->>SP: Open app SP-->>B: Redirect with SAML AuthnRequest B->>IdP: AuthnRequest IdP->>E: Password E-->>IdP: Password IdP->>E: MFA push E-->>IdP: Approve IdP->>IdP: Conditional access: managed device OK IdP-->>B: Signed SAML assertion (POST) B->>SP: Assertion to ACS URL SP->>SP: Validate signature and audience SP-->>E: Logged in
A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.
The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.