Why: The modern federated protocols the MFA rollout standardizes on — OIDC and SAML over TLS, with signed, time-limited assertions — protect the authenticity of the authentication sessions they establish, resisting hijacking and assertion replay on the paths the rollout converts.
What this does not claim: May partially address the requirement. Session authenticity spans every communications session in the boundary — TLS configuration, certificate validation, and session handling for applications, services, and infrastructure the identity rollout never touches — and post-authentication token theft remains a live attack the base protocols do not stop; token protection and session policy are separate work.
- Standardize applications on federated SSO with signed assertions
- Shorten token lifetimes and apply conditional session policies for sensitive applications
- Identity-provider session and token policy exports
- SSO protocol configuration showing assertion signing
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06