Why: Centralizing applications behind the identity provider — a step the MFA rollout forces — is what makes unique identification, authentication, and re-authentication enforceable in one place; session lifetime and sign-in frequency policy is where the re-authentication parameter gets implemented.
What this does not claim: The requirement covers every access path and adds organization-defined re-authentication circumstances the practice does not itself choose. Paths that never join the identity provider — local accounts, appliances — and the association of unique identities with running processes must be evaluated separately within the defined system boundary.
- Move applications behind single sign-on as MFA enforcement expands
- Configure session lifetime and re-authentication policy in the identity provider
- SSO application register
- Session and re-authentication policy exports
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06