IDENTITY SECURITY · LAB
Guard recovery with fresh checks and a gated help desk reset
See a stale session refused when it tries to change a sign-in method, confirm the owner is emailed, and give Ben a help desk role whose reset permission the tenant checks on every request.
Partly readyUses your lab tenant
The lesson
Builds on: Threat modeling an identity system.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.
- G34 Identity proofing
- G37 Security context in Audit (network, device, session, method; subject on failed sign-ins) and user "this wasn't me" reporting
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
A stale session cannot add a sign-in method
Recorded as
account.securityrejected (reauthentication_required).A fresh session adds the authenticator app
Recorded as
account.securitysucceeded (method_enrolled).Give the help desk role the reset permission
Recorded as
tenant.roles.updatesucceeded.Ben resets Mia's sign-in methods
Recorded as
tenant.users.methods.resetsucceeded.Ben's reset is refused after the permission is removed
Recorded as
tenant.users.methods.resetrejected.
Setup
Press Start on this page.
In Roles, create a role named
lab-supportwith only the permission to list tenant users (tenant.users.read).In Users, open Ben and give him the
lab-supportmanagement role. Set an administrator password for Ben if he does not have one.Sign in as Ben at
$ISSUER/loginin a private window. The tenant asks role holders for a second step, so Ben is asked to set one up. Enroll an authenticator app for him.Make sure Mia (from the Threat modeling lab) can sign in with her password, and that Authenticator app is Optional in Authentication.
Walkthrough
Sign in as Mia at
$ISSUER/login. Leave the session open for more than 10 minutes, then try to add an authenticator app at$ISSUER/account/security. The page says to confirm it is you first.
Why it matters: the lesson says changing a recovery channel or sign-in method needs the same fresh check as signing in. A session alone, however it was obtained, is not enough to add a way back in.
Sign out, sign in as Mia again, and add the authenticator app within a few minutes. It succeeds. Check Mia's inbox: a method-changed notice has arrived.
Why it matters: the lesson's "making recovery visible." A notice to a channel the owner already has gives the real owner a chance to say "this wasn't me" while it still matters.
In Ben's private window, open
$ISSUER/manageand then Users. Ben can list users, but he has no action to reset a user's sign-in methods.
Why it matters: assisted recovery is privileged access. A help desk role should hold exactly what the help desk does, granted on purpose.
As yourself (Tenant Admin), edit
lab-supportand add the permission to reset users' sign-in methods (tenant.users.methods.reset). In Ben's window, refresh Users. The reset action now appears.
Why it matters: the tenant evaluates Ben's current role assignments on each request. The new permission works without Ben signing in again, and its removal will too.
Before Ben acts, write down the procedure he must follow, as the lesson describes: call Mia back on the number on record, never a number the caller gives; ask a second person to approve resets on privileged accounts; never ask for, read out or forward a password, code or link.
Why it matters: the tenant provides the tool and checks who may use it. The procedure decides whether the person on the phone deserves it, which software cannot check for Rowan.
As Ben, reset Mia's sign-in methods. In Mia's window, refresh
$ISSUER/account: her session has ended. Sign in as Mia with her password: her authenticator app is gone and she is offered enrollment again. Her inbox has a notice that her methods were reset.
Why it matters: the lesson says recovery should replace what was lost, not everything at once. An administrator reset clears enrolled methods and recovery codes and ends every session, but leaves the password, so the person can sign in the usual way and enroll again.
In Audit, source User directory, open the
tenant.users.methods.resetevent. It names Ben as the actor and Mia as the subject, and holds no secret values.
Why it matters: resets done by support need their own review. The lesson asks for who acted and which account changed; Ben's record answers both.
Break it
Keep Ben's Users page open. As Tenant Admin, remove the reset permission from
lab-supportagain. As Ben, without refreshing, try to reset Mia's methods once more. The tenant refuses it, even though the button was still on Ben's screen.
Why it matters: authority is checked when the request arrives, not when the page loaded. Removing the permission is the restore step, so nothing else needs undoing.
Check your work
Check my progress confirms the refused stale change, the fresh enrollment, the role update, Ben's reset and the refusal after removal.
In Audit, source User directory, the refused reset shows reason
access_deniedwith Ben as the actor.In Audit, source Protocol activity, Mia's
account.securityevents showreauthentication_requiredand thenmethod_enrolled.
Cleanup
Keep
lab-supportwith onlytenant.users.read, assigned to Ben. Later labs build on it.Mia can enroll her authenticator app again at her next sign-in, or skip it.
Missing infrastructure
G37: the tenant does not notify a previous address after an email change, has no waiting period before a full recovery takes effect, and cannot restrict an account for the first hours after recovery. Once it exists, the lab will change Mia's address and confirm the old address is told, then try to add a second method during the restricted window and see it refused.
G34: re-proofing someone who has lost every method, in person or on a video call with a document, is not available. The help desk procedure you wrote is the substitute. Once it exists, the lab will send Mia a proofing request before Ben may reset her methods.