Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

IDENTITY SECURITY · LAB

Guard recovery with fresh checks and a gated help desk reset

See a stale session refused when it tries to change a sign-in method, confirm the owner is emailed, and give Ben a help desk role whose reset permission the tenant checks on every request.

Partly readyUses your lab tenant

The lesson

Builds on: Threat modeling an identity system.

New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.

Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.

Your progress

Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.

  1. A stale session cannot add a sign-in method

    Recorded as account.security rejected (reauthentication_required).

  2. A fresh session adds the authenticator app

    Recorded as account.security succeeded (method_enrolled).

  3. Give the help desk role the reset permission

    Recorded as tenant.roles.update succeeded.

  4. Ben resets Mia's sign-in methods

    Recorded as tenant.users.methods.reset succeeded.

  5. Ben's reset is refused after the permission is removed

    Recorded as tenant.users.methods.reset rejected.

Setup

  1. Press Start on this page.

  2. In Roles, create a role named lab-support with only the permission to list tenant users (tenant.users.read).

  3. In Users, open Ben and give him the lab-support management role. Set an administrator password for Ben if he does not have one.

  4. Sign in as Ben at $ISSUER/login in a private window. The tenant asks role holders for a second step, so Ben is asked to set one up. Enroll an authenticator app for him.

  5. Make sure Mia (from the Threat modeling lab) can sign in with her password, and that Authenticator app is Optional in Authentication.

Walkthrough

  1. Sign in as Mia at $ISSUER/login. Leave the session open for more than 10 minutes, then try to add an authenticator app at $ISSUER/account/security. The page says to confirm it is you first.

Why it matters: the lesson says changing a recovery channel or sign-in method needs the same fresh check as signing in. A session alone, however it was obtained, is not enough to add a way back in.

  1. Sign out, sign in as Mia again, and add the authenticator app within a few minutes. It succeeds. Check Mia's inbox: a method-changed notice has arrived.

Why it matters: the lesson's "making recovery visible." A notice to a channel the owner already has gives the real owner a chance to say "this wasn't me" while it still matters.

  1. In Ben's private window, open $ISSUER/manage and then Users. Ben can list users, but he has no action to reset a user's sign-in methods.

Why it matters: assisted recovery is privileged access. A help desk role should hold exactly what the help desk does, granted on purpose.

  1. As yourself (Tenant Admin), edit lab-support and add the permission to reset users' sign-in methods (tenant.users.methods.reset). In Ben's window, refresh Users. The reset action now appears.

Why it matters: the tenant evaluates Ben's current role assignments on each request. The new permission works without Ben signing in again, and its removal will too.

  1. Before Ben acts, write down the procedure he must follow, as the lesson describes: call Mia back on the number on record, never a number the caller gives; ask a second person to approve resets on privileged accounts; never ask for, read out or forward a password, code or link.

Why it matters: the tenant provides the tool and checks who may use it. The procedure decides whether the person on the phone deserves it, which software cannot check for Rowan.

  1. As Ben, reset Mia's sign-in methods. In Mia's window, refresh $ISSUER/account: her session has ended. Sign in as Mia with her password: her authenticator app is gone and she is offered enrollment again. Her inbox has a notice that her methods were reset.

Why it matters: the lesson says recovery should replace what was lost, not everything at once. An administrator reset clears enrolled methods and recovery codes and ends every session, but leaves the password, so the person can sign in the usual way and enroll again.

  1. In Audit, source User directory, open the tenant.users.methods.reset event. It names Ben as the actor and Mia as the subject, and holds no secret values.

Why it matters: resets done by support need their own review. The lesson asks for who acted and which account changed; Ben's record answers both.

Break it

  1. Keep Ben's Users page open. As Tenant Admin, remove the reset permission from lab-support again. As Ben, without refreshing, try to reset Mia's methods once more. The tenant refuses it, even though the button was still on Ben's screen.

Why it matters: authority is checked when the request arrives, not when the page loaded. Removing the permission is the restore step, so nothing else needs undoing.

Check your work

  • Check my progress confirms the refused stale change, the fresh enrollment, the role update, Ben's reset and the refusal after removal.

  • In Audit, source User directory, the refused reset shows reason access_denied with Ben as the actor.

  • In Audit, source Protocol activity, Mia's account.security events show reauthentication_required and then method_enrolled.

Cleanup

  • Keep lab-support with only tenant.users.read, assigned to Ben. Later labs build on it.

  • Mia can enroll her authenticator app again at her next sign-in, or skip it.

Missing infrastructure

  • G37: the tenant does not notify a previous address after an email change, has no waiting period before a full recovery takes effect, and cannot restrict an account for the first hours after recovery. Once it exists, the lab will change Mia's address and confirm the old address is told, then try to add a second method during the restricted window and see it refused.

  • G34: re-proofing someone who has lost every method, in person or on a video call with a document, is not available. The help desk procedure you wrote is the substitute. Once it exists, the lab will send Mia a proofing request before Ben may reset her methods.

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab