microsegment.io

segment all the things

The Login Worked. The Breach Did Not.

A stolen identity session should not become access to every application behind the identity provider

ReliaQuest's August 2026 social-engineering attempt shows why authentication is only the first policy decision. This article explains how device trust, per-application authorization, session controls, and microsegmentation contain a valid but hostile login.

Your Identity Provider Needs a Containment Boundary

When the signing key is the credential, MFA is no longer the control

Mandiant's new AD FS research shows why federation servers belong inside a Tier 0 containment boundary, with tightly governed management paths, explicit dependencies, and an incident plan built around signing-key compromise.