ILP Risk Score Integration for IdP Session Management
This feature introduces ILP risk score awareness into the IdP session lifecycle. Currently, when a threat is detected during session validation, the system can only revoke the session or continue it — with no consideration of actual risk level. This feature closes that gap.
What it does:
The ILP risk score retrieved during session validation and used to drive the action taken on the session. Administrators can to force the user to re-authenticate, or revoke the entire IdP session. The risk score and confidence level are also stored on the session record in Elasticsearch and displayed on the IdP audit screen, giving security teams visibility into the risk profile of active and historical sessions.
The new toggle that decide if we force auth or revoke completely the session is under Identity Provider on a new section named Session binding (this section comes with session-binding.json too)
To be more clear about the high risk score, we added on the IdP authentication session, the high risk score and confidence of it: