ip-label is now officially part of ITRS. Read the press release.

ip-label is now officially part of ITRS. Read the press release.

MFA and Monitoring: securing access without losing sight of the user experience

01
MFA
& Access Security
Cybersecurity & monitoring

Securing access is no longer enough: you also need to make sure it works.

Securing access to information systems has become a major challenge for cybersecurity, data protection and regulatory compliance.

MFA
Strengthen authentication

Reduce the risk associated with compromised credentials

As cyberattacks and account compromises increase, organizations are progressively strengthening their authentication mechanisms. Among them, multi-factor authentication (MFA) plays a central role.

MON
Monitor the user journey

Security itself becomes a critical digital journey

Adding MFA introduces new steps into the login journey. It therefore becomes necessary to verify that these mechanisms remain available, functional and accessible to users.

Security × digital experience

More secure authentication that no longer works can become a point of failure for the entire service.

The challenge is therefore not only to deploy new security controls. Organizations must also be able to verify their operation over time and quickly detect anomalies that may prevent legitimate users from accessing applications.

MFA: access security under the CNIL’s scrutiny

Cybersecurity is playing an increasingly important role in CNIL inspections. Recent decisions highlight the importance of implementing security measures proportionate to the risks to which information systems and data are exposed.

Recent case
Protection of remote access

Sensitive access can no longer be considered independently of its level of protection.

A recent example concerns Hôpital privé de la Loire, which was sanctioned following a cyberattack that allowed an attacker to access a significant volume of personal and health data.

One of the weaknesses identified was remote access to patient records without a VPN or multi-factor authentication.

!
This case illustrates an important shift: beyond the mere existence of security mechanisms, organizations must also assess their robustness and actual effectiveness.

Access protection relies on several complementary layers.

Authentication is only one step in the chain. Effectively securing an information system requires combining access control, traceability, monitoring and detection capabilities.

01
Authenticate Verify the user’s identity.
02
Control Verify associated permissions.
03
Limit Restrict access to what is necessary.
04
Trace Maintain visibility over access activity.
05
Monitor Verify operation over time.
06
Detect Quickly identify anomalies.

What is multi-factor authentication?

Multi-factor authentication, or MFA, involves using multiple independent factors to verify a user’s identity before allowing them to access an application or system.

The objective is to reduce the risk that stolen credentials alone could allow an attacker to access an application or sensitive data.

01
Password or PIN
02
Smartphone or authentication app
03
Token or security key
04
Biometric verification
05
One-time code
Example authentication journey
Username + password
Second MFA factor
Access to the application
The new operational challenge

MFA secures access. But who verifies that the authentication journey is actually working?

By adding new steps to the login process, MFA transforms the user’s digital journey. Availability of the authentication service, display of the MFA prompt, second-factor validation or redirection to the application: each step can become a point of friction or failure. This is precisely the journey that now needs to be monitored.

02
Access journey
& availability
From security to accessibility

Securing access is one thing. Making sure it works is another.

When an organization deploys MFA, the access journey to an application becomes more complex. Each new security step also introduces a new potential dependency.

The actual user journey

Accessing an application is no longer simply about reaching a URL.

For example, a user may have to follow the journey below:

Access journey with MFA authentication
01 Application
02 Login page
03 Identity Provider
04 Credentials
05 MFA
06 Validation
07 Redirection
08 Business application
Chacune de ces étapes constitue une dependency. The business application itself may be fully available while users are unable to access it.
Where can the journey fail?

The issue can occur before the user even reaches the application.

A service disruption can originate from multiple components or steps within the authentication journey.

01
Authentication page unavailable Entry point
02
Identity Provider indisponible Identity Provider
03
Abnormally long authentication time Performance
04
Second-factor failure MFA
05
Incorrect redirection Navigation
06
Session expiration User session
07
Change to the login journey Application change
08
SSO issue Single Sign-On
09
Failure at an intermediate step User journey
Two different realities
Infrastructure view

Application operational

The servers are responding, the infrastructure is operational and the application may appear available.

User view

Service inaccessible

An issue with authentication, MFA, SSO or redirection can prevent the user from reaching the service.

The traditional question

“Is my application available?”

The real question becomes: “Can my users actually access it?”

End-to-end monitoring

MFA and monitoring: monitoring the entire access journey

The more complex authentication mechanisms become, the more important it becomes to monitor the experience end to end.

Synthetic Monitoring

Regularly test the journey as a real user would.

With a Synthetic Monitoring solution for the user experience, user journeys can be simulated regularly to verify that the different steps required to access a service are working correctly.

From availability to the business journey

The objective is no longer simply to monitor a URL or server availability.

01 Access
02 Authenticate
03 Complete the security steps
04 Reach the application
05 Perform a critical action
Traditional monitoring

Check the components

The URL, server, infrastructure or technical availability may all appear operational.

Experience monitoring

Verify the service actually delivered

Journey simulation helps identify issues that could remain invisible with monitoring focused solely on the infrastructure.

03
Ekara
& MFA Monitoring
Digital Experience Monitoring

What Ekara can bring as MFA becomes more widespread

With Ekara, organizations can integrate access and authentication journeys into a comprehensive Digital Experience Monitoring approach.

Visibility beyond authentication

Integrate authentication mechanisms into broader digital experience monitoring.

The challenge is not simply to know whether an MFA mechanism is responding. It is about understanding whether the user can complete all access steps, reach the expected service and perform the actions required for their work.

From journey monitoring to precise incident identification.

01
End-to-end monitoring

Monitor authentication journeys end to end

With Synthetic Monitoring, teams can simulate critical user journeys to regularly verify that they are working properly.

The objective is not to limit monitoring to the availability of the login page. Monitoring can cover different steps in the journey all the way through to access to the expected service.

Verify that a user is actually able to reach their application and perform the actions essential to their work.
Login
Identity Provider
MFA
Application
Business action
02
Proactive detection

Detect an issue before it impacts users at scale

A failure in an authentication mechanism can have a significant impact.

If the same Identity Provider or authentication system is used across multiple applications, a single anomaly can potentially affect multiple services.

Synthetic monitoring makes it possible to regularly execute journeys and quickly identify a failure or degradation.

IT teams can be alerted when a journey no longer works as expected, rather than waiting for user tickets to accumulate.
Journey executed regularly
Anomaly detected → IT alert
03
Performance

Measure access journey performance

An authentication journey can work without necessarily delivering a satisfactory experience.

An MFA step that takes too long, a particularly slow redirection or an Identity Provider with deteriorating response times can have a direct impact on the user experience.

Monitoring makes it possible to track the performance of the authentication journey, rather than only its success or failure.
IDP Response time
MFA Validation
SSO Redirection
04
Troubleshooting

Precisely identify the step causing the issue

When a user simply reports “I can’t log in,” diagnosis can be complex.

Is the issue coming from the application? The network? The Identity Provider? SSO? MFA? A redirection?

Detailed journey monitoring provides operational teams with more context to understand where the journey begins to degrade.

The objective: reduce the time required to identify the root cause of an incident and accelerate its resolution.
Application
Identity Provider
MFA ISSUE
Redirection
05
Continuous evolution

Maintain monitoring as security mechanisms evolve

Authentication systems are not static. An organization may decide to deploy MFA, change its Identity Provider, modify its access policies or evolve its SSO.

These changes can have a direct impact on existing monitoring scenarios.

When an MFA mechanism is introduced or modified, existing monitoring scenarios need to be adapted in order to continue reproducing real-world conditions for accessing digital services.

Ekara teams can support customers in adapting their monitoring journeys to take these changes into account and maintain continuous visibility over their critical services.
01 New MFA
02 New Identity Provider
03 SSO evolution
04 Monitoring adaptation
Ekara Studio · Flow AI

Evolve monitoring journeys using natural language.

Customers who want to evolve their journeys themselves can also use Ekara Studio’s Flow AI capability to integrate these changes from a description written in natural language.

Discover Flow AI
Flow AI

“Adapt my login journey to take the new MFA step into account before access to the application.”

Monitoring journey adapted
Continuous visibility

Secure access without losing sight of the experience actually delivered to users.

By integrating authentication mechanisms into monitored journeys, teams can detect failures, measure performance degradation, gain more context during incidents and adapt their monitoring lorsque les dispositifs mechanisms evolve.

04
Security
& Monitoring
A complementary approach

Monitoring as a complement to a security strategy

Ekara is not intended to replace cybersecurity solutions, IAM tools or MFA solutions. Its role is complementary.

SEC
Security tools

Protect access

Cybersecurity, IAM, MFA and access control solutions help strengthen the protection of applications and information systems.

MON
Monitoring

Verify access

Monitoring makes it possible to verify that access remains operational and performant from the user’s perspective.

A comprehensive strategy
MFA
IAM
SSO
Access control
Synthetic Monitoring
End-to-end observability
Enhanced security + continuous visibility into the user experience
Beyond availability

From security to digital resilience

The widespread adoption of MFA reflects a broader evolution of information systems. Applications are now surrounded by a growing number of services and dependencies.

01 Identity Provider
02 API
03 SaaS
04 Cloud
05 Networks
06 Authentication
07 Third-party components
A chain of dependencies

Application availability no longer depends solely on the application itself.

It depends on the entire chain that enables users to access and use it. This is why access security and observability must be considered together.

Build a resilient approach
01 Secure access
02 Monitor the journey
03 Detect anomalies
04 Measure performance
05 Alert
06 Analyze
07 Improve
This approach helps strengthen not only security, but also the resilience of digital services.
Security × visibility × experience

Enhanced security, visibility maintained

The growing adoption of multi-factor authentication addresses a key need: better protecting information systems against account compromise and unauthorized access.

The key point

Each new security layer also becomes a new component of the digital journey.

And anything that becomes critical to access must also become visible in monitoring.

With Ekara, organizations can monitor their digital journeys end to end, identify degradations and maintain visibility into actual access to their applications, including as their authentication mechanisms evolve.

Let’s talk about your journeys

Are you deploying MFA or evolving your authentication mechanisms?

Ekara teams can support you in analyzing the impact of these changes on your monitoring scenarios, adapting the relevant journeys and maintaining continuous monitoring of your critical services.

Analyze l’impact
Adapt the journeys
Maintain monitoring
Accessible · Available · Performant
Previous Post

Leave a Reply

Discover more from Ekara by ip-label

Subscribe now to keep reading and get access to the full archive.

Continue reading