Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Log authentication attempts #1254

Closed
tsundvoll opened this issue Dec 12, 2023 · 3 comments
Closed

Log authentication attempts #1254

tsundvoll opened this issue Dec 12, 2023 · 3 comments
Labels
improvement Improvement to existing functionality stale This issue or pull request already exists

Comments

@tsundvoll
Copy link
Contributor

tsundvoll commented Dec 12, 2023

Describe the improvement you would like to see
Log authentication attempts when a user tries to authenticate towards Flotilla (also when the authentication fails)

How will this change existing functionality?
No functional change for the user. Operations team will get better overview of usage.

How will this improvement affect the current Threat Model?
Increases overview of the usage of the application, the operations team can see if there has been a lot of authentication attempts.

@tsundvoll tsundvoll added the improvement Improvement to existing functionality label Dec 12, 2023
@eivindsjovold
Copy link
Contributor

We log authentication attempts in the respective managed identities(linked to app registration) in Azure AD. There should be some setting to bundle this logging with the AI, I propose we investigate this pattern.

@aeshub
Copy link
Contributor

aeshub commented Feb 17, 2024

This issue has automatically been marked as stale as there has been no activity for 60 days.

@aeshub aeshub added the stale This issue or pull request already exists label Feb 17, 2024
@tsundvoll
Copy link
Contributor Author

We log authentication attempts in the respective managed identities(linked to app registration) in Azure AD. There should be some setting to bundle this logging with the AI, I propose we investigate this pattern.

Great, I was not aware. This seems sufficient for now. I dont think we need or want to also log this in Application Insights, so I will close this issue.

What we may want in the future is some automatic report / notification if there is a lot of unknown / unsuccessful authentication attempts in a short period of time

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
improvement Improvement to existing functionality stale This issue or pull request already exists
Projects
None yet
Development

No branches or pull requests

3 participants