- Managed device:
- The request comes from a machine the organisation administers.
- Phishing-resistant factor:
- A passkey or hardware key, not a code that can be read out.
- Expected country:
- The connection originates where the person is supposed to be.
- Recent re-authentication:
- The session was proved within the last few hours, not last month.
- Working hours:
- The request falls inside the hours that role normally works.
- Healthy device:
- Patch level and protection are current at the moment of asking.
An analyst at her desk
legitimateOpening the customer database on a Tuesday afternoon.
The easy case. Any policy allows it, which is why testing a rule against this one proves nothing.
Satisfies: Managed device, Phishing-resistant factor, Expected country, Recent re-authentication, Working hours, Healthy device.
A salesman in an airport
legitimateChecking the pipeline from the company laptop over hotel wifi.
Fails only the country condition. Whether that should block him is the first real decision a policy makes.
Satisfies: Managed device, Phishing-resistant factor, Recent re-authentication, Working hours, Healthy device.
A director on her own phone
legitimateApproving an expense claim on a Sunday evening.
Personal device, outside hours, patch level unknown. Strict policies block the person most able to overrule them.
Satisfies: Phishing-resistant factor, Expected country, Recent re-authentication.
A contractor at a supplier
legitimateReaching the shared project folder from their employer's machine.
Never on a managed device by definition. Requiring one excludes every third party you deliberately work with.
Satisfies: Phishing-resistant factor, Expected country, Recent re-authentication, Working hours.
Someone with a stolen password
attackSigning in from an unfamiliar machine and network.
The commonest attack, and almost any condition beyond a password stops it.
Satisfies: Working hours.
A relaying phishing page
attackForwarding a code typed by a genuine employee minutes ago.
Passes almost everything, because a real person really did just authenticate. Only the bound factor refuses.
Satisfies: Expected country, Recent re-authentication, Working hours, Healthy device.
Malware holding a stolen session
attackContinuing from the employee's own laptop after they logged in.
Indistinguishable on every signal except freshness. This is the case that argues for re-authenticating rather than trusting a session for a month.
Satisfies: Managed device, Phishing-resistant factor, Expected country, Working hours, Healthy device.
A developer at four in the morning
could be eitherDeploying a fix from a personal machine while abroad on holiday.
Genuinely ambiguous. It is either the person saving the weekend or somebody wearing their credentials, and no rule settles it — which is why a policy needs a path to ask rather than only a verdict.
Satisfies: Phishing-resistant factor, Recent re-authentication.