Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “Federation”

8 publications
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Entra emergency access that survives normal sign-in failure

A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Make secret rotation reach every running application

Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.

Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Rotate Entra application certificates with proof of adoption

A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.

Identity & access · Microsoft Entra / Azure Key Vault · By Cloud Security Desk
Technical guideSource-based analysis

Short SSH certificates still need explicit access boundaries

An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.

Identity & access · OpenSSH · By Cloud Security Desk
Technical guideSource-based analysis

Trace Google service account impersonation across every hop

A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.

Identity & access · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Close the AWS sessions that survive identity shutdown

Removing a login does not by itself establish that issued AWS credentials have lost their authority. Build a revocation procedure that accounts for both.

Identity & access · AWS · By Cloud Security Desk
Technical guideIllustrative analysis

Recover the control plane before you need it

A recovery plan that depends on the compromised identity system is an aspiration. Build and test an independent administrative path.

Resilience · Identity & access · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh