Skip to content

Generic identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Generic, Black Cat runs 8 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies.

Checks (8)

severity: high Login from Residential Proxy fix difficulty: medium #

Investigate the login source and enforce conditional access or IP allowlists to block residential proxy usage

  1. Identify the user account and source IP address from the finding details
  2. Determine whether the user has a legitimate reason to access corporate SaaS via a residential proxy
  3. Review recent activity for the account in your identity provider audit logs for additional anomalies
  4. If unauthorized or suspicious, revoke active sessions and require the user to re-authenticate
  5. Enforce conditional access policies or IP allowlists in your identity provider to block residential proxy ingress

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: medium Login from Datacenter Proxy fix difficulty: medium #

Verify the datacenter IP is from an authorized VPN or cloud egress, and restrict access if not

  1. Identify the user account and datacenter IP address from the finding details
  2. Cross-reference the IP against your organization's known VPN egress ranges and authorized cloud NAT gateways
  3. If the IP is not from an approved source, contact the user out-of-band to confirm the login was intentional
  4. Review identity provider logs for other logins from the same datacenter IP range
  5. Update your conditional access policy to require additional verification for unrecognized datacenter sources

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: critical High Confidence Proxy Login fix difficulty: medium #

Block the high-confidence proxy IP and require step-up authentication for the affected account immediately

  1. Identify the user account and source IP address flagged with a high proxy confidence score
  2. Immediately revoke active sessions for the affected account in your identity provider
  3. Block the source IP at your network perimeter or in your identity provider's IP blocklist
  4. Contact the user out-of-band to verify whether the login was intentional
  5. Require re-authentication with hardware MFA or a FIDO2 security key before restoring access
  6. Review all actions performed during the session for signs of unauthorized activity

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: high Failed Login from Proxy fix difficulty: medium #

Investigate failed login attempts from proxy IPs for credential stuffing or brute force activity and block the source

  1. Identify the targeted account and source IP address from the finding details
  2. Query identity provider logs for the total count of failed attempts from this IP and time window
  3. Determine whether multiple accounts were targeted from the same proxy IP, which indicates credential stuffing
  4. Block the source IP at your network perimeter or identity provider if brute force patterns are confirmed
  5. Enable account lockout policies and rate limiting on authentication endpoints if not already in place
  6. Reset credentials for any accounts that show signs of compromise and notify affected users

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: critical Admin Login from Proxy fix difficulty: medium #

Investigate admin proxy login immediately and enforce step-up authentication for all admin accounts

  1. Identify the admin account and source IP address from the finding details
  2. Contact the admin user out-of-band to verify whether the login attempt was intentional
  3. If unauthorized, rotate the account credentials and revoke all active sessions immediately
  4. Review identity provider audit logs for all actions performed by the admin account during the session
  5. Enforce IP allowlist or require hardware MFA for all admin accounts to prevent future proxy-based logins

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: high Login from Disallowed Country fix difficulty: medium #

Confirm whether the login from a disallowed country was authorized; if not, revoke sessions and tighten conditional access

  1. Identify the user account, source country, and IP from the finding details
  2. Confirm with the user out-of-band whether the access was intentional (travel, relocation, VPN egress)
  3. If unauthorized, revoke active sessions and force re-authentication in the identity provider
  4. Review the tenant geo policy to confirm the country list reflects current business needs
  5. Add conditional access / IP allowlist rules in the identity provider to block the disallowed region

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.2

severity: medium Login from New Country fix difficulty: medium #

Verify a login from a country not previously seen for this account is legitimate

  1. Identify the user account, new country, and source IP from the finding details
  2. Compare against the account's historical login geography in the geo observation drill-down
  3. Confirm with the user out-of-band whether the new-country access was intentional
  4. If suspicious, revoke active sessions and require re-authentication
  5. Consider adding the country to the tenant geo deny list if access from it is never expected

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.2

severity: high Impossible Travel Login fix difficulty: medium #

Two logins from distant countries within a window too short for physical travel — likely credential compromise or session theft. Distance is approximate (country-centroid based).

  1. Identify the account, the two countries, the time gap, and implied speed from the finding details
  2. Confirm with the user out-of-band whether both logins were theirs (VPN egress can cause benign hops)
  3. If unauthorized, revoke all active sessions and force re-authentication in the identity provider
  4. Add conditional-access / impossible-travel rules in the identity provider

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.2

More Generic checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial