Identity, MFA & sign-in security checks across 20 apps
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
Why it matters
An admin account without MFA is the finding most often behind a SaaS tenant takeover: one phished password becomes full control of mail, files and identity. Auditors ask for it first, and ISO 27001, SOC 2, NIS2 and DORA all expect enforced strong authentication for privileged roles.
Browse by app
- Salesforce 15 checks
- Workday 12 checks
- Teleport 11 checks
- Cisco Duo 11 checks
- PingOne 11 checks
- Generic 8 checks
- Auth0 7 checks
- Cloudflare Access 6 checks
- ServiceNow 6 checks
- JumpCloud 6 checks
- Microsoft 365 5 checks
- Google Workspace 5 checks
- Okta 5 checks
- Chrome Enterprise 5 checks
- Google Cloud 4 checks
- GitLab 4 checks
- Dropbox 4 checks
- OpenRouter AI 3 checks
- 1Password 3 checks
- BambooHR 3 checks
Highest-severity checks
The 8 most severe Identity, MFA & sign-in checks across all 20 apps — each links to the connector page where the setting, its remediation and its framework mapping are documented.
- Admin Login from Proxy — Generic severity: critical
- Admin Without MFA — Salesforce severity: critical
- Cluster MFA Disabled — Teleport severity: critical
- Default Admin Account Active — ServiceNow severity: critical
- Group 2FA Not Enforced — GitLab severity: critical
- Group Owner Without 2FA — GitLab severity: critical
- High Confidence Proxy Login — Generic severity: critical
- MFA Disabled — 1Password severity: critical
Where to start
Connect Salesforce first — it carries the most Identity, MFA & sign-in checks in the catalog(setup guide, read-only access). A first scan takes about 15 minutes and reports every failing check on this page with its remediation steps.