Why: Centralizing applications behind the identity provider — a step the MFA rollout forces — is how authentication-before-access becomes enforceable in one place rather than per application.
What this does not claim: The requirement covers every access path, including device authentication and paths that never join the identity provider. The practice strengthens the central path; the periphery must be evaluated separately within the organization's defined system boundary.
- Move applications behind single sign-on as MFA enforcement expands
- Inventory access paths that authenticate locally and assign each an owner
- SSO application register
- Local-authentication exception list with owners
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06