Session

Combining OIDC, Passkeys, and Step-Up Authentication for High-Risk Actions

Modern apps increasingly need more than “logged in” versus “not logged in.”

This session explores how to combine OpenID Connect, passkeys, and step-up authentication to protect sensitive operations like payments, account recovery, email changes, and privilege escalation.
It focuses on designing flows that are both phishing-resistant and usable, while meeting stronger authentication requirements only when risk demands it.

OAuth 2.0 Step Up Authentication Challenge Protocol RFC 9470 formalizes how resource servers can request stronger or more recent authentication when the current token is not sufficient.

Roland Guijt

Microsoft MVP and MCT, Pluralsight author

Utrecht, The Netherlands

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top