Session
Combining OIDC, Passkeys, and Step-Up Authentication for High-Risk Actions
Modern apps increasingly need more than “logged in” versus “not logged in.”
This session explores how to combine OpenID Connect, passkeys, and step-up authentication to protect sensitive operations like payments, account recovery, email changes, and privilege escalation.
It focuses on designing flows that are both phishing-resistant and usable, while meeting stronger authentication requirements only when risk demands it.
OAuth 2.0 Step Up Authentication Challenge Protocol RFC 9470 formalizes how resource servers can request stronger or more recent authentication when the current token is not sufficient.
Roland Guijt
Microsoft MVP and MCT, Pluralsight author
Utrecht, The Netherlands
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top