Currently, when a user registers for private content, there are a few options. Password-less authentication, Social sign-on, and Single-sign on. We have a use-case where, due to some info-security certifications we maintain, we require sign-on to any cloud platform to be challenged. Or in other words, sign-on cannot just be a simple username and password combo. Unfortunately, this doesn't seem possible for private content with the current settings. SSO sounds like it would work, except it requires that you have the accounts using SSO registered in the identity provider that you set up to use SSO. This is not the case for us. We want to be giving access to customers or prospects who are not affiliated with us, and so not registered in any single identity provider. Password-less and social sign-on would meet the requirement, except that they are not enforced. Enabling them gives the users the option to use them, it does not require them to use them. So there is still nothing preventing a user from using a basic username and password. Another common approach is MFA/2FA, sending an email, SMS or authenticator app challenge that needs to be met before access is granted, but this does not seem to be an option for Private Content. My idea would be to have a toggle option on the Private Content settings page to require the available registration options, not just allow them. The end user experience would then be, when registering for Private Content, they would only be able to use the selected required options, preventing them from signing up with a simple username and password. Currently we are unable to make use of Private Content as it would go against our security certifications. We would very much like to use it though, as it's a great way to host content that we want to have more control over who is able to access it!
...read more