Jump to content

Recommended Posts

Posted

I keep getting consent requests for an App identifying itself as "tid-azure-common-ad-app-prod" with a reply URL of "https://azure-social-federation-oidc-prod.auth.us-west-2.amazoncognito.com/oauth2/idpresponse"

 

Anyone got any idea what app people are trying to use that is generating these? My guess is that some 3rd party app is using amazon cognito for federated identity - but that isn't much help since it doesn't make clear what app the end user is expecting to be able to use?

  • 1 month later...
Posted

If you are unsure ignore/reject it. If it is important someone will come to you with a confused look wondering why they can't login to an app or have had a rejected message.

 

Do the requests not come with a username?

  • Thanks 1
  • 7 months later...
Posted

Still getting them. Reviewing the latest batch, it seems to be Trimble (SketchUP).

 

Not sure why though, since we've got the SketchUP app itself authorized and that seems to work well.

 

The URL / API that needs to be authorized is worryingly non-specific... it looks a lot like authorizing it would authorise all apps running through the Amazon Cognito service. I lack the time to dive into how Cognito works.

 

So it remains unauthorised.

Posted
I would turn off the ability for users to request application permissions via this mechanism. Have a process in place for people requesting these and any thing that asks for app delegated permissions needs questioning.
Posted

I kind of like the way they it encourages them to engage with us via the UX, otherwise they don't try anything new because they can't be bothered to engage with the process, or they just upload the student details to whatever site takes their fancy - because how would we (IT / DPO) ever know?

 

Yeah Yeah GDPR etc.

 

Sometimes you need the technological carrot and stick to support best practice, and this seems to work pretty well.

 

Still not sure what flow people are following to trigger specifically the above though - it was initially configured because the HoD followed process with us to make it work.

Posted (edited)

Those permission can be large in scope and if it was just about GDPR that would be one thing but there is more to this than just that...

 

I have seen even well known companies have bat crazy permission requests.

Edited by HPlum78
  • 11 months later...
Posted
I realize OP posted this quite some time ago, but in case anyone else stumbles upon this thread. I believe this is SketchUp's 3D Warehouse. I dont know why it doesnt pass credentials through. The only thing I can think of is that this is a result of the fractured ecosystem that they inherited, and they wanted to get sketchup licensing moved over to Trimble accounts as fast as possible, and 3D Warehouse was put on the back burner. I believe you can have accounts on both services that share a primary ID, but are unique from oneanother. But that is just a guess.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...