psydii Posted October 17, 2022 Posted October 17, 2022 I keep getting consent requests for an App identifying itself as "tid-azure-common-ad-app-prod" with a reply URL of "https://azure-social-federation-oidc-prod.auth.us-west-2.amazoncognito.com/oauth2/idpresponse" Anyone got any idea what app people are trying to use that is generating these? My guess is that some 3rd party app is using amazon cognito for federated identity - but that isn't much help since it doesn't make clear what app the end user is expecting to be able to use?
5tu Posted November 21, 2022 Posted November 21, 2022 I get these too on a regular basis and also have no idea what it is. 1
TechMonkey Posted November 21, 2022 Posted November 21, 2022 If you are unsure ignore/reject it. If it is important someone will come to you with a confused look wondering why they can't login to an app or have had a rejected message. Do the requests not come with a username? 1
psydii Posted June 23, 2023 Author Posted June 23, 2023 Still getting them. Reviewing the latest batch, it seems to be Trimble (SketchUP). Not sure why though, since we've got the SketchUP app itself authorized and that seems to work well. The URL / API that needs to be authorized is worryingly non-specific... it looks a lot like authorizing it would authorise all apps running through the Amazon Cognito service. I lack the time to dive into how Cognito works. So it remains unauthorised.
HPlum78 Posted June 23, 2023 Posted June 23, 2023 I would turn off the ability for users to request application permissions via this mechanism. Have a process in place for people requesting these and any thing that asks for app delegated permissions needs questioning.
psydii Posted June 23, 2023 Author Posted June 23, 2023 I kind of like the way they it encourages them to engage with us via the UX, otherwise they don't try anything new because they can't be bothered to engage with the process, or they just upload the student details to whatever site takes their fancy - because how would we (IT / DPO) ever know? Yeah Yeah GDPR etc. Sometimes you need the technological carrot and stick to support best practice, and this seems to work pretty well. Still not sure what flow people are following to trigger specifically the above though - it was initially configured because the HoD followed process with us to make it work.
HPlum78 Posted June 23, 2023 Posted June 23, 2023 (edited) Those permission can be large in scope and if it was just about GDPR that would be one thing but there is more to this than just that... I have seen even well known companies have bat crazy permission requests. Edited June 23, 2023 by HPlum78
nhfilz Posted May 30, 2024 Posted May 30, 2024 I realize OP posted this quite some time ago, but in case anyone else stumbles upon this thread. I believe this is SketchUp's 3D Warehouse. I dont know why it doesnt pass credentials through. The only thing I can think of is that this is a result of the fractured ecosystem that they inherited, and they wanted to get sketchup licensing moved over to Trimble accounts as fast as possible, and 3D Warehouse was put on the back burner. I believe you can have accounts on both services that share a primary ID, but are unique from oneanother. But that is just a guess. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now