Implementation examples
24 examples referencing Cloud IdP
- MA.L2-3.7.5[a] [b]
Vendor remote sessions: MFA to get in, watched throughout, torn down at hang-up
AO coverage. Addresses both Nonlocal Maintenance objectives: multifactor authentication to establish sessions over external network connections, and termination of those sessions when the work is…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - SI.L2-3.14.7[a] [b]
Write down what authorized use looks like, then alert on what falls outside it
AO coverage. Addresses both Identify Unauthorized Use objectives: authorized use of the system is defined, and unauthorized use is identified. Defining authorized use [a]. This is the objective most…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet Both ends prove who they are: validated TLS for people, mutual TLS and pinned keys for machines
AO coverage. Addresses the single Communications Authenticity objective for the session types in scope: user-to-application, application-to-application, and administrative. User-to-application.…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet- SC.L2-3.13.3[a] [b] [c]
Management interfaces unreachable from user devices; admin work happens on a separate plane
AO coverage. Addresses all three Role Separation objectives: identifying user functionality, identifying system management functionality, and separating the two. User functionality identified [a].…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - CM.L2-3.4.6[a] [b]
Role-shaped images: each server role ships only the packages that role needs
AO coverage. Addresses both Least Functionality objectives: essential capabilities are defined per role, and systems are configured to provide only those. Defining essential capabilities [a]. Each…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - CM.L2-3.4.5[a] [b] [e] [f] [g] [h]
Only the deployment pipeline can write to production; humans hold review rights
AO coverage. Claims the logical access restriction objectives [e] defined, [f] documented, [g] approved, and [h] enforced, plus [a] and [b] — physical restrictions are defined and documented for the…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.9[a] [b]
Two named log administrators; analysts and engineers get read-only search
AO coverage. Addresses both Audit Management objectives: the subset of privileged users allowed to manage audit logging functionality is defined, and management is limited to that subset. Defined…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.2[a] [b]
Retiring the shared itadmin account so every action names a human
AO coverage. Addresses both User Accountability objectives: the record content needed to trace actions to a user is defined, and created records actually contain it. Defined record content [a]. For…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.9[a]
Single-use 60-minute reset credential; the session cannot continue without a permanent one
AO coverage. Addresses the single Temporary Passwords objective: an immediate change to a permanent credential is required when a temporary one is used to log on. Reset path. The help desk issues a…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.6[a] [b]
35-day inactivity disable for people, 90 with owner sign-off for service identities
AO coverage. Addresses both Identifier Handling objectives: the inactivity period is defined, and identifiers are disabled after it. Defined periods. Interactive human accounts: 35 days without a…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.5[a] [b]
24-month identifier hold, with mail aliases reserved permanently
AO coverage. Addresses both Identifier Reuse objectives: the non-reuse period is defined, and reuse is prevented within it. Defined period. Account identifiers (UPN, sAMAccountName, MES user ID, and…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.1[a] [b] [c]
One naming standard for people, svc- identities, and device records
AO coverage. Addresses all three Identification objectives: users, processes acting on behalf of users, and devices that access the system. Users. Person accounts follow with a numeric suffix on…
ControlVerdict Corpus@cv-corpusJul 31, 2026Not enough signal88% · 2 - AC.L2-3.1.20[a] [b] [c] [d] [e]
External system connections via CASB allow-list and reviewed integrations
AO coverage. Claims objectives [a]–[e] for verifying and limiting connections to external systems that handle CUI. Objective [f] (limit use of portable storage on external systems) is covered under…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.14[a] [b]
All remote paths land on managed VPN or IdP — no direct RDP to enclave
AO coverage. Addresses both Remote Access Routing objectives. Control points. Internet users reach CUI only via (1) IdP SSO to SaaS or (2) full-tunnel VPN into the lab VRF. Edge firewall denies…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.13[a] [b]
TLS 1.2+ and approved ciphers on every remote access path
AO coverage. Addresses both Remote Access Confidentiality objectives. Identified mechanisms. Remote paths use TLS 1.2+ (SaaS/IdP) or IPsec/IKE suites approved on the crypto inventory (VPN). TLS…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.11[a] [b]
Idle and max session lifetimes on VPN and SSO
AO coverage. Addresses both Session Termination objectives. VPN. Idle disconnect ≤12 hours; absolute session lifetime forces re-auth. Concurrent sessions limited to one unless ticketed. SSO. IdP…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.9[a] [b]
CUI rules banner before enclave session and on shared workstations
AO coverage. Addresses both Privacy & Security Notices objectives for CUI rules. Notices. Before first daily access to enclave apps, users accept an IdP Terms of Use stating CUI handling rules,…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.8[a] [b]
Smart lockout on IdP and VPN; no endless password spray
AO coverage. Addresses both Unsuccessful Logon Attempts objectives. Thresholds. IdP smart lockout after repeated failures (org baseline: lock after sustained failures within a window, with…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.6[a] [b]
Day-to-day work on standard accounts; elevate only for admin tasks
AO coverage. Addresses both Non-privileged Account Use objectives. Standard accounts. Email, Office, and CUI SaaS are used from the user’s non-privileged account. Local admin rights are removed from…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.4[a] [b] [c]
No single person both approves and provisions enclave access
AO coverage. Addresses all Separation of Duties objectives for enclave IAM and privileged IT functions. Conflicting duties. Documented pairs that must not be held by one person: (1) access approver…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet