"Humans are often considered the weakest link in security "
When implementing MFA for an OutSystems Reactive Web application using components like the Microsoft Login Connector or IdP, security depends not only on those components itself but also on how it is integrated/developed by the developer to our OutSystems application. If there are vulnerabilities left behind, they could weaken the security.
How can we test or verify that the MFA and SSO implemented in our OutSystems application are secure and free from vulnerabilities?
Hi @Priya Naveen ,
If you are not sure whether your OutSystems reactive application is secure or not even after implementing the MFA & SSO. then you must conduct/schedule a PEN testing for your application.
According to me, most of the organization conduct PEN test to ensure whether their application are secure or not. This is done by 3rd party most of the time.
You can request the same.
There are loads of article available over the internet for PEN test.
https://www.ibm.com/think/topics/penetration-testing
Regards,
Manish Jawla