Local third-party application logins create an easy path around SSO and MFA. Spot and eliminate misconfigured access policies so every user authenticates through secure controls.

Find and eliminate every direct authentication path between users and third-party applications to enforce strict, consistent access controls through your identity perimeter.



A direct login access violation occurs when users access third-party applications using local credentials instead of single sign-on (SSO), often bypassing intended security controls and multi-factor authentication.
Despite SSO configuration, direct logins can persist due to legacy local accounts, break-glass credentials, misconfigured conditional access policies, and third-party applications that still allow non-SSO authentication paths.
Obsidian continuously monitors third-party application environments via API connections and additionally leverages visibility from its browser extension to identify evidence of local account logins. Together, these methods ensure real-time, high-fidelity detection.
Manual reviews require correlating third-party applications, IdP, and network logs, interviewing users, and collecting evidence, leading to high operational costs and delays in detecting and responding to security incidents.
Persistent violations increase compliance risk, raise operational costs, weaken incident response times, and decrease confidence among customers and auditors.
Obsidian automates the detection of policy drift in real time and provides clear evidence for remediation, reducing reliance on periodic manual reviews and minimizing unnoticed violations.
Knowing the difference helps teams quickly identify unauthorized access routes, prevent MFA bypass, and ensure only approved authentication methods are used.