← Back to Baseline

MB-R235

HUMAN VERIFICATION REQUIRED ASVS 6.8.4 Authentication-context validation (when federated_identity is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

If an application uses a separate Identity Provider (IdP) and expects specific authentication strength, methods, or recentness for specific functions, the application verifies this using the information returned by the IdP. For example, if OIDC is used, this might be achieved by validating ID Token claims such as 'acr', 'amr', and 'auth\_time'(if present). If the IdP does not provide this information, the application must have a documented fallback approach that assumes that the minimum strength authentication mechanism was used (for example, single-factor authentication using username and password).