<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Sso on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/sso/</link><description>Recent content in Sso on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sat, 15 Jun 2024 11:30:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/sso/index.xml" rel="self" type="application/rss+xml"/><item><title>Onboarding Password Risks &amp; How to Fix Them</title><link>https://zxcloudsecurity.co.uk/posts/onboarding-temporary-password-security-risk-identity-hygiene/</link><pubDate>Mon, 15 Jun 2026 11:30:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/onboarding-temporary-password-security-risk-identity-hygiene/</guid><description>Temporary onboarding passwords shared via email or SMS often go unchanged, creating lasting credential risks. Here&amp;#39;s how to close the gap.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/the-onboarding-password-mistake-that.html">The Hacker News</a></p>
<hr>
<p>Many organisations issue temporary passwords during employee onboarding that are shared over insecure channels such as email or SMS, and often never changed. These credentials can persist indefinitely, be reused across multiple accounts, and represent an easily exploitable entry point for attackers. The risk is compounded at scale, as every new hire represents a potential window of exposure if the process is not tightly controlled.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Enforce password-change-on-first-login policies at the identity provider level and integrate onboarding flows with your SSO and MFA platform so temporary credentials have a hard expiry — ideally under 24 hours. Audit existing accounts for credentials that were never rotated post-onboarding using your IdP&rsquo;s sign-in logs.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/the-onboarding-password-mistake-that.html">The Onboarding Password Mistake That Creates Unnecessary Risk</a></p>
]]></content:encoded></item></channel></rss>