The 14 Auth0 security checks Black Cat runs
Black Cat SSPM evaluates 14 security policies against your Auth0 configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.
audit
Review successful Management API change events for unexpected configuration changes
authentication
Enable brute-force protection on database connections
configuration
Disable tenant-wide Dynamic Client Registration unless explicitly required
identity
Block or remove Auth0 accounts inactive for 90+ days
logging
Confirm Auth0 tenant logs are being generated and retained
mfa
Enroll Auth0 users in multi-factor authentication
Enable MFA on database connections
Enforce MFA at the tenant level via a Guardian policy
oauth
Remove ROPC (password) and implicit grant types from applications
Add client authentication to applications using confidential grants
Replace wildcard and insecure callback/origin URLs with exact HTTPS URLs
password policy
Raise the password policy on database connections to good or excellent
privilege
Review roles that grant write access to the Auth0 Management API
session
Reduce the tenant session lifetime to 168 hours (7 days) or less