BambooHR identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On BambooHR, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the BambooHR connector needs.
Checks (3)
severity: high Terminated Employee With Active Login fix difficulty: easy #
Disable the BambooHR login for this terminated employee
- Open BambooHR > Settings > Access Levels / Users
- Locate the user linked to the terminated employee
- Disable the user's login access
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium Stale BambooHR Login fix difficulty: easy #
Review and disable enabled logins that are dormant or never used
- Open BambooHR > Settings > Users
- Review the last-login date for the flagged user
- Disable the login if it is no longer needed
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium Orphaned BambooHR Login fix difficulty: easy #
Investigate the login that is not linked to any employee record
- Open BambooHR > Settings > Users
- Confirm whether the login is a service/leftover account
- Disable or document the account
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6