But that's just certificate auth, which happens during session establishment and before data transmission isn't it? So isn't it an idp with cert auth as the primary first factor?
So for example Shibboleth with privacyIDEA and enabled webAuthn and 2FA for AnyConnect or some other VPN?
This is what I was thinking
I guess it could be categorised as a PAM (privileged access management) solution with a built-in IdP?
I was about to say this sounds like our on prem PAM setup which is integrated with our idp - or some mixture of things folks are asking about. Seems like this is something largely solved regardless of how it's being done, but maybe we're all missing something. Or maybe his implementation is just that slick.
Does your PAM include a data loss prevention feature?