← Tutte le news
ARTICOLO
22 settembre 2026

FAQ MSP: separare accesso umano vs NHI e token a vita breve cross-tenant

Umani ≠ NHI. Token short-lived per-tenant. Soft Auris m2m/tenant-bound (non cert). Distinta da FAQ GDAP e login≠isolation.

FAQ MSP: separare accesso umano vs NHI e token a vita breve cross-tenant

· fire RADAR 2026-09-20 15:00 Europe/Rome · publish = umano (Nao).

Hook: Come deve un MSP separare accesso umano dei tecnici da NHI (automation) e tenere token a vita breve su molti tenant clienti?

Claim: umani e NHI non condividono credenziali né ruoli permanenti. Principali distinti, scope least-privilege per-tenant, token short-lived, rotazione, audit per-tenant con classe di identità. FAQ distinta da GDAP e login≠isolation già staged.

Checklist:

  • App IdP / service principal separati per umani vs automation (NHI)
  • Niente password break-glass condivise tra helpdesk e pipeline
  • Access token in minuti–ore; refresh sotto change control
  • Token machine (m2m) bound a un solo tenant cliente — mai god key cross-tenant
  • Audit con classe identità (human | NHI) e tenant_id

Soft Auris (non una cert): check live @ 2026-09-20T13:01:26Z: ok, m2m, tenant_id bound, org_id null, probe ok, 0 violations, lifetimeSeconds 3600 — postura prodotto per token machine short-lived/tenant-bound, non cert. Lodestar saltato (403). No ACN/C5/SecNumCloud/CLOUD Act.

Solo draft.