Aarkam / Aarkam Wiki / Cyber Security / Identity & Access Management (MFA, SSO, RBAC)
IAM & Zero Trust Cyber Security

Identity & Access Management (MFA, SSO, RBAC)

TOTP Multi-Factor Authentication, NIST password policies, session concurrency limits, and enterprise SSO.

Last updated: Sep 23, 2026

Aarkam’s Identity & Access Management (IAM) tier enforces stringent enterprise security controls aligned with NCA ECC-2:2024 §2-2, NIST SP 800-63B, and ISO/IEC 27001:2022.


1. Multi-Factor Authentication (MFA / TOTP)

Aarkam enforces hardware or software TOTP Multi-Factor Authentication across all administrative and tenant-privileged access:

  • Algorithm: RFC 6238 Time-Based One-Time Password (TOTP)
  • Time Step: 30 seconds with 1-step drift tolerance
  • Enrollment: Secure QR-code provisioning with encrypted shared secrets for Microsoft Authenticator, Google Authenticator, and hardware YubiKeys.
  • Service Implementation: Implemented in IMfaService and required prior to generating API tokens or accessing administrative panels.

2. Password Governance & NIST Compliance

User authentication enforces strict cryptographic hygiene in AarkamPersistenceModule:

Policy Setting Standard Compliance
Minimum Length 12 Characters NIST SP 800-63B / NCA ECC
Character Complexity Upper, Lower, Numeric, Special NCA ECC-2:2024 §2-2
Account Lockout 15 Minutes after 5 Failed Attempts Prevent Brute-Force Password Spraying
Password History 120-Day History Validator (PasswordHistoryValidator) Prohibits Reusing Previous 5 Passwords
Password Expiration Maximum 90-Day Lifespan Automated Expiration Enforcement

3. Session Security & Concurrency Controls

To prevent unauthorized concurrent session hijacking, Aarkam.IO restricts session lifetimes:

  • Concurrent Session Limits: LoginByUserNameOrEmailHandler restricts accounts to a maximum of 3 concurrent sessions. Logging into a 4th session automatically prunes and invalidates the oldest session.
  • Instant Revocation on Credential Change: ChangePasswordRequestHandler immediately revokes all active JWT Refresh Tokens across all devices when an account password or MFA status changes.
  • HMAC Signed JWTs: Session tokens are signed using HMAC-SHA256 with automated token rotation upon each refresh request.

4. Enterprise SSO Federation

Aarkam integrates into existing enterprise identity providers via standard federated protocols:

  • OpenID Connect (OIDC): Native integration with Microsoft Entra ID (Azure AD), Okta, and Ping Identity.
  • SAML 2.0: Support for on-premises Active Directory Federation Services (AD FS) and government identity gateways.