4Security policy and access control
- 4.1Strengthening authentication (2-step verification, SSO)
Understand enforcing 2-step verification (2SV) and stronger methods (security keys/passkeys), SAML SSO federation with an external IdP, password policy (length, reuse, strength), and configuring secure account recovery.
- 4.2Access control and security response
Understand context-aware access to control access by device/location/IP, the security dashboard and alert center to understand and respond to threats, blocking less secure apps, and operations to protect accounts during compromise.

