Totally agree on the compromised credential check, hence it‘s also part of my general password policy recommendations [0].
I also agree that IdPs and SSO is commodity nowadays (to speak in Wardley-terms). However, some orgs still have vastly heterogeneous authentication systems. In these situations it might be financially beneficial first do unify and then switch to an off-the-shelf service provider later. OIDC makes it possible.
I also agree that IdPs and SSO is commodity nowadays (to speak in Wardley-terms). However, some orgs still have vastly heterogeneous authentication systems. In these situations it might be financially beneficial first do unify and then switch to an off-the-shelf service provider later. OIDC makes it possible.
[0]: https://www.jbspeakr.cc/password-strength-policy-guide/#pass...