July 2026 Summaries
5 posts from PropelAuth
Filter
Month:
Year:
Post Summaries
Back to Blog
User impersonation is a favored feature among customers for its ability to assist in debugging, user support, and sales demonstrations by allowing team members to access the product as if they were a specific user. PropelAuth's system ensures this powerful tool is used responsibly with a suite of safety and access-control features, including employee-level impersonation permissions, audit logs, real-time alerts, and session monitoring. Impersonation is disabled by default and requires explicit activation by an Owner, who then assigns access on a need-only basis, fostering a least-privilege model. The system offers proactive controls like approval requirements, organization blocklists, and allowlists to manage who can be impersonated, thus providing granular oversight and preventing unauthorized access. Additionally, developer tools in PropelAuth libraries help detect and customize application behavior during impersonation, ensuring security and accountability while maintaining the flexibility to quickly address customer issues.
Jul 22, 2026
1,339 words in the original blog post.
User impersonation is a valuable feature for debugging, support, and demonstrations, but it raises concerns about sensitive access, prompting the introduction of new controls to manage it more securely. PropelAuth announces three enhancements: Organization Blocklists, Impersonatable Organizations, and direct Impersonation Links. Organization Blocklists enforce restrictions by preventing certain customer accounts from being impersonated, eliminating reliance on manual checks. Impersonatable Organizations allow tailored access by enabling employees to impersonate only the accounts they manage, while direct Impersonation Links streamline the process by providing a direct pathway to the impersonation workflow without bypassing existing permissions. These features are designed to offer flexibility and security, allowing teams to maintain the efficiency impersonation provides while ensuring precise control and accountability over who accesses customer accounts and for what purpose.
Jul 21, 2026
595 words in the original blog post.
SCIM (System for Cross-domain Identity Management) is an open standard designed to automate the lifecycle management of user accounts across various applications through integration with an identity provider (IdP) such as Okta, Microsoft Entra ID, or JumpCloud. Functioning as a REST API with JSON payloads, SCIM facilitates the creation, updating, and deactivation of user accounts, ensuring that changes in a company's employee directory are reflected across all managed applications. It works alongside authentication protocols like SAML and OIDC, which handle user login processes, whereas SCIM focuses on provisioning and synchronizing user data, including roles and group memberships. While it offers proactive management of user accounts, addressing issues such as deprovisioning when employees leave, SCIM implementation can be complex due to variations among IdPs and requires careful handling of custom attributes and security measures. Despite its complexity, SCIM is crucial for companies selling to mid-market or enterprise clients, as it often becomes a requirement for completing security and compliance checks during the sales cycle.
Jul 13, 2026
1,806 words in the original blog post.
Member Audit Logs provide customers with visibility into individual account activities within their organizations, enhancing transparency for security and compliance. Previously, audit logs focused on organization-wide events like Enterprise SSO configurations and MFA restrictions, but now customers can track member-specific actions such as logins, password changes, and email confirmations. This feature is particularly useful for understanding individual member activity and addressing any concerns that arise when a team member leaves, as it provides a historical record limited to the user's active membership period. This additional oversight allows customers to independently access information without needing to contact support, thereby meeting the demands of security-conscious teams seeking to enhance their monitoring capabilities. To implement Member Audit Logs, users can adjust settings in the PropelAuth dashboard to expand the scope of audit logs.
Jul 08, 2026
368 words in the original blog post.
PropelAuth has introduced a new Session Management feature that enhances both user and administrative visibility and control over active sessions within their dashboard. This feature allows users and administrators to view details such as the device's user agent, IP address, country, and the last active time for each session. Additionally, sessions can be terminated remotely, either by users themselves through PropelAuth hosted pages or by administrative teams via the PropelAuth dashboard, which is especially useful for security and device management. This functionality also extends to user impersonation sessions, providing comprehensive oversight for companies dealing with larger client bases and addressing security concerns commonly raised in security questionnaires.
Jul 07, 2026
244 words in the original blog post.