<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Awad Yafai</title>
    <description>The latest articles on DEV Community by Awad Yafai (@awadyafai).</description>
    <link>https://dev.to/awadyafai</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3619809%2Fe506d733-f009-4f86-a538-973a169da351.png</url>
      <title>DEV Community: Awad Yafai</title>
      <link>https://dev.to/awadyafai</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/awadyafai"/>
    <language>en</language>
    <item>
      <title>[Boost]</title>
      <dc:creator>Awad Yafai</dc:creator>
      <pubDate>Fri, 12 Dec 2025 21:23:09 +0000</pubDate>
      <link>https://dev.to/awadyafai/-51jj</link>
      <guid>https://dev.to/awadyafai/-51jj</guid>
      <description>&lt;div class="ltag__link"&gt;
  &lt;a href="/awadyafai" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__pic"&gt;
      &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3619809%2Fe506d733-f009-4f86-a538-973a169da351.png" alt="awadyafai"&gt;
    &lt;/div&gt;
  &lt;/a&gt;
  &lt;a href="https://dev.to/awadyafai/a-zero-trust-identity-playbook-with-okta-sailpoint-that-costs-nothing-extra-and-deploys-in-one-4fd6" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__content"&gt;
      &lt;h2&gt;Designing a Zero Trust Identity Architecture with Okta and SailPoint&lt;/h2&gt;
      &lt;h3&gt;Awad Yafai ・ Nov 20 '25&lt;/h3&gt;
      &lt;div class="ltag__link__taglist"&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/a&gt;
&lt;/div&gt;


</description>
    </item>
    <item>
      <title>The 5 Identity Controls Every Modern Enterprise Is Missing in 2025</title>
      <dc:creator>Awad Yafai</dc:creator>
      <pubDate>Fri, 05 Dec 2025 23:01:52 +0000</pubDate>
      <link>https://dev.to/awadyafai/the-5-identity-controls-every-modern-enterprise-is-missing-in-2025-mpk</link>
      <guid>https://dev.to/awadyafai/the-5-identity-controls-every-modern-enterprise-is-missing-in-2025-mpk</guid>
      <description>&lt;h1&gt;
  
  
  Production-ready SailPoint IdentityIQ / IdentityNow rule templates we ship to every client – now free for you
&lt;/h1&gt;

&lt;p&gt;After leading identity programs for seven enterprises (15,000–110,000 identities), the same five gaps appear every single time.&lt;/p&gt;

&lt;p&gt;Here are the exact five controls we make mandatory on Day 1 — complete with the SailPoint BeanShell and XML rules we drop into every tenant.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Real-Time Toxic Combination Blocker&lt;/strong&gt; – SoD at request time, not just certification time
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dormant Account Auto-Disable After 25 Days&lt;/strong&gt; – not 90**
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;90-Day Auto-Expiry on All High-Risk Entitlements&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Just-In-Time Elevation with Automatic Rollback&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Continuous Mini-Certification When Risk Score ≥ 750&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;All five rules + installation guide are now public and 100 % free:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/awadyafai20-jpg/https-github.com-nexlify-public-sailpoint-modern-controls-2025/tree/main" rel="noopener noreferrer"&gt;https://github.com/awadyafai20-jpg/https-github.com-nexlify-public-sailpoint-modern-controls-2025/tree/main&lt;/a&gt;&lt;br&gt;
We have run these exact rules in production for over 110,000 identities with &lt;strong&gt;zero false positives&lt;/strong&gt; in 2024 and 2025.&lt;/p&gt;

&lt;p&gt;Implement even two of them, and you will instantly jump from “compliant” to “best-in-class”.&lt;/p&gt;

&lt;p&gt;Happy securing, &lt;/p&gt;

&lt;p&gt;Awad Bin Khaled Yafai&lt;/p&gt;

&lt;p&gt;Founder &amp;amp; CEO – Nexlify Innovations LLP&lt;/p&gt;

</description>
      <category>iam</category>
      <category>sailpoint</category>
      <category>identity</category>
      <category>security</category>
    </item>
    <item>
      <title>48-Hour Contractor Onboarding at Scale – The Exact SailPoint + Okta Workflow We Run in Production</title>
      <dc:creator>Awad Yafai</dc:creator>
      <pubDate>Fri, 28 Nov 2025 11:08:37 +0000</pubDate>
      <link>https://dev.to/awadyafai/48-hour-contractor-onboarding-at-scale-the-exact-sailpoint-okta-workflow-we-run-in-production-53id</link>
      <guid>https://dev.to/awadyafai/48-hour-contractor-onboarding-at-scale-the-exact-sailpoint-okta-workflow-we-run-in-production-53id</guid>
      <description>&lt;p&gt;&lt;strong&gt;Zero-touch provisioning and audit-proof offboarding for 500+ external users per month&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Most enterprises still take 7–21 days to onboard contractors and consultants.&lt;br&gt;&lt;br&gt;
At Nexlify, we are committed to a &lt;strong&gt;48-hour SLA&lt;/strong&gt; for every client — and we have met it 99.7% of the time over the last 18 months.&lt;/p&gt;

&lt;p&gt;Here is the exact automation flow we built using &lt;strong&gt;only SailPoint IdentityNow + Okta Workflows&lt;/strong&gt; (no custom middleware, no extra licenses):&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Contractor fills a 30-second Microsoft Form (start date + manager email)
&lt;/li&gt;
&lt;li&gt;Okta Workflow instantly creates the IdentityNow identity and triggers a self-service access catalog
&lt;/li&gt;
&lt;li&gt;SailPoint auto-provisions birthright roles based on contract type
&lt;/li&gt;
&lt;li&gt;Manager approves/rejects extra requests in &amp;lt; 4 hours (mobile push)
&lt;/li&gt;
&lt;li&gt;All access auto-expires on the exact contract end date — no manual cleanup ever&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Real production numbers from one anonymized client&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
• Average onboarding time: 9.2 days → &lt;strong&gt;41 hours&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
• Offboarding errors: 31 % → &lt;strong&gt;0 %&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
• Contractor-related audit findings: &lt;strong&gt;100 % eliminated&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The complete workflow JSON, SailPoint population rules, and step-by-step setup guide are now public and free:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/awadyafai20-jpg/contractor-48hr-onboarding" rel="noopener noreferrer"&gt;https://github.com/awadyafai20-jpg/contractor-48hr-onboarding&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Clone it, test it in your sandbox, deploy it tomorrow — zero cost.&lt;/p&gt;

&lt;p&gt;We run this exact flow for every enterprise client at Nexlify Innovations.&lt;/p&gt;

&lt;p&gt;Stay secure,&lt;br&gt;&lt;br&gt;
Awad Bin Khaled Yafai&lt;br&gt;
Founder &amp;amp; CEO – Nexlify Innovations LLP &lt;/p&gt;

</description>
      <category>security</category>
    </item>
    <item>
      <title>Designing a Zero Trust Identity Architecture with Okta and SailPoint</title>
      <dc:creator>Awad Yafai</dc:creator>
      <pubDate>Thu, 20 Nov 2025 01:00:56 +0000</pubDate>
      <link>https://dev.to/awadyafai/a-zero-trust-identity-playbook-with-okta-sailpoint-that-costs-nothing-extra-and-deploys-in-one-4fd6</link>
      <guid>https://dev.to/awadyafai/a-zero-trust-identity-playbook-with-okta-sailpoint-that-costs-nothing-extra-and-deploys-in-one-4fd6</guid>
      <description>&lt;p&gt;How We Reduced Phishing Success from 22% to 0.4% in a Large Enterprise with Existing IAM Tools.&lt;/p&gt;

&lt;p&gt;Over the last 24 months, we helped three enterprises (with 12,000–45,000 identities) reduce their phishing success rates from double digits to near zero — without purchasing a single new license.&lt;/p&gt;

&lt;p&gt;Here is the exact architecture and the five controls we switched on in their existing Okta + SailPoint tenants:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Continuous Device Trust Scoring (instead of one-time MFA)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Impossible Travel + New Device Step-Up with automatic challenge&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Risk-Based Conditional Access using SailPoint identity risk attributes&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Real-time session revocation when the risk score jumps&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Phishing-Resistant Authentication enforced for all privileged paths&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Results across all three clients&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Phishing click-to-compromise rate: 22 % → 0.4 %&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Zero additional vendor spend&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full rollout in under 14 business days&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The complete configuration guide and production rules are now public:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/awadyafai20-jpg/zero-trust-2025" rel="noopener noreferrer"&gt;https://github.com/awadyafai20-jpg/zero-trust-2025&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Clone, sandbox test, deploy today — we use this exact pattern for every new client at Nexlify Innovations Inc.&lt;/p&gt;

&lt;p&gt;Stay safe,&lt;/p&gt;

&lt;p&gt;Awad bin khaled Yafai&lt;/p&gt;

&lt;p&gt;Founder &amp;amp; CEO – Nexlify Innovations LLP&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
