Dominick Baier's Avatar

Dominick Baier

@leastprivilege.com

Advisor & Board Member at Duende Software - @duendesoftware.com

293
Followers
30
Following
75
Posts
10.11.2024
Joined
Posts Following

Latest posts by Dominick Baier @leastprivilege.com

Preview
Training Information

Duende Software's legendary training on Identity and Access Management was originally created by Dominick Baier and Brock Allen.

We're offering the training online/remotely as 6 half-day blocks in EU afternoons/US mornings, starting March 10.

Read more and sign up at sustainsys.com/training

05.03.2026 12:42 πŸ‘ 0 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Livestream: Are your access tokens really secure? Are your APIs vulnerable? Explore JWT pitfalls, learn to prevent exploits, and compare JWTs vs. opaque tokens in this expert-led session.

The livestream starts NOW! πŸ”΄ Security you can’t prove isn’t security, it’s hope.

Stop relying on manual checks. We’re showing you how to automate your security testing to ensure your API only accepts your trusted tokens.

πŸ”— Join us now: duende.link/lsjwt26b

#OAuth2 #JWT #DotNet

03.03.2026 15:03 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Rate Limiting IdentityServer Endpoints Learn why rate limiting Duende IdentityServer endpoints is usually unnecessary, and when you do need it. Explore a layered approach using network proxies, ASP.NET Core middleware, and custom…

Should you add rate limiting to your Duende IdentityServer deployment? πŸ€”

Our new article breaks down the why (and why not), plus 3 implementation options.

Read the full article πŸ‘‰ duende.link/87wrkjh

#dotnet #ASPNETCore #OAuth #OpenIDConnect

03.03.2026 18:30 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Null exceptions are costly. We are enforcing strict Nullable Reference Types across the IdentityServer API in .NET 10. The compiler catches bugs before you deploy.

The community deserves rigorous design.

Learn More: duende.link/bpicb

#aspnet #dotnet

04.03.2026 07:01 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
The Big Picture An overview of modern application architecture patterns and how OpenID Connect and OAuth 2.0 protocols implemented by IdentityServer solve authentication and API access challenges

Stability is a community asset. Aligning with the Microsoft LTS schedule provides a shared timeline for the industry. We can all plan, budget, and coordinate releases together.

Predictability helps the whole community function better.

Learn more: duende.link/bpicb

#aspnet #dotnet #LTS

26.02.2026 18:01 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Implementing Zero Trust with Resource Isolation Learn how to enforce strict trust boundaries between your APIs and prevent overprivileged access tokens by adopting Resource Isolation, based on OAuth 2.0's RFC 8707, with Duende IdentityServer.

No more overprivileged access tokens? πŸ”‘

Implement strict trust boundaries in your APIs with resource isolation (#OAuth RFC 8707).

Learn how to configure it in Duende IdentityServer: duende.link/87qt2j

#dotnet

10.02.2026 18:00 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
MORE Essential HTTP Headers
MORE Essential HTTP Headers In this video, we look deeper into critical security-related HTTP headers that can significantly strengthen your website's defenses. What you'll learn in this video: * X-Content-Type-Options:…

In this video, we look deeper into critical security-related HTTP headers that can significantly strengthen your website's defenses. Expect X-Content-Type-Options, Referrer-Policy:, X-FRAME-OPTIONS, Content Security Policy (CSP), ...

youtu.be/OztgrdMQG94 #dotnet #aspnetcore #SecurityTips

10.02.2026 21:30 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Jennifer Lawrence "What Do You Mean" #shorts
Jennifer Lawrence "What Do You Mean" #shorts YouTube video by Quotes For Eternity

www.youtube.com/shorts/LRt3x...

06.02.2026 10:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende IdentityServer The most flexible and standards-compliant OpenID Connect and OAuth framework for ASP.NET Core.

SaaS providers are black boxes. Duende gives you full source access. Step-through to understand exactly how it all works.

Learn More: duende.link/2swrhhw

#aspnet #aspnetcore #dotnet

05.02.2026 17:01 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Supply chain something something... not an issue - all focus back on AI!

30.01.2026 07:21 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Preview
BenchmarkDotNet - Open Source Sponsorship Duende Software's latest Open Source Sponsorship goes to BenchmarkDotNet, a benchmarking library for .NET.

We're proud to announce that Duende Software's latest Open Source Sponsorship goes to #BenchmarkDotNet! πŸš€

Check out the full post for details on the project: duende.link/o55bmd

#dotnet

27.01.2026 13:01 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1
Going Passwordless - A Practical Guide to Passkeys in ASP.NET Core - Maarten Balliauw
Going Passwordless - A Practical Guide to Passkeys in ASP.NET Core - Maarten Balliauw YouTube video by NDC Conferences

Recording of my talk on passkeys in #aspnetcore at NDC Copenhagen is up! #dotnet

Also includes a pointer on how to add passkeys to Razor Pages for folks who aren't on the #Blazor train.

www.youtube.com/watch?v=P7eb... #dotnet

20.01.2026 20:15 πŸ‘ 10 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration Learn the core benefits of building a federation gateway that brings together Entra ID, Okta, SAML, Auth0 though a centralized authentication provider like DUende IdentityServer.

Simplify your identity mess! 🀯

Learn how a Federation Gateway with Duende IdentityServer orchestrates all your IdPs (Entra ID, Google, SAML) for unified, agile security. Must-read architecture deep dive!

duende.link/8aefizq

#IdentityOrchestration #SSO #Security #dotnet

21.01.2026 17:30 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - adamralph/minver: 🏷 Minimalistic versioning using Git tags. 🏷 Minimalistic versioning using Git tags. Contribute to adamralph/minver development by creating an account on GitHub.

My OSS is developed by humans github.com/adamralph/mi...

24.01.2026 10:02 πŸ‘ 16 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration Learn the core benefits of building a federation gateway that brings together Entra ID, Okta, SAML, Auth0 though a centralized authentication provider like DUende IdentityServer.

Stop struggling with diverse identity providers. πŸ›‘

A Federation Gateway, such as Duende IdentityServer, is the key to:
πŸ”‘ Centralized Compliance
⚑️ Operational Agility
πŸ‘€ Unified User Login

duende.link/8aefizq

#IdentityOrchestration #SSO #Security #dotnet

07.01.2026 15:15 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Duende Resolution: Don't Store Tokens in the Browser. πŸ”

Browser tokens are an XSS risk. Secure your SPAs and Blazor WASM apps with the Duende BFF framework, the best way to handle protocol interactions and token management safely.

➑️ duende.link/bff4b1b

06.01.2026 20:02 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Join the Duende Insiders Discord Server! Check out the Duende Insiders community on Discord – hang out with 42 other members and enjoy free voice and text chat.

The Duende Product Insiders program is a private technical channel for partnership. Discuss Identity Strategy, Architecture, and Deployment Nuances directly with Duende experts. Stop guessing, start collaborating. πŸ™Œ

➑️ duende.link/discord

05.01.2026 20:02 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende Product Insiders We invite you to join a deeply technical, standards-driven community to help shape the future of .NET security and identity.

For devs who care about identity 🚨, Product Insiders get:

- Early access to features.

- Deep collaboration with Duende leaders.

- Direct influence on .NET identity & security.

Where standards meet code. Apply: duende.link/insiders

#DuendeInsiders #SecurityExperts

30.12.2025 19:02 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Secure frontend apps with the BFF Pattern Secure frontend apps with the Backend for Frontend (BFF) pattern. Simplify token management and boost security using Duende BFF v4, with multi-frontend support.

BFF v4: You can't secure what you can't see.

OpenTelemetry is baked right in for end-to-end observability of your auth journey (redirect, token exchange, API calls).

duende.link/bff4b1b

#OpenTelemetry #Observability #DuendeBFF #Diagnostics #Tracing

29.12.2025 19:01 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Join the Duende Insiders Discord Server! Check out the Duende Insiders community on Discord – hang out with 42 other members and enjoy free voice and text chat.

Your opinion on that tricky DPoP implementation? We want it. Duende Product Insiders is the high-signal, zero-noise channel for advanced .NET identity and security discussions. Join Duende's Product Insiders.

➑️ duende.link/discord

#dotnet #ZeroNoise #Identity

22.12.2025 08:01 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Join the Duende Insiders Discord Server! Check out the Duende Insiders community on Discord – hang out with 42 other members and enjoy free voice and text chat.

Identity developers, lead the way! Join Duende Product Insiders: Directly influence the roadmap, get early feature access, and collaborate with senior experts. Your expertise is needed.

Apply today: duende.link/discord

#DuendeInsiders #SecurityExperts

18.12.2025 08:01 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende BFFv4 is now available Duende BFFv4 is now available! Learn about multi-frontend, simplified security, and unlock end-to-end visibility with OpenTelemetry.

πŸ›‘οΈ BFF v4: Frontend Security Simplified

Frontend devs shouldn't handle tokens or refresh cycles. BFF keeps security on the server, eliminating XSS risks.

v4 adds multi-frontend support for operational sanity. Ditch the token burden entirely.

➑️ duende.link/bff4b0b

19.12.2025 08:00 πŸ‘ 1 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

Happy Holidays from the Duende Team! πŸŽ„

As the year winds down, we want to thank our amazing community for trusting Duende Software to secure your applications. We wish you and yours a wonderful holiday season filled with joy, rest, and peace.

Wishing you safe deployments and happy days!

17.12.2025 17:02 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Join the Duende Insiders Discord Server! Check out the Duende Insiders community on Discord – hang out with 42 other members and enjoy free voice and text chat.

Stop wishing for a feature. Start building it with us. The Duende Product Insiders program is your channel for direct influence on the IdentityServer and BFF roadmap.

Join the Insiders: duende.link/discord

#DuendeSoftware #IdentityServer

16.12.2025 20:00 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration Learn the core benefits of building a federation gateway that brings together Entra ID, Okta, SAML, Auth0 though a centralized authentication provider like DUende IdentityServer.

Stop struggling with diverse identity providers. πŸ›‘

A Federation Gateway, such as Duende IdentityServer, is the key to:
πŸ”‘ Centralized Compliance
⚑️ Operational Agility
πŸ‘€ Unified User Login

duende.link/8aefizq

#IdentityOrchestration #SSO #Security #dotnet

12.12.2025 09:15 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende BFFv4 is now available Duende BFFv4 is now available! Learn about multi-frontend, simplified security, and unlock end-to-end visibility with OpenTelemetry.

Duende BFF v4 is available! Architecturally, this is huge: you can now support multiple frontends from a single, robust backend. Plus, we've integrated OpenTelemetry for seamless end-to-end observability in your identity flow.

Simplify your stack: duendesoftware.com/blog/2025120...

11.12.2025 20:02 πŸ‘ 3 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
6 Used Cars That Are Way Too Cheap
6 Used Cars That Are Way Too Cheap YouTube video by Doug DeMuro

youtube.com/shorts/fseUv...

10.12.2025 11:21 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Generating SBOMs for .NET apps and NuGet packages with Microsoft.Sbom.Targets How to use the Microsoft.SBOM.Targets NuGet package to produce a Software Bill of Materials (SBOM) during your release builds.

Generating SBOMs for .NET apps and NuGet packages with Microsoft.Sbom.Targets

08.12.2025 09:46 πŸ‘ 27 πŸ” 8 πŸ’¬ 1 πŸ“Œ 1
Understanding the X-Content-Type-Options Header
Understanding the X-Content-Type-Options Header Ever wondered how browsers determine what kind of content they're displaying? It's usually through the Content-Type header. But what happens when that's missing or incorrect? That's where MIME type…

Ever wondered how browsers determine what kind of content they're displaying? It's usually through the Content-Type header. But what happens when that's missing or incorrect? It can be a serious security risk!

Let's see how to fix this in #aspnetcore youtu.be/kSaSb2hBbyk #dotnet

08.12.2025 16:15 πŸ‘ 0 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - dotnet/try: Try .NET provides developers and content authors with tools to create interactive experiences. Try .NET provides developers and content authors with tools to create interactive experiences. - dotnet/try

Farewell to try .NET a way to run code right in docs that allowed me to introduce a new set of developers and PMs to various security challenges and problems over 10 years.

It evolved from running lots of containers in weird isolation setups, all the way through to WASM.

03.12.2025 02:32 πŸ‘ 22 πŸ” 6 πŸ’¬ 2 πŸ“Œ 0