The idea of continually re-verifying the legitimacy of access, rather than stopping after one authentication.
An approach that treats authentication not as a one-time event but continually re-evaluates risk and legitimacy throughout the session. If a change in device state or suspicious behavior is detected, re-authentication can be required mid-session.
© 2026 ITBGM