"Identity is the new Perimeter "

I should have raged against this nonsense when it started to become a buzz phrase

Web-based Session management is the emperor's new clothes and identity based controls are left naked as a result.

@Enigma MFA is only target hardening. Malware on the endpoint will always be able to snag a session token post AuthN . Hence privileged access management solutions and PAWs