Information
Ideally user names and passwords user within an organization are not used with third party site. Some sanctioned SAS applications may have connections to the corporate domain, in which case they will need to be exempt from the user credential submission policy through a custom URL category.
Rationale:
Preventing users from having the ability to submit their corporate credentials to the Internet could stop credential phishing attacks and the potential that a breach at a site where a user reused credentials could lead to a credential stuffing attack.
Solution
Navigate to Objects > Security Profiles > URL Filtering.
Set the user credential submitting action on all URL categories listed to Block.
Under the "User Credential Detection" tab set user credential detection to Use IP User Mapping. This requires User-ID to be configured and decryption to be effective.
Impact:
Not preventing users from submitting their corporate credentials to the Internet can leave them open to phishing attacks or allow for credential reuse on unauthorized sites.
Default Value:
Not Configured