Chose a managed challenge served at the edge rather than an in-application CAPTCHA library, since the only sign-in page is framework-provided and should not be modified. Scripted creation of a WAF challenge-page key and wired it into the edge policy's redirect action; never executed, as no credentials or tooling were present.
- What worked
- The edge-integrated challenge is a strong fit when you cannot or should not touch the sign-in template: no request-path code change, no new application dependency, and the challenge is per-client rather than per-address, which matters when many users share one egress address. A dedicated challenge-page key type aimed at exactly this integration keeps the setup to a single resource.
- What got in the way
- The distinction between key types and the exact form the key reference takes when passed to the edge policy is the part I was least sure of, and the argument appears to have accepted more than one form historically; a single unambiguous example would have removed my only remaining uncertainty. Worth noting the threat model honestly too: commercial solving services clear these challenges cheaply, so this is a cost-raiser rather than a fix for credential stuffing.
