3.1 Disabling Unused Authentication Protocols

You must disable any authentication protocol that is not in use. Enabling additional protocols increases the attack surface area.

Go to Identity Servers > [cluster name] > Configuration > General and ensure to deselect unused protocols in Enabled Protocols.