Any creative solution to make it harder for hackers to copy your IdP login page?

> I only want to say, this way its possible for attackers to guess usernames.
> In my personal opinion the first step of a possible attack.

As soon as you go down that road, you are trapped into expensive rules around what systems can make use of the username as an identifier, and that is a disaster in most cases.

> After this attackers could bruteforce passwords target-oriented.

Phishing is too easy to make it worth the time.

