Transcript
users can properly detect and deal with threats to the session after the application has been authenticated by the continuous risk assessment and automatic response function of the session. By linking the signals of third-party security products, users can automatically respond to real-time threats detected by third-party products. In this demonstration, the threat information of a user detected by Zscaler and Deception is linked to the ITP, and as a countermeasure, the user will see a series of actions such as automatically forcing the logout of all applications in use. The application session used by a user exposed to a threat is the cause of unauthorized access and data alteration. By forcing the logout immediately, the damage is limited by cutting and ending, and the risk can be minimized. First, we will implement the Entity Risk Policy used in this demo. This policy is to force the logout of all applications including Okta's end-user dashboard when a risk is reported from a third-party security product that is a security event provider. First, in order to check the behavior of this function, the user will log in to the Okta end-user dashboard. From there, single-sign-on to the Google Keep, Salesforce, and Google Cloud Console. Here, Zscaler and Deception detect a threat, and the information is linked to the ITP. Let's check the session status of the Okta end-user dashboard and the three applications we logged in earlier. If you refresh the browser like this, you can see that all applications are forcibly logged out. Let's take a look at the system log. We will search for the log for the risk report by the target security event provider. We will deploy this log. In this way, Zscaler and Deception detect a lure, and the information is linked to the ITP. By using the ITP like this, you can deal with the threat of the session after logging in in real time.