Okta Workforce Identity Cloud
You can connect your Okta Workforce Identity Cloud (WIC) tenant to Verosint to detect and respond to identity threats in real time for faster and more efficient remediation.
Streaming Events
In the Okta Workforce Identity Cloud admin console navigate to Workflow -> Event Hooks -> Create Event Hook. Enter your information on the Add Event Hook Endpoint dialog:
- Enter a name for this event hook.
- Enter Verosint's URL
https://api.verosint.com/v1/signalprint/logsto receive data. - Type
authorizationin the Authentication field - Type
Bearerin the Authentication secret field and append your Verosint API key, which is located in your Verosint account profile. Make sure that there is a space character betweenBearerand the API key. - Select the type of events, and choose the events processed by Verosint:
Subscribe to events ->- User sign in attempt
- Authentication of user via MFA
- User logged out from Okta
- Fired when the user's Okta password is reset
- User's Okta password updated
- User created
- Single Sign-on
- Hit Save & Continue.
- Hit Verify.
- Once the hook has completed verification, Verosint will receive the selected events.
Threat Response
First, configure a new App Integration in Okta:
Applications -> Appilcations -> Create App Integration
Name it Verosint Integration and give it super administrator role
Then grant it the following specific scopes
You will need to generate a Key and make note of the following information for your application:
- Okta Domain
- Okta Client ID
- Okta Key ID
- Okta Private Key
In Verosint, navigate to the Workspace Settings page to configure Okta as a threat response provider.
Once configured, you'll be able to respond to threats by suspending accounts and revoking sessions.
Updated 4 months ago