惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
A
About on SuperTechFans
博客园 - Franky
Engineering at Meta
Engineering at Meta
Recent Announcements
Recent Announcements
云风的 BLOG
云风的 BLOG
B
Blog
Microsoft Security Blog
Microsoft Security Blog
L
LangChain Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
Martin Fowler
Martin Fowler
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
博客园 - 叶小钗
Vercel News
Vercel News
Apple Machine Learning Research
Apple Machine Learning Research
The Cloudflare Blog
Last Week in AI
Last Week in AI
腾讯CDC
Microsoft Azure Blog
Microsoft Azure Blog
爱范儿
爱范儿
V
V2EX
G
Google Developers Blog

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Protect your Okta identities with Wiz
Shaked Rotlevi, Yariv Ashkenazy · 2024-10-23 · via Wiz Blog | RSS feed

Protecting identities in the cloud is paramount to ensuring the security and integrity of your data and resources. Misconfigured identities or identity-related risks can create an entry point into your cloud environment and even lead to lateral paths, and eventually your crown jewels. Such identity risks can put an environment at critical risk such as a breach or account takeover and according to Verizon, 77% of attacks involve compromised credentials. That is why it is crucial to implement robust identity protection measures in place. 

To reduce the overhead of securely managing identities, many organizations leverage Okta for cloud federation and identity management. Okta helps organizations manage authentication into their cloud version control systems (such as GitHub), and other SaaS platforms and provides an easy and secure way for them to centrally manage identities and the applications they build. With Okta, users get an easy and secure login that removes passwords and leverages a user-friendly authentication flow.  

Today, we are adding support for Okta to enable customers to secure their cloud identities managed by Okta by gaining deep visibility into Okta users and API tokens, their cloud permissions, misconfigurations and related risks, and real-time threats. With this launch, mutual customers can effectively protect their Okta identities and remove risk from their Okta and cloud environment. 

Secure your Okta entitlements with Wiz 

Full Visibility into Okta Identities 

To effectively protect cloud entitlements, organizations need to successfully answer “Do I know what all my cloud identities and their permissions are?”. Therefore, the first step is to obtain a centralized view of all your identities, no matter where they are managed, along with their cloud permissions. Customers can now gain comprehensive visibility into Okta identities, which are also modeled on the Wiz Security Graph, so they can easily identify which users are in which groups, and what their effective permissions in the cloud are.  

Analyze effective permissions to identify high-privileges, admin, and excessive permissions 

After answering “who can access what?”, organizations need to consider whether the given permissions follow the principle of least privilege and answer “are the effective permissions properly scoped?”. With this launch, Wiz automatically identifies Okta identities that have cloud high privileges or admin permissions so you can easily detect and scope down permissions. You can also detect Okta identities with excessive permissions in the cloud and get granular recommendations to adjust these permissions. This enables you to follow guided remediation steps to reduce access and revoke unused permissions effectively. 

In addition, Wiz now extends our attack path analysis to Okta, correlating misconfigurations and other CIEM information to cloud risks such as sensitive data, vulnerabilities, and exposed secrets to detect attack paths that can result in a critical risk such as a breach or account takeover. This enables customers to understand and proactively remove Okta to cloud attack paths.

Enforce secure configuration in Okta

“How do I establish security best practices to protect my Okta organization?” is the question organizations need to ask next. Misconfigured security settings can pose significant security risks. Wiz helps identify those misconfigured settings in Okta through built-in checks. For example, these checks assess to see if that there is an MFA policy for the user that requires hardware authenticator, as well as a check to evaluate that the password policies adhere to Okta’s recommendations. You can quickly identify deviations from security best practices and remediate to increase the security posture of your Okta environment.

Remove threats in Okta in near real-time 

Not only are customers empowered to proactively remove identity risks in their environment, but they can now also detect threats in near real-time in Okta. We've introduced new built-in threat detection rules for Okta which enable customers to quickly identify and respond to potential threats, such as an Okta user that had MFA deactivated or MFA enumeration brute force. With the graph-based context, you can easily understand what is the blast radius of such a threat in the cloud and reduce its impact.

Wiz's support for Okta empowers customers to protect their cloud identities and remove risk, from prevention to detection. Get started now with protecting your Okta identities, you can learn more in the Wiz docs (login needed). If you prefer a live demo, we would love to connect with you.