<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Authentication/Single Sign-on/User Directory on SolCyber Knowledgebase</title><link>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/</link><description>Recent content in Authentication/Single Sign-on/User Directory on SolCyber Knowledgebase</description><generator>Hugo</generator><language>en</language><atom:link href="https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/index.xml" rel="self" type="application/rss+xml"/><item><title>DUO Security</title><link>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/duo-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/duo-security/</guid><description>&lt;blockquote class='book-hint note' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;circle cx="12" cy="12" r="10"/&gt;&lt;path d="M12 16v-4"/&gt;&lt;path d="M12 8h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;Note that only administrators with the &lt;a href="https://duo.com/docs/admin-roles"&gt;Owner&lt;/a&gt; role can create or modify an Admin API application in the Duo Admin Panel.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Securonix supports ingestion of the following types of DUO logs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Duo Security Administrator&lt;/li&gt;
&lt;li&gt;Duo Security Authentication&lt;/li&gt;
&lt;/ul&gt;
&lt;ol&gt;
&lt;li&gt;Log in to the &lt;a href="https://admin.duosecurity.com/"&gt;Duo Admin Panel&lt;/a&gt; and navigate to &lt;strong&gt;Applications&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;Protect an Application&lt;/strong&gt; and locate the entry for &lt;strong&gt;Admin API&lt;/strong&gt; in the applications list. Click &lt;strong&gt;Protect&lt;/strong&gt; to the far-right to configure the application and get your &lt;strong&gt;integration key, secret key, and API hostname&lt;/strong&gt;. You&amp;rsquo;ll need to provide these credentials to SolCyber via onetimesecret.com or other secure methods. &lt;/li&gt;
&lt;li&gt;The required permissions are:
&lt;ul&gt;
&lt;li&gt;Grant read log&lt;/li&gt;
&lt;li&gt;Grant read information&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;figure&gt;&lt;img src="https://kb.solcyber.com/assets/duo.png" alt=""&gt;&lt;figcaption&gt;&lt;/figcaption&gt;&lt;/figure&gt;</description></item><item><title>EntraID (aka Azure Active Directory) User Import</title><link>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/azure-active-directory-user-import/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/azure-active-directory-user-import/</guid><description>&lt;ul&gt;
&lt;li&gt;Login to &lt;strong&gt;Azure&lt;/strong&gt; portal.&lt;/li&gt;
&lt;li&gt;Locate &lt;strong&gt;App registrations&lt;/strong&gt; using the &lt;strong&gt;Search&lt;/strong&gt; bar from &lt;strong&gt;Dashboard&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%28188%29.png" alt="" /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click &lt;strong&gt;New Registration&lt;/strong&gt; from the &lt;strong&gt;App registrations&lt;/strong&gt; screen to register an application.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%2868%29.png" alt="" /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provide the following details in the &lt;strong&gt;Register an application&lt;/strong&gt; screen:&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; &lt;strong&gt;Name&lt;/strong&gt;: Securonix AzureAD Users&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; &lt;strong&gt;Supported account Types&lt;/strong&gt;: Select the &lt;strong&gt;Accounts in this organizational directory only&lt;/strong&gt; option.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Click &lt;strong&gt;Register&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Make a copy of &lt;strong&gt;Application (client ID)&lt;/strong&gt; and &lt;strong&gt;Directory (tenant ID)&lt;/strong&gt; for the application from the Application screen.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%28175%29.png" alt="" /&gt;&lt;/p&gt;</description></item><item><title>EntraID (AzureAD) Risky Users and Detections</title><link>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/entraid-azuread-risky-users-and-detections/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/entraid-azuread-risky-users-and-detections/</guid><description>&lt;blockquote class='book-hint warning' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;path d="M10.29 3.86 1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z"/&gt;&lt;path d="M12 9v4"/&gt;&lt;path d="M12 17h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;ul&gt;
&lt;li&gt;An &lt;strong&gt;Azure P1 or P2&lt;/strong&gt; license is required to ingest Azure Risky Users events. &lt;/li&gt;
&lt;li&gt;An &lt;strong&gt;Azure P2&lt;/strong&gt; license is required to ingest Azure Risky Detection events.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Logon to the &lt;a href="https://portal.azure.com/"&gt;Azure portal&lt;/a&gt; as an admin and search for &lt;strong&gt;Apps registration&lt;/strong&gt; from the top search bar.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%28145%29.png" alt="" /&gt;&lt;/p&gt;</description></item><item><title>EntraID (aka Azure Active Directory) Audit/Sign In</title><link>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/entraid-aka-azure-active-directory-audit-sign-in/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/entraid-aka-azure-active-directory-audit-sign-in/</guid><description>&lt;h1 id="ms-entra-aka-azure-active-directory-auditsign-in"&gt;MS Entra (aka Azure Active Directory) Audit/Sign In&lt;a class="anchor" href="#ms-entra-aka-azure-active-directory-auditsign-in"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class='book-hint warning' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;path d="M10.29 3.86 1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z"/&gt;&lt;path d="M12 9v4"/&gt;&lt;path d="M12 17h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;You must have an &lt;strong&gt;MS Entra ID P1 or P2 license&lt;/strong&gt; in order to export Entra/Azure Active Directory Sign In logs. These logs provide us visibility into all authentication attempts to Azure AD accounts and are an important source of intel in the case of compromised accounts. We recommend that customers either move to a different M365 license or, at a minimum, purchase an &lt;strong&gt;Azure P1&lt;/strong&gt; license as an add on, &lt;em&gt;especially&lt;/em&gt; if the company uses AzureAD as an IDP for Single Sign On.&lt;/p&gt;</description></item><item><title>Google Directory</title><link>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/google-directory/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/google-directory/</guid><description>&lt;p&gt;&lt;strong&gt;Follow the documentation for Google Workspace in the Cloud Services/SaaS category:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a class="kb-content-card" href="https://kb.solcyber.com/supported-data-sources-categories/cloud-services-saas/google-workspace/"&gt;&lt;span class="kb-card-body"&gt;&lt;span class="kb-card-title"&gt;Google Workspace&lt;/span&gt;&lt;span class="kb-card-desc"&gt;Complete the following steps to configure the Google Workspace connection using OAuth2.0&lt;/span&gt;&lt;/span&gt;&lt;span class="kb-card-arrow" aria-hidden="true"&gt;→&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description></item><item><title>JumpCloudSSO</title><link>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/jumpcloudsso/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/jumpcloudsso/</guid><description>&lt;ul&gt;
&lt;li&gt;Log in to the JumpCloud SSO portal: &lt;a href="https://console.jumpcloud.com/"&gt;https://console.jumpcloud.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Click the circle in the top right corner of the screen.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%2875%29.png" alt="" /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click &lt;strong&gt;API Settings&lt;/strong&gt;. Your API key will appear.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class='book-hint note' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;circle cx="12" cy="12" r="10"/&gt;&lt;path d="M12 16v-4"/&gt;&lt;path d="M12 8h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;&lt;strong&gt;Warning:&lt;/strong&gt; Because Jumpcloud has only one API key per site, any change will stop your JumpCloud datasource from ingesting data. Please communicate this impact with your SolCyber administrators.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;</description></item><item><title>Okta System Authentication</title><link>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/okta-system-authentication/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/authentication-single-sign-on-user-directory/okta-system-authentication/</guid><description>&lt;ul&gt;
&lt;li&gt;Navigate to the &lt;a href="https://login.okta.com/"&gt;Okta login screen&lt;/a&gt; and sign in with your credentials.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%2840%29.png" alt="" /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click &lt;strong&gt;API &amp;gt; Tokens&lt;/strong&gt; from the navigation menu. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%2819%29.png" alt="" /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click &lt;strong&gt;Create Token&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%2856%29.png" alt="" /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enter a name for your token, then click &lt;strong&gt;Create Token&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%28235%29.png" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;The token name above will be used within SNYPR when you set up the Okta connector.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Make a note of the &lt;strong&gt;Token Value&lt;/strong&gt; then click &lt;strong&gt;OK, got it&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%28124%29.png" alt="" /&gt;&lt;/p&gt;</description></item></channel></rss>