{"id":2730,"date":"2018-04-11T12:37:59","date_gmt":"2018-04-11T16:37:59","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=2730"},"modified":"2018-04-11T12:37:59","modified_gmt":"2018-04-11T16:37:59","slug":"key-authentication-findings-okta-blog-q1-2018","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/","title":{"rendered":"Key Authentication Findings from the Okta Security Blog, Q1 2018"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-2731\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/okta_logo-mod.png\" alt=\"okta authentication blog posts\" width=\"800\" height=\"400\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/key-findings-tools4ever-blog-q1-2018\/\" target=\"_blank\" rel=\"noopener\">Once<\/a> <a href=\"https:\/\/solutionsreview.com\/identity-management\/key-ciam-findings-ubisecure-blog-q1-2018\/\" target=\"_blank\" rel=\"noopener\">again<\/a> we at Solutions Review return to our <a href=\"https:\/\/solutionsreview.com\/identity-management\/key-identity-management-findings-centrify-blog-q1-2018\/\" target=\"_blank\" rel=\"noopener\">recurring series<\/a> of reading through the identity and access management blogs of major solutions providers for their key findings and best practices. After all, no one knows the direction of the idustry or the most worrisome threats than those on the front lines of the digital battle. This time the identity and access management blog of interest belongs to Californian vendor <\/span><a href=\"https:\/\/www.okta.com\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">Okta<\/span><\/a><span style=\"font-weight: 400\">. We read their most compelling authentication blog posts, including:<\/span><\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"iam-inject\" href=\"https:\/\/suggestionengine.solutionsreview.com\/buyer\/signup\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2021\/02\/Identity_Suggestion_Engine_Horiz_800.gif\" alt=\"IAM Solution Suggestion Engine\" width=\"800\" height=\"100\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n<h3 style=\"text-align: justify\"><span style=\"color: #3366ff\"><a style=\"color: #3366ff\" href=\"https:\/\/www.okta.com\/blog\/2018\/03\/international-womens-day-2018\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">International Women&#8217;s Day 2018: Lots to Celebrate, But Still Much to Do By Lorraine Costello<\/span><\/a><\/span><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">March\u2014Women\u2019s History Month\u2014may be over, but gender issues in cybersecurity raised in March persist every day of the year. Lorraine Costello\u2019s Okta blog post highlighted some key statistics about the depths of this disparity and what it means for gender equality overall as technology is the fastest-growing job market in the U.S. and is one of the best paid fields. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The statistics Costello and Okta share show a fundamental disconnect between men and women in the perception of women\u2019s positions and growth in cybersecurity. As just one example, 63% of men say their enterprise is taking steps to address the gender disparity in cybersecurity, but only 49% of women said the same.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Encouraging and accepting more women in cybersecurity isn\u2019t just about equality\u2014although that should be a powerful motivating factor\u2014it\u2019s also about creating the most comprehensive and secure cybersecurity solutions via different perspectives. \u00a0<\/span><\/p>\n<h3 style=\"text-align: justify\"><span style=\"color: #3366ff\"><a style=\"color: #3366ff\" href=\"https:\/\/www.okta.com\/security-blog\/2018\/04\/incident-response-in-the-cloud-%E2%80%93-is-your-security-team-ready\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">Incident Response in the Cloud \u2013 Is Your Security Team Ready? By Cameron Ero<\/span><\/a><\/span><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Okta acknowledges that digital transformation and cloud adoption can offer huge benefits to enterprises of any size, but with the caveat that identity security and incident response can suffer in the new IT environment. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A typical incident response tends to have four major components: information gathering, incident containment, threat removal, and damage assessment. For a compromised employee or privileged access identity, information gathering involves determining who\u2019s identity it is, what their permissions are, what systems they\u2019ve access recently, and what they did with that access. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Under a normal system, role-based controls, multifactor authentication, and audit logging can help enterprise IT security teams collect that vital information quickly and determine if the digital identity has been compromised. On the other hand, under a cloud system IT teams suffer from a much looser grip on their security options. Cloud providers\u2019 SaaS platforms don\u2019t offer nearly the same suite as an identity and access management solution; combined with the large number of cloud identities employees can have the time security experts spend gathering information can significantly increase along with threat dwell time.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">According to Okta, deploying an IAM or PAM solution with a centralized digital identity directory system, single sign-on, multifactor authentication, and cloud integration capabilities is essential to improve incident response time and keep a close eye on your identities. <\/span><\/p>\n<h3 style=\"text-align: justify\"><span style=\"color: #3366ff\"><a style=\"color: #3366ff\" href=\"https:\/\/www.okta.com\/security-blog\/2018\/03\/what-is-multi-factor-or-two-factor-authentication\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">What is Multi-factor, or Two-factor Authentication? By Teju Shayamsundar <\/span><\/a><\/span><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Okta agrees with us: passwords just don\u2019t cut it anymore. The old identity security paradigm of single factor authentication is insufficient to protect your employee and privileged access credentials in the modern threat age. Passwords by themselves are vulnerable to: <\/span><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Easy cracking or guessing <\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Phishing and spearphishing theft attacks <\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In contrast, two factor authentication (2FA) requires two forms of identity verification data before allowing users to access enterprise applications or systems. 2FA often combines a password with a hard token or an SMS a user\u2019s mobile device. It requires hackers to spoof whatever the second factor is in order to crack the employee\u2019s or privileged access user\u2019s credentials\u2014stopping or discouraging an attack. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Multifactor authentication, according to Okta, is basically two factor authentication with more flexibility on what the second factor is required: hard token, SMS, biometric, geofencing, etc. Deployed properly, it shouldn\u2019t disrupt the end user experience as some enterprises fear. What factors are required can even be based on roles, with more severe authentication factors required of privileged access users or to access privileged data. <\/span><\/p>\n<h3 style=\"text-align: justify\"><span style=\"color: #3366ff\"><a style=\"color: #3366ff\" href=\"https:\/\/www.okta.com\/security-blog\/2018\/03\/what-is-continuous-authentication\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">What is Continuous Authentication? By Nick Fisher <\/span><\/a><\/span><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Okta argues that current identity security trends mandate authentication as a process rather than as an event to prevent session imposters, credential stuffing, and phishing attacks. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In that vein, continuous authentication continually reevaluates if the user logged in is still the user that initially logged in. The solution makes this determination based on users\u2019 behavior, location, time of day, and the length of their session, and will ask them for new authentication factors if certain suspicion thresholds are met. Enterprises can set their own individual thresholds for what constitutes risky behavior or factors. <\/span><\/p>\n<h3 style=\"text-align: justify\"><span style=\"color: #3366ff\"><a style=\"color: #3366ff\" href=\"https:\/\/www.okta.com\/security-blog\/2018\/03\/5-identity-attacks-that-exploit-your-broken-authentication\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">5 Identity Attacks That Exploit Your Broken Authentication by Nick Fisher \u00a0<\/span><\/a><\/span><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Among old favorites phishing and spearphishing and newcomer man-in-the-middle-attacks, Okta introduces readers to much more insidious threats including credential stuffing\u2014a brute force attack in which already compromised credentials are used on other websites to see if something clicks. Also included is password spraying\u2014essentially the opposite of credential stuffing where the most common passwords are applied by a hacker to different accounts and usernames to see what sticks. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Both can be prevented by simply deploying an extra step to authentication, forcing hackers to work that much harder to reach your enterprise\u2019s data. This often means that hackers either can\u2019t crack your employee\u2019s credentials or will simply give up and look for an easier target. Either way is better for you. \u00a0<\/span><\/p>\n<br \/>Widget not in any sidebars<br \/>\n","protected":false},"excerpt":{"rendered":"<p>Once again we at Solutions Review return to our recurring series of reading through the identity and access management blogs of major solutions providers for their key findings and best practices. After all, no one knows the direction of the idustry or the most worrisome threats than those on the front lines of the digital [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[142,125,16,64,124,91,123,90,25],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Key Authentication Findings from the Okta Security Blog, Q1 2018<\/title>\n<meta name=\"description\" content=\"This time the identity and access management blog of interest belongs to Okta. We read their most compelling authentication blog posts.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/\",\"name\":\"Key Authentication Findings from the Okta Security Blog, Q1 2018\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/okta_logo-mod.png\",\"datePublished\":\"2018-04-11T16:37:59+00:00\",\"dateModified\":\"2018-04-11T16:37:59+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"This time the identity and access management blog of interest belongs to Okta. We read their most compelling authentication blog posts.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/okta_logo-mod.png\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/okta_logo-mod.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Key Authentication Findings from the Okta Security Blog, Q1 2018\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Key Authentication Findings from the Okta Security Blog, Q1 2018","description":"This time the identity and access management blog of interest belongs to Okta. We read their most compelling authentication blog posts.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/","url":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/","name":"Key Authentication Findings from the Okta Security Blog, Q1 2018","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/okta_logo-mod.png","datePublished":"2018-04-11T16:37:59+00:00","dateModified":"2018-04-11T16:37:59+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"This time the identity and access management blog of interest belongs to Okta. We read their most compelling authentication blog posts.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/okta_logo-mod.png","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/okta_logo-mod.png"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/key-authentication-findings-okta-blog-q1-2018\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Key Authentication Findings from the Okta Security Blog, Q1 2018"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/2730"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=2730"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/2730\/revisions"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=2730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=2730"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=2730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}