Endpoint security integrations

You can integrate Okta Verify with your organization's endpoint detection and response (EDR) solution. When users try to access a protected resource, Okta Verify probes their device for context and trust signals and then uses these signals to determine an access decision. Endpoint security integration extends device posture evaluation by enabling Okta Verify to capture signals collected by your EDR client running on the same device. All signals are then sent to the Okta server and evaluated against the authentication policies that you have configured in the Okta Admin Console.

Okta currently supports integrations with CrowdStrike, Microsoft Windows Security Center, and Chrome Device Trust.

How endpoint security integrations work

Integrating Okta Verify with your endpoint detection and response (EDR) solution allows Okta Verify to serve as a device posture integration layer between the Okta server and EDR vendors that also have services running on end-user devices. When a user tries to access a protected resource, Okta Verify probes their device for context and trust signals and sends the information to the Okta server. The server evaluates the information against your Okta authentication policies to help inform the access decision.

Here's a high-level description of how it works.

  1. Plugins allow Okta Verify to communicate locally with the EDR client running on the same device:
  2. The plugin is invoked whenever a user uses Okta Verify as an authenticator to access a resource protected by an authentication policy that requires EDR signal(s).
  3. Okta Verify captures the signal(s) collected by the plugin and provides these to the Okta server when requested.
  4. EDR signals are cached in Okta for up to eight hours or until the session times out, whichever occurs first. The cache is updated whenever new signals are processed.
  5. The Okta server evaluates the signal(s) against the authentication policy and either allows or denies access to the resource.
  6. If access is denied for any reason:
    • The You do not have permission to perform the requested action message appears.
    • A system log message is generated that confirms that the authentication policy evaluation resulted in denied access. Admins can evaluate the context of the system log message together with information from the EDR dashboard to determine why access was denied.

Topics