Okta: SaaSポスチャー統合の設定

Prev Next

Overview

SaaS Posture integrations provide visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.

Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.

For more information, see Reviewing the Security Posture of Your SaaS Applications.

To configure the SaaS Posture integration, you need to:

  1. Configure the required settings in the SaaS application

  2. Create the API connector in the CMA

A CASB license is required for SaaS Posture integrations.

Okta統合の設定

Okta統合を設定するには、APIトークンを作成します。

前提条件

  • アクティブなOkta組織

  • スーパー管理者ロールを持つ専用のOkta管理者アカウント

  • Okta管理コンソールへのアクセスとAPIトークン作成の権限

ステップ1: Okta管理コンソールで統合の設定

Okta管理コンソールでAPIトークンを作成する。

Okta統合を設定するには:

  1. Okta管理コンソールでセキュリティ > APIに進みます。

  2. トークンタブで、トークンを作成をクリックします。

  3. 説明を追加します。

  4. トークンのネットワークゾーン制限を組織のセキュリティポリシーに従って設定します。 選択した制限がCatoサービスがOkta組織に接続することを許可していることを確認します。

  5. トークンを作成をクリックします。

  6. トークンをコピーして保存し、それをCMAに入力できるようにします。

ステップ 2: CMAでのAPIコネクタ作成

必要なアプリケーションとの統合設定後、その詳細を CMA に追加します。

CMAでAPIエンドポイントコネクタを作成するには:

  1. ナビゲーションメニューから、リソース > 統合 をクリックします。

  2. 統合されたアプリケーション タブをクリックします。

  3. 「新規」をクリックします。

    新しい統合 パネルが開きます。

  4. 追加する SaaSアプリケーション を選択します。

  5. 機能ドロップダウンでSaaSポスチャーを選択します。

  6. 手順1で作成した詳細を追加します:

    • Oktaドメイン - Okta組織のベースURLを含むhttps://(管理コンソールURLではありません)。 例には次のものが含まれます:

      • https://companyname.okta.com

      • https://companyname.okta-emea.com

      • https://companyname.oktapreview.com

    • APIトークン - 手順1で作成したトークン                                

  7. 保存をクリック。

  8. アプリは、統合されたアプリ 表に 接続済み 状態で表示されます。

確認された制限事項

  • Oktaのデフォルトの全ユーザーAPIは、検索またはフィルタが使用されない限り、DEPROVISIONEDステータスのユーザーを省略します。 コネクタのユーザーリストはすべての非供給アカウントを含まないことがあります。Oktaが返す一時停止されたアカウントは評価されます。

  • スーパー管理者によって作成されたコネクタトークンは、必要な組織全体のソースをすべて読むことができます。 その結果、そのトークンはスーパー管理者の所有するAPIトークンには表示されません - Okta。 それを文書化されたコネクタの例外として扱い、特権資格情報として保護し、組織のポリシーに従って回転させます。