Okta:配置SaaS姿势集成

Prev Next

Overview

SaaS Posture integrations provide visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.

Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.

For more information, see Reviewing the Security Posture of Your SaaS Applications.

To configure the SaaS Posture integration, you need to:

  1. Configure the required settings in the SaaS application

  2. Create the API connector in the CMA

A CASB license is required for SaaS Posture integrations.

配置Okta集成

要配置Okta集成,请创建API令牌。

条件

  • 活跃的Okta组织

  • 具有超级管理员角色的专用Okta管理员账户

  • 访问Okta管理控制台并有权创建API令牌

步骤1:在Okta管理控制台中配置集成

在Okta管理控制台中,创建一个API令牌。

要配置Okta集成:

  1. 在Okta管理控制台,导航到安全性 > API。

  2. 在令牌标签页上,点击创建令牌。

  3. 添加描述。

  4. 根据您组织的安全策略配置令牌的网络区域限制。 确保选择的限制允许Cato服务连接到您的Okta组织。

  5. 点击创建令牌。

  6. 复制并保存令牌,以便输入到CMA中。

步骤2:在CMA中创建API连接器

在应用程序需要的集成设置之后,将详情添加到 CMA。

要在CMA中创建API连接器:

  1. 从导航菜单中,点击资源 > 集成。

  2. 点击 集成应用程序 标签。

  3. 新建集成 面板打开。

    新集成面板开启。

  4. 选择您要添加的 SaaS应用程序。

  5. 在 功能下拉菜单中,选择 SaaS姿态。

  6. 加入在步骤1中创建的详细信息:

    • Okta域名 - 您的Okta组织的基本URL,包括https://(不是您的管理控制台URL)。 包括示例:

      • https://companyname.okta.com

      • https://companyname.okta-emea.com

      • https://companyname.oktapreview.com

    • API令牌 - 您在步骤1中创建的令牌                                

  7. 应用程序在 集成的应用程序 表中显示,状态为 已连接。

  8. 应用程序在集成应用程序表中可见,并显示为已连接状态。

已知局限性

  • Okta的默认“列出所有用户API”会省略处于取消供应状态的用户,除非使用搜索或过滤。 连接器的用户列表可能不包括所有取消供应的帐户;Okta返回的已暂停帐户会被评估

  • 该连接器令牌由超级管理员创建,因此可以读取所有必需的组织范围的来源。 因此,该令牌可能出现在没有超级管理员拥有的API令牌 - Okta中。 将其视为记录在案的连接器异常,作为特权凭证保护,并根据组织的策略旋转。