Identity Guardians

HOW SPYCLOUD IDENTITY GUARDIANS SECURE ACCESS ACROSS AD, ENTRA ID, AND OTKA

Identity Guardians

SpyCloud Identity Guardians help secure access across your workforce by detecting and remediating exposed identity data across Active Directory, Microsoft Entra ID, and Okta Workforce environments.

Identity Guardians address two types of exposures: exposed passwords and stolen session data. The Identity Guardian capabilities you need depend on where your organization manages passwords and where users authenticate and maintain sessions.

Use this guide to determine which Identity Guardian applies to your environment, then read the individual guides for setup and configuration.

How Identity Guardians secure access

A workforce identity can be exposed through both its credentials and its active sessions. Each requires a different remediation action:

  • Password remediation addresses an exposed password by resetting it or initiating another configured account action.
  • Session revocation addresses exposed authentication artifacts, such as session cookies and refresh tokens, by terminating affected sessions so those artifacts can no longer provide access.

These capabilities don't always run in the same identity system.

A simple way to determine your coverage: Password remediation follows where the password is managed. Session remediation follows where the session is managed.

For example, your organization might manage passwords in Active Directory while users authenticate through Entra ID or Okta. In that environment, Active Directory Guardian handles password remediation, while the corresponding Entra ID or Okta Workforce Guardian handles session remediation.


Which Identity Guardians apply to my environment?

Use the table below to identify the Guardian capabilities that apply based on where your workforce passwords and sessions are managed.

Identity environmentGuardian(s)Coverage
AD onlyActive Directory GuardianUse ADG for password scanning and remediation.
AD + Entra ID – synced accountsActive Directory Guardian + Entra ID GuardianUse ADG for passwords managed in AD and Entra ID Guardian to remediate exposed Entra ID sessions.
AD + Entra ID – cloud-only Entra accountsActive Directory Guardian + Entra ID GuardianUse ADG for passwords managed in AD. Use Entra ID Guardian to detect exposed passwords for cloud-only Entra accounts and remediate exposed Entra ID sessions.
Entra ID onlyEntra ID GuardianUse Entra ID Guardian for both password and session remediation.
AD + OktaActive Directory Guardian + Okta Workforce GuardianUse ADG for passwords managed in AD and Okta Workforce Guardian for Okta session remediation. ADG can also make an API call to Okta to revoke sessions after a confirmed password match for an AD employee.
Okta onlyOkta Workforce GuardianUse Okta Workforce Guardian for both password and session remediation.

Identity Guardian overview

SpyCloud supports Identity Guardians for Active Directory, Microsoft Entra ID, and Okta Workforce. Depending on your identity environment, you may use one Guardian or combine Guardians to address both password and session exposure.

SpyCloud Identity GuardianIdentity systemPassword remediationSession remediation
Active Directory Guardian (ADG)Active DirectoryA locally deployed app scans supported AD accounts for exposed passwords and initiates configured remediation actions.In AD + Okta environments, ADG can initiate an API call to Okta to revoke sessions after a confirmed password match.
Entra ID GuardianMicrosoft Entra IDAn Azure app checks supported Entra ID accounts for exposed passwords and supports remediation.Through the SpyCloud console, identifies exposed authentication artifacts and terminates affected Entra ID sessions.
Okta Workforce GuardianOkta WorkforceThrough SpyCloud-provided Okta Workflows, checks supported Okta identities for exposed passwords and supports automated remediation.Through the SpyCloud console, identifies exposed authentication artifacts, terminates affected Okta sessions, and triggers Universal Logout.

Active Directory Guardian

Active Directory Guardian (ADG) supports organizations that manage workforce passwords in Microsoft Active Directory.

ADG is a locally deployed app that checks AD accounts against SpyCloud exposure data. When ADG identifies a password match, it can initiate configured remediation actions for the affected account.

ADG telemetry is available in the SpyCloud console, giving you visibility into Guardian activity.

If you use Active Directory with Okta, ADG can also initiate an API call to Okta to revoke sessions after a confirmed credential match.

For details about supported scans, deployment, configuration, remediation workflows, and the ADG-to-Okta workflow, see the Active Directory Guardian guide.


Entra ID Guardian

Entra ID Guardian supports both password and session remediation for Microsoft Entra ID environments. The two capabilities are configured separately.

Passwords

Entra ID Guardian password coverage runs as an Azure app. It checks supported Entra ID accounts for exposed passwords and supports remediation when an exposure is identified.

For deployment, configuration, supported scanning, and password remediation, see the Entra ID Guardian credential guide.

Sessions

Entra ID Guardian session remediation is managed through the SpyCloud console. It checks for exposed authentication artifacts associated with Entra ID identities and can automatically revoke affected sessions.

For configuration and session remediation, see the Entra ID Guardian session guide.


Okta Workforce Guardian

Okta Workforce Guardian supports both password and session remediation for organizations using Okta Workforce. The two capabilities are configured separately.

Passwords

Okta Workforce Guardian checks supported Okta identities for exposed passwords. Password remediation is handled through Okta Workflows provided by SpyCloud.

For setup, supported password checks, and remediation configuration, see the Okta Workforce Guardian credential guide.

Sessions

Okta Workforce Guardian session remediation is managed through the SpyCloud console. It checks for supported exposed authentication artifacts associated with Okta identities and can terminate affected sessions and trigger Universal Logout.

For configuration and session remediation, see the Okta Workforce Guardian session guide.




Did this page help you?