Demo Center Home > Identity Guardians Demo
Automatically remediate exposed passwords and active sessions to secure corporate access. Walk through what a modern combolist actually contains,
and how SpyCloud matches it to your workforce and automates the response.
IDENTITY GUARDIANS by SpyCloud
SpyCloud Identity Guardians automatically remediate exposed workforce identities across the identity providers you run, resetting exposed passwords and revoking active sessions so a stolen credential or session cannot be used for access.
The walkthrough follows an exposure from detection to remediation. SpyCloud confirms the exposed identity, the matching Identity Guardian revokes the exposed session and refresh token according to your policy, and every action is logged. You will see how the same workflow applies whether the exposure surfaces through continuous monitoring or at the moment a user tries to authenticate.
SpyCloud recaptures exposed passwords, cookies, and tokens from the criminal underground.
Match your workforce identity against that recaptured data to confirm exposed sessions.
One policy resets the exposed password and revokes active sessions and refresh tokens.
Logs every remediation action from exposed sessions for audit insights and operational visibility.
Identity Guardians secure access no matter your identity architecture. Match your environment to the Guardian, or combination of Guardians, that protects it.
| YOUR ENVIRONMENT | RECOMMENDED GUARDIAN |
|---|---|
| On-premises or hybrid Active Directory | Active Directory Guardian |
| Microsoft cloud (Entra ID) | Entra ID Guardian |
| Okta cloud | Okta Workforce Guardian |
| Active Directory plus Entra ID or Okta | Active Directory Guardian with Entra ID Guardian and/or Okta Workforce Guardian |
| Multiple cloud identity providers | Entra ID Guardian and Okta Workforce Guardian |
On-premises & hybrid Active Directory
Holistic identity matching finds up to 14× more exposed passwords.
Microsoft Entra ID
Native session revocation plus automated password remediation.
Okta Workforce Identity
Universal Logout revokes sessions across connected apps.
See your real-time breach exposure details powered by our data.
It shows how SpyCloud detects a confirmed workforce identity exposure and automatically remediates it across your identity provider, resetting the exposed password and revoking the exposed session according to policy. The walkthrough covers Active Directory, Microsoft Entra ID, and Okta Workforce Identity under one remediation policy.
It depends on your identity architecture. Active Directory Guardian protects on-premises and hybrid Active Directory, Entra ID Guardian protects Microsoft Entra ID, and Okta Workforce Guardian protects Okta Workforce Identity. Organizations running more than one identity provider can deploy the matching Guardians together under a single remediation policy.
A reset invalidates the password but does not end an active session. If an attacker captured a valid session cookie or refresh token, they can continue to access the account after the reset by replaying that session and bypassing MFA. Identity Guardians remediate the password and the session together, so stolen authentication artifacts do not outlive the reset.
In Okta Workforce Identity, Universal Logout ends the session across every connected application. In Microsoft Entra ID, session revocation runs natively. In Active Directory environments, Identity Guardians push a session termination signal to Okta to force re-authentication, which closes the session path even in passwordless environments.
SpyCloud identifies infostealer-malware exposures within five minutes of recapture and exposures from other criminal underground sources within hours. In Active Directory environments, automated password remediation can complete in as little as five minutes from discovery.
NEW RESEARCH: Over 2/3 of orgs had an identity event last year – NHIs were the top cause. Read on →