[weglot_switcher]

Products · Integrations

Identity Guardians

See automated identity threat protection in action, from detecting an exposed session to revoking it in Okta, Entra ID, and Active Directory.

Security dashboard showing user verification and revoke options.

Walk through remediation of an exposed password and active session across Active Directory, Entra ID, and Okta.

What you'll see

Revoke an exposed session, start to finish

SpyCloud Identity Guardians automatically remediate exposed workforce identities across the identity providers you run, resetting exposed passwords and revoking active sessions so a stolen credential or session cannot be used for access. This demo walks through how a security team sees a confirmed identity exposure with exposed session data and watches automated remediation close the access, whether the environment runs on Active Directory, Microsoft Entra ID, Okta Workforce Identity, or a combination of them.

The walkthrough follows an exposure from detection to remediation. SpyCloud confirms the exposed identity, the matching Identity Guardian revokes the exposed session and refresh token according to your policy, and every action is logged. You will see how the same workflow applies whether the exposure surfaces through continuous monitoring or at the moment a user tries to authenticate.

Review
a queue of workforce identities exposing active session data, recaptured from infostealer malware and 2FA phishing kits
Open
one finding to see exactly what was taken, including the session cookies and refresh tokens
Revoke
the session and OAuth refresh token in your Okta tenant in one click
Watch
the identity flip to Revoked, so the stolen token is dead and the next attempt forces a fresh login
Check
the audit log: who acted, when, and the raw data sent to your IdP

Same exposure, same automatic response across Okta, Entra ID, and Active Directory, whether your workforce identities are hosted on-prem, in hybrid environments, or fully cloud.

Outcomes of Automated Identity Threat Protection

5 min

Time to remediate exposed passwords
in Active Directory

14x

More exposed passwords found with holistic identity matching

1,000

Password variations tested
per exposed credentials

HOW IT WORKS

Recapture, match, remediate, report

STEP 1

Recapture

SpyCloud recaptures exposed passwords, cookies, and tokens from the criminal underground.

STEP 2

Match

Match your workforce identity against that recaptured data to confirm exposed sessions.

STEP 3

Remediate

One policy resets the exposed password and revokes active sessions and refresh tokens.

STEP 4

Report

Logs every remediation action for audit and operational visibility.

CHOOSE YOUR FIT

Which Identity Guardian fits your environment?

Identity Guardians secure access no matter your identity architecture. Match your environment to the Guardian, or combination of Guardians, that protects it.

YOUR ENVIRONMENT RECOMMENDED GUARDIAN
On-premises or hybrid Active Directory Active Directory Guardian
Microsoft cloud (Entra ID) Entra ID Guardian
Okta cloud Okta Workforce Guardian
Active Directory plus Entra ID or Okta Active Directory Guardian with Entra ID Guardian and/or Okta Workforce Guardian
Multiple cloud identity providers Entra ID Guardian and Okta Workforce Guardian

THE IDENTITY GUARDIANS

What each Guardian does

Active Directory Guardian

On-premises & hybrid Active Directory

Holistic identity matching finds up to 14× more exposed passwords.

Entra ID Guardian

Microsoft Entra ID

Native session revocation plus automated password remediation.

Okta Workforce Guardian

Okta Workforce Identity

Universal Logout revokes sessions across connected apps.

Check Your Exposure

See your real-time breach exposure details powered by SpyCloud data.

Identity Guardian Demo FAQs

It shows how SpyCloud detects a confirmed workforce identity exposure and automatically remediates it across your identity provider, resetting the exposed password and revoking the exposed session according to policy. The walkthrough covers Active Directory, Microsoft Entra ID, and Okta Workforce Identity under one remediation policy.

It depends on your identity architecture. Active Directory Guardian protects on-premises and hybrid Active Directory, Entra ID Guardian protects Microsoft Entra ID, and Okta Workforce Guardian protects Okta Workforce Identity. Organizations running more than one identity provider can deploy the matching Guardians together under a single remediation policy.

A reset invalidates the password but does not end an active session. If an attacker captured a valid session cookie or refresh token, they can continue to access the account after the reset by replaying that session and bypassing MFA. Identity Guardians remediate the password and the session together, so stolen authentication artifacts do not outlive the reset.

In Okta Workforce Identity, Universal Logout ends the session across every connected application. In Microsoft Entra ID, session revocation runs natively. In Active Directory environments, Identity Guardians push a session termination signal to Okta to force re-authentication, which closes the session path even in passwordless environments.

SpyCloud identifies infostealer-malware exposures within five minutes of recapture and exposures from other criminal underground sources within hours. In Active Directory environments, automated password remediation can complete in as little as five minutes from discovery.

X