Products · Integrations
Identity Guardians
See automated identity threat protection in action, from detecting an exposed session to revoking it in Okta, Entra ID, and Active Directory.
Walk through remediation of an exposed password and active session across Active Directory, Entra ID, and Okta.
What you'll see
Revoke an exposed session, start to finish
SpyCloud Identity Guardians automatically remediate exposed workforce identities across the identity providers you run, resetting exposed passwords and revoking active sessions so a stolen credential or session cannot be used for access. This demo walks through how a security team sees a confirmed identity exposure with exposed session data and watches automated remediation close the access, whether the environment runs on Active Directory, Microsoft Entra ID, Okta Workforce Identity, or a combination of them.
The walkthrough follows an exposure from detection to remediation. SpyCloud confirms the exposed identity, the matching Identity Guardian revokes the exposed session and refresh token according to your policy, and every action is logged. You will see how the same workflow applies whether the exposure surfaces through continuous monitoring or at the moment a user tries to authenticate.
Review
Open
Revoke
Watch
Check
Same exposure, same automatic response across Okta, Entra ID, and Active Directory, whether your workforce identities are hosted on-prem, in hybrid environments, or fully cloud.
Outcomes of Automated Identity Threat Protection
5 min
in Active Directory
14x
1,000
per exposed credentials
HOW IT WORKS
Recapture, match, remediate, report
STEP 1
Recapture
SpyCloud recaptures exposed passwords, cookies, and tokens from the criminal underground.
STEP 2
Match
Match your workforce identity against that recaptured data to confirm exposed sessions.
STEP 3
Remediate
One policy resets the exposed password and revokes active sessions and refresh tokens.
STEP 4
Report
Logs every remediation action for audit and operational visibility.
CHOOSE YOUR FIT
Which Identity Guardian fits your environment?
Identity Guardians secure access no matter your identity architecture. Match your environment to the Guardian, or combination of Guardians, that protects it.
| YOUR ENVIRONMENT | RECOMMENDED GUARDIAN |
|---|---|
| On-premises or hybrid Active Directory | Active Directory Guardian |
| Microsoft cloud (Entra ID) | Entra ID Guardian |
| Okta cloud | Okta Workforce Guardian |
| Active Directory plus Entra ID or Okta | Active Directory Guardian with Entra ID Guardian and/or Okta Workforce Guardian |
| Multiple cloud identity providers | Entra ID Guardian and Okta Workforce Guardian |
THE IDENTITY GUARDIANS
What each Guardian does
Active Directory Guardian
On-premises & hybrid Active Directory
Holistic identity matching finds up to 14× more exposed passwords.
Entra ID Guardian
Microsoft Entra ID
Native session revocation plus automated password remediation.
Okta Workforce Guardian
Okta Workforce Identity
Universal Logout revokes sessions across connected apps.
Check Your Exposure
See your real-time breach exposure details powered by SpyCloud data.
Identity Guardian Demo FAQs
It shows how SpyCloud detects a confirmed workforce identity exposure and automatically remediates it across your identity provider, resetting the exposed password and revoking the exposed session according to policy. The walkthrough covers Active Directory, Microsoft Entra ID, and Okta Workforce Identity under one remediation policy.
It depends on your identity architecture. Active Directory Guardian protects on-premises and hybrid Active Directory, Entra ID Guardian protects Microsoft Entra ID, and Okta Workforce Guardian protects Okta Workforce Identity. Organizations running more than one identity provider can deploy the matching Guardians together under a single remediation policy.
A reset invalidates the password but does not end an active session. If an attacker captured a valid session cookie or refresh token, they can continue to access the account after the reset by replaying that session and bypassing MFA. Identity Guardians remediate the password and the session together, so stolen authentication artifacts do not outlive the reset.
In Okta Workforce Identity, Universal Logout ends the session across every connected application. In Microsoft Entra ID, session revocation runs natively. In Active Directory environments, Identity Guardians push a session termination signal to Okta to force re-authentication, which closes the session path even in passwordless environments.
SpyCloud identifies infostealer-malware exposures within five minutes of recapture and exposures from other criminal underground sources within hours. In Active Directory environments, automated password remediation can complete in as little as five minutes from discovery.