Integration Category
Identity Provider Integrations
Okta, Microsoft Entra ID, Duo, Ping Identity, JumpCloud, CyberArk — ManySignal correlates authentication, MFA, session, and privilege events from all your identity providers into a unified threat detection timeline.
Supported integrations
Identity and access management platforms
Okta
Authentication, MFA, session, user lifecycle, admin events
Microsoft Entra ID
Sign-in, audit, risky users, Conditional Access policy events
Auth0
Login events, user management, anomaly detection, MFA events
Ping Identity
PingFederate, PingOne, PingAccess authentication and admin events
Duo Security
Authentication logs, MFA responses, admin actions
JumpCloud
Directory insights, SSO events, RADIUS, MDM commands
OneLogin
Authentication events, role changes, provisioning activity
Keycloak
Realm events, admin events, user management activity
CyberArk
Privileged session recordings, vault access, safe management
BeyondTrust
Privileged access requests, session management, password safe events
SailPoint
Identity governance events, access certification, role management
HashiCorp Vault
Secrets access audit, token lifecycle, policy changes
Data collected across identity integrations
- Authentication success and failure events with MFA status
- User lifecycle events (create, modify, deactivate, delete)
- Group membership and role assignment changes
- Admin and privileged user action events
- OAuth 2.0 / SAML token issuance and consent events
- Conditional Access policy evaluation results
Automated response actions
- Suspend or disable user account immediately via IdP API
- Revoke all active sessions for a compromised user
- Force password reset and MFA re-enrolment
- Remove user from privileged group on verdict
- Lock CyberArk/BeyondTrust privileged vault account
- Trigger Okta Workflows for complex identity remediation
Identity integration FAQs
Why is identity telemetry critical for SOC operations?
Identity-based attacks — phishing, credential stuffing, MFA fatigue, session hijacking — are the leading initial access vectors in cloud breaches. Identity logs from Okta, Entra ID, and similar systems are often the first signal of a compromise, sometimes hours before endpoint or network indicators appear.
What is the most important event type to collect from Okta?
The Okta System Log provides all event types: authentication, user changes, admin actions, and API activity. ManySignal ingests the full Okta System Log via the API. Priority event types for detection include user.authentication.auth_via_mfa_challenge, user.session.start, and system.admin.auth.
Does ManySignal detect MFA fatigue attacks?
Yes. ManySignal monitors Okta, Entra ID, and Duo for repeated MFA denial followed by approval — the MFA fatigue pattern. Alerts fire within 60 seconds of the suspicious approval, and automated session revocation can be configured.
How does ManySignal handle Entra ID Conditional Access events?
Entra ID sign-in logs include Conditional Access policy evaluation results (applied, failed, not applied). ManySignal detects Conditional Access policy bypass attempts and alerts on authentication events where expected policies were not applied.
Can ManySignal correlate identity events with endpoint data?
Yes. ManySignal's entity graph links identity events (Okta user session) to the device used for authentication (CrowdStrike or SentinelOne device ID). A single compromised identity shows both its authentication anomalies and the endpoint activity during the session.
What privileged access management (PAM) tools does ManySignal integrate with?
ManySignal integrates with CyberArk, BeyondTrust, and HashiCorp Vault for privileged access telemetry. CyberArk session recordings and vault access events are correlated with other identity and cloud events.
Does ManySignal detect impossible travel across identity providers?
Yes. ManySignal correlates authentication events across multiple identity providers for the same user. Impossible travel is detected whether the two logins occur in Okta, Entra ID, or any other IdP — the entity graph links them.
How quickly can ManySignal suspend a compromised user account?
ManySignal can trigger Okta or Entra ID account suspension within seconds of a high-confidence verdict. For Okta, the suspend API call is typically acknowledged within 200ms. Session revocation follows immediately.
Does ManySignal monitor service accounts and non-human identities?
Yes. Service accounts, OAuth applications, and API keys are first-class entities in ManySignal's entity graph. Anomalous service account behaviour — accessing new resources, operating outside maintenance windows, appearing in new geographies — is detected with the same logic as human identity anomalies.
What is the recommended identity integration deployment order?
Start with your primary identity provider (Okta or Entra ID) — this provides the most immediate detection value. Add PAM tools (CyberArk, Vault) second. Then add RADIUS/VPN authentication sources for complete perimeter identity coverage.
Connect your identity providers to ManySignal
Start detecting credential-based attacks within an hour of connecting Okta or Entra ID.