Auth0
You can integrate Auth0 with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Auth0 product overview
Auth0 is an authentication and authorization platform, specializing in providing secure access to applications and systems through a cloud-native solution. Auth0 focuses on enhancing user experiences by offering developers flexible, easy-to-implement authentication and authorization capabilities, including single sign-on (SSO), multi-factor authentication, and social login. Its dynamic approach in managing and securing user identities across various applications makes it a powerful tool for organizations aiming to bolster their cybersecurity infrastructure while maintaining user accessibility and convenience.
What we ingest
Sophos XDR collects Auth0 data over HTTPS by polling the Auth0 Management API’s log events endpoint, using an Auth0 Management API access token for authentication. The following data is collected:
- Tenant log events: Auth0 tenant log events covering authentication and authorization activity, each carrying the event type code and description, the result, the client application, the user, and the source IP and user agent.
Event and data types
All Auth0 tenant log events are normalized uniformly to authentication telemetry. They include:
- Authentication: Login successes and failures, logouts, and token exchanges such as client-credentials and refresh-token grants.
- Multi-factor authentication: MFA enrollment, challenges, and verification successes and failures.
- Account and credential management: Account lockouts and unblocks, password changes and resets, and user management changes.
- Pre-authentication risk: Pre-login risk assessments.
Data provided by this integration
Data provided by Auth0 gets normalized to the following schemas:
auth
For more information about using schemas in Data Lake Search, see Schemas and logical types.