Making Your Digital Workplace More Secure with User Risk Analytics and Shadow IT Insights

Endpoint SecuritySecure DX

As the Digital Employee Experience (DEX) market keeps evolving and we see more and more customers starting to review and implement improved digital workplace strategies, we also see an increased demand for addressing additional use cases from our customers using the ControlUp DEX Platform.

And these use cases go beyond the traditional “user experience issues” such as fixing slow applications, slow logins and slow networks: digital workplace IT teams are equally responsible for reducing security risk, improving patch compliance and reducing configuration drift when it comes to the digital workplace.

So, when we released our Secure DX module earlier this year, we provided our customers with capabilities that helped them:

  • Reduce device attack surface with automated patch & vulnerability management
  • Improve device compliance through configuration drift prevention
  • Gain better visibility into digital workplace risk for both IT and security teams

But with employees getting more choice in how, when and where they want to work, just looking at the device alone is no longer providing you with a complete picture.

Especially with SaaS application adoption continuing to grow for both SaaS applications that are known to IT, as well as “Shadow SaaS” applications, new capabilities are required to further improve visibility into risk and compliance.

Figure 1 – enhancements to Secure DX capabilities

User Risk Analytics

We are excited to introduce new functionality for Secure DX that allows you to improve your digital workplace risk assessment and reporting by providing insights into what SaaS applications your employees are using and logging into.

This new feature will capture SaaS application logins from two different sources:

  • Through API integration with third party authentication platforms, with initial support for Entra ID and Okta
  • Using our new Secure DX browser extension available for Google Chrome and Microsoft Edge browsers
Figure 2 – options to capture SaaS application logins

Based on this data, we can now determine the “Login Risk” for each SaaS application login based on the authentication type used, if the login came from a device that is managed or not and the certification strength of the SaaS app.

Figure 3 – Widget showing recent user logins using different authentication types

And by combining all the SaaS login data available, we can provide a User Security score for each employee, to quickly understand where additional mitigation could be needed.

Figure 4 – Widgets showing breakdown of authentication methods and user security score

And the integration with third party authentication platforms doesn’t limit you to collect logins for just SaaS applications, but could also be logins to other platforms, including VPN gateway logins.

Shadow IT Insights

The integration into third party authentication platforms will collect authentication events for applications that are managed by IT, but the browser extension will capture any SaaS login for specified domains. For example, I can configure the extension to capture any login that uses @controlup.com as part of the username.

This will allow IT teams to get a better understanding of employees using SaaS applications from their corporate devices that they might not have been aware of before.

Figure 5 – SaaS application report

These new insights allow IT teams to determine the path forward for those applications, e.g. officially onboard those applications so they can improve security, user experience and track usage for those applications. Or possibly to set restrictions on usage of these non-IT supported applications.

Bringing it all together

Finally, to help IT teams to get a quick overview of their digital workplace security as it applies to both device and employee security, we have a new overview dashboard in Secure DX that allows teams to quickly understand where improvements could be made.

In addition to high level trending information such as security score over time and breakdown of security issue severity, it will also provide the top 10 issues that affect digital workplace risk, including security misconfigurations and application vulnerabilities and show you the top 10 “Risky Users” that shows you which users have the lowest user security scores.

Figure 6 – Secure DX digital workplace overview dashboard

See (or try!) it yourself

To see how the new User Risk Analytics work, check out the five-minute video below or ff you want to learn more about how ControlUp can help you deliver a more secure digital workplace, we are happy to set up meeting with you to discuss your use cases, give you a live demonstration and answer any questions you might have. Not ready to talk yet, but want to try it out? Get your own fully functional trial of ControlUp’s DEX platform now.

Joel Stocker

Joel Stocker is a technologist's technologist. An industry veteran with over 25 years of experience in End-User Computing (EUC), he's held numerous technical field sales and product roles at Citrix. Never one to settle, Joel always seeks to unlock the super powers of ControlUp technology and expand its usefulness for our customers. All of this, paired with a genuine love of technology and the ways it can change business (not to mention incisive wit and witticism) helps him help our customers and partners improve their EUC infrastructure and deliver stellar end-user experiences.