Changelog

Subscribe to all Changelog posts via RSS to stay updated on everything we ship at Nudge Security.

We recently revamped our SaaS events record to provide additional context, including associated resources, and to make it even easier to search and filter events by event type, time range, or user. This applies to the Events tab for SaaS apps and SaaS accounts.

‍

Each SaaS app has its own events record where you can search and filter activities for all users of that app. For example, you could review a timeline of user account creation events within an app.  Additionally, each SaaS account has its own event record, so you can review activities associated with an individual user account, such as password reset or MFA disablement events.

‍

Now that SaaS resources are associated with their relevant events and searchable, we’ve also retired the all-purpose Resources tab from the primary navigation.

‍

Nudge Security streamlines the process of onboarding applications to SSO through playbooks for Azure AD and Okta onboarding. Within both playbooks, we’ve added filters to help you prioritize applications that support SSO. 

‍

We’ve also made it easier to target applications for Okta onboarding based on the specific authentication types they support. You can filter by supported authentication types, including SAML, SCIM, SWA, and OIDC.

‍

We’ve enhanced our ability to collect information about app usage from employees by updating an existing nudge. We’ve added more relevant response options to the “Request clarification of use” nudge, and we’re storing employees’ answers in a more actionable format. 

‍

Now, you can send a nudge to the technical owner of an app asking them to specify whether an application is fully adopted, under evaluation, just an experiment, or for personal use only. Optionally, the employee can also add a text response and select whether the application will handle corporate, customer, employee, or financial data. These responses populate fields labeled “Lifecycle stage” and “Data type,” which can be used to filter the Apps view. 

‍

Nudge Security has released new app health statuses showing the operational state of the SaaS applications in use across your organization. Now, security and IT teams can see an at-a-glance view of the operational health of your organization’s SaaS applications and swiftly identify if a SaaS service is experiencing disruptions.

‍

Learn more in today’s blog.

‍

We’ve released new functionality to help you understand and address your company’s exposure to a recently disclosed Google OAuth vulnerability, including a new default notification rule and a new filter view to help you discover existing accounts. Now, all Nudge Security customers will receive alerts automatically when employees create new shadow Google accounts. Additionally, you can view a list of all the shadow Google accounts at your organization by visiting the Google Workspace app overview page, clicking on the Resources tab, and filtering by “Account alias.”

‍

Read our blog post to learn more about the vulnerability and how our new functionality can help.

‍

Nudge Security has introduced a new app directory to streamline the process of onboarding employees to SaaS applications. Now, security and IT teams can share a directory of approved SaaS apps with employees, making it easier for users to request access to apps that are in compliance with corporate guidelines and have already cleared security review and procurement processes. 

‍

To get started, enable the app directory under Organization Settings and invite users to sign up for Nudge Security accounts with Personal View set as the user role. Note: Administrative privileges are required to change these settings or approve access requests for new users.

‍

Read our blog tutorial to learn more, or check out our interactive demo below.

‍

Nudge Security offers a variety of nudges to help you communicate with your employees. For example, you can send nudges prompting users to enable MFA, accept your generative AI usage policy, or delete an account, among other options.

‍

Now, you can customize the language in these nudges to suit your organization. You can edit the subject line and body copy for each nudge template and use variables to insert context-specific copy. Nudge customization options can be found within Settings. 

‍

Nudge Security has introduced the ability to multi-select filter options. Now, you can choose more than one option in each filter category, making it easier to find what you need with filters. For example, you can use filters to see all apps with approval statuses of Approved, Acceptable, and In Review, rather than looking at one of these approval statuses at a time. 

‍

‍

Nudge Security designates a technical contact for every app in your environment. This should be someone with administrative privileges within the app who can serve as the point-person for all questions and requests related to the technical aspects of managing that app, including access controls. While the first user of an app can often fill that role, employee turnover and team changes can sometimes make it challenging to figure out who to turn to for help with tasks like onboarding or offboarding users.

‍

Now, we’ve introduced a new nudge to help you find and validate the right technical contact for an app. With this nudge, you can send an email or Slack message to the person currently designated as an app's technical contact asking them to confirm whether or not they’re the right person for that role. If they aren’t the right contact, they’ll have the opportunity to identify the right contact, helping you keep this information up to date.

‍

Nudge Security has enhanced our SaaS discovery engine with support for Google Single Sign-On (SSO). This update enables our system to recognize and analyze the use of Google SSO in authenticating user accounts. Now we can provide deeper insights into authentication patterns, improving security and compliance across your SaaS applications by offering detailed visibility into how Google SSO is employed in your environment. 

‍