Changelog

Subscribe to all Changelog posts via RSS to stay updated on everything we ship at Nudge Security.

Nudge Security continually monitors the security posture of your Google Workspace and Microsoft 365 environments so you can detect, prioritize, and fix risks and misconfigurations. 

‍

Now, we’ve added new rules to surface Microsoft Sharepoint security posture risks and misconfigurations. Nudge Security enables you to resolve risks efficiently with nudge workflows and context-aware remediation guidance for each finding. 

‍

Note: Existing customers using Microsoft 365 will need to accept additional scopes to enable these new security posture checks. To do so, go to Settings > Email Analysis, select “Update Permissions,” and accept the scope allowing Nudge Security to read the tenant-level settings of SharePoint and OneDrive.

‍

Nudge Security enables you to scale your SaaS security and governance efforts by nudging users through Slack or email. We’ve made several improvements to make it easier for you to re-nudge users who haven’t responded yet. Now, you can:

‍

  • Re-nudge manually from the Nudge History page
  • Customize automated re-nudging settings, including how many times to re-nudge and how long to wait between nudges
  • Re-nudge directly from playbooks, either in bulk or to individual users

‍

Manage the authorizing user for your Microsoft 365 or Google Workspace integration

‍

Nudge Security enables email discovery using delegated permissions from the email administrator who serves as the authorizing user for your Microsoft 365 or Google Workspace integration. Now, we’ve made it easier for you to update your authorizing user when someone leaves your organization or the structure of your team changes. 

‍

You can change your authorizing user by going to Settings > Email Analysis. Before making the change, just make sure the new user has sufficient email admin privileges. 

‍

Nudge Security enables you to engage your workforce at scale by nudging users through Slack or email with just-in-time interventions that can be sent through playbooks, automated rules, or manually. Now, Nudge Security will automatically send a second nudge if a user doesn’t respond within three days. Users have 30 days to respond before the nudge expires.

‍

You can keep track of nudges, follow-up nudges, and responses within Nudge History, where you can filter apps by nudge type, response status, date range, app, or user. You can see each app’s Nudge History within its App Overview, or check out your global Nudge History under Notifications > Nudge History within the lefthand navigation.

‍

Nudge Security has extended our patented SaaS discovery method to include SaaS spend data from invoices in your users’ mailboxes, uncovering SaaS expenses that may not be captured by financial software.

‍

Now, Nudge Security discovers and analyzes invoices from the last two years to extract spend data such as billing frequency, amount, renewal date, billing owner, cost center, and most recent transaction, powering the platform’s cost optimization insights. For additional context, we’ve added an inventory of invoice details we’ve uncovered for each app, including information like invoice ID, date, payment status, payee, and description of services.

‍

These new discovery capabilities enable SaaS spend forecasting that accounts for previously-unknown spend and changes in SaaS adoption. You can track your own estimated annual budget for each app alongside Nudge Security’s record of historical spend for the last 12 months and projected spend based on actual usage. Nudge Security also calculates each app’s average cost per user, helping you prioritize SaaS deployment and investment decisions.

‍

‍

Nudge Security has released new API endpoints to help you search and retrieve security posture findings for Google Workspace and Microsoft 365. Now, you can use Nudge Security’s API to report on findings or ingest security posture data into your SIEM or SOAR tool to correlate events and accelerate incident response. 

‍

See our API documentation for more information on the new endpoints

‍

Nudge Security delivers a risk score for each OAuth grant in your environment to help you prioritize and manage OAuth risks at scale. Previously, risk scores were based on the permissiveness of each grant’s scopes. 

‍

Now, Nudge Security has updated these risk scores to account for our recently-added OAuth risk insights, which highlight signals such as popularity, trust signals from vendors, and indicators of potential phishing. For example, a grant with an unusually high level of access may have a lower risk score if the grant was created by Google or Microsoft or has passed a security review. In contrast, a grant may have a high risk score despite more limited access if Nudge Security detects malicious domains or potentially deceptive practices within an app’s registration information.

‍

Today, we’ve expanded our SaaS security and governance capabilities with SaaS security posture management (SSPM) for Google Workspace and Microsoft 356, enabling you to remediate risks and misconfigurations in your identity infrastructure. 

‍

Now, Nudge Security regularly checks your Google Workspace or Microsoft 365 environment against technical benchmarks to detect:

‍

  • Misconfigurations such as missing SSO or MFA and suspicious email audit rules
  • Identity risks like delegated email access and inactive privileged accounts
  • SaaS-to-SaaS integration risks, including unused OAuth grants with privileged access and unapproved grants with risky scopes

‍

You can see an overview of findings from those checks in the new Posture dashboard, which highlights top findings, riskiest users, and remediation activities. See a full list of issues under Findings and resolve risks quickly with remediation workflows, including nudges to engage the right stakeholders and track resolution outcomes. Learn more in today’s blog.

‍

Nudge Security provides an AI Usage dashboard summarizing AI apps and usage trends across your organization, which includes AI tools users sign up for using SSO, username and password, and OAuth. 

‍

Now, we’ve added a list of integrations associated with AI tools to the AI Usage dashboard, making it easier to surface OAuth risk insights for these integrations and discover opportunities to revoke OAuth grants for AI tools automatically.

‍

For each app in Nudge Security, customers are able to set an Approval Status of In Review, Approved, Acceptable, or Not Permitted. These statuses can be used to determine which apps appear in an employee-facing App Directory. 

‍

Now, Nudge Security has added Approval Status as an available trigger for notification rules. For example, customers can create a rule to alert them if an employee creates an account with an Unapproved app, or automatically nudge the user to delete their account. New notification rules can be created by going to Notifications > Rules from the left menu bar and clicking “Create new rule.”

‍