Subscribe to all Changelog posts via RSS to stay updated on everything we ship at Nudge Security.
We’ve released new filters to help you view and prioritize OAuth grants based on OAuth risk insights from Nudge Security. You can sort and filter your organization’s OAuth grants based on insight into an app’s popularity, configuration choices, vendor trust signals, use of restricted or sensitive scopes, and indicators of deceptive practices.Â
‍
We’ve added new filtering options for accounts and OAuth grants within Nudge Security to help you manage your organization's SaaS estate.
‍
Now, you can filter accounts by MFA status to surface and prioritize enrollment gaps. You can also filter accounts and OAuth grants based on categories such as organizational unit, department, division, location, and cost center, which are fields set within Google Workspace or Microsoft 365.
‍
Nudge Security has released new SaaS spend data and cost optimization insights to help security and IT teams drive smarter, more efficient SaaS investment decisions and surface opportunities to optimize SaaS spend.
‍
To help organizations take advantage of new spend data, Nudge Security has released a Spend dashboard highlighting SaaS expenses that may be unnecessary or redundant. With this new dashboard, customers can:
‍
‍
Nudge Security has added new SaaS spend discovery, empowering customers to make better SaaS investment decisions by triangulating insights into SaaS spend, risk, and usage.
‍
Now, Nudge Security automatically categorizes apps as paid based on data from email invoices and other billing communications from the previous three years, enabling organizations to track SaaS spend alongside app risk and usage insights. Nudge Security also automatically identifies a billing owner and cost center for each paid app. You customize the Google or Microsoft field Nudge Security uses to allocate spend to cost centers by going to Settings > Organization Settings.
‍
Customers can add additional spend data manually, such as estimated annual spend, billing frequency, and renewal date. This information can be found in a new Spend card within each App Overview, or you can sort, filter, and edit these new fields in bulk directly from the App view.
‍
Note: By default, Nudge Security will only extract billing information from emails associated with users that have accounts for an app, which means we will not analyze mailboxes without associated accounts such as accounts payable (ex: [email protected]) or group accounts. If there are additional mailboxes used to receive billing information that you would like to analyze, you can add them under Settings > Spend Settings.
‍
We’ve made it easier to consolidate SaaS usage by adding a new chart to the App Overview page showing similar apps in use at your organization. Now, you can visualize the adoption of apps with similar purposes and quickly assess how much their usage overlaps, helping you identify areas where you may be paying double.
‍
Nudge Security has introduced a chart within the App Overview pane to help you visualize app usage across different areas of your organization.
‍
Now, you can see how app usage breaks down by organizational unit, cost center, department, location, or organization, based on employee data from Google Workspace or Microsoft 365.
‍
We’ve enhanced Nudge Security’s ability to detect and assess potential security risks associated with OAuth grants with new OAuth risk insights to help accelerate OAuth investigations into suspicious, misleading, or malicious grants.
‍
Now, customers can quickly and easily identify the use of restricted or sensitive scopes, detect suspicious domains and email activities, assess vendor trust signals, and understand an app’s popularity both within their own organization and across other environments.
‍
Nudge Security has added the ability to discover and inventory multiple instances of the same app, enabling customers to identify and rationalize duplicate instances and shadow tenants.Â
‍
Previously, Nudge Security categorized some instance types as resources within an app. Now, we’ll display instances defined by a unique subdomain (ex, company.slack.com) in an Instances tab within the App Overview page. Within that same pane, we’ll also associate individual accounts with the instances they have access to.
‍
‍
From food delivery to media apps, not every tool your employees use at work requires the same level of oversight. Now, Nudge Security admins can choose to ignore any app and its associated accounts from view as they work in Nudge Security.
‍
Nudge Security will exclude ignored apps from your Progress dashboard results, your total counts of apps and accounts on the Overview dashboard, and total counts on your Apps and Accounts pages. These changes will make it easier to focus on your most important apps.Â
‍
Ignored apps will still trigger notification rules, including breach alerts, and you’ll still be able to view the app’s health status and breach notifications on the Overview dashboard. They will also remain included in your Attack Surface overview, App Directory, and all playbooks.Â
‍
Nudge Security has updated our filters to make them more intuitive and user-friendly. As part of that effort, we’ve added a new filter that makes it possible to view your organization’s apps by the number of accounts. Now, you can use the new filter to see all apps with more accounts than a number you choose, or fewer.
‍
For example, let’s say you’ve offboarded all users associated with an app and have zero remaining accounts. You can use the new filter to view only apps with greater than zero accounts. Alternatively, you can prioritize low-adoption apps by filtering to see only apps with fewer than 5 associated accounts.
‍