Introduction
Risk score integrations allow you to connect your organization’s identity providers (IdPs) and endpoint detection and response (EDR) solutions to SoSafe’s Human Risk OS (HROS). These integrations enable HROS Risk Scoring, providing a more comprehensive view of your organization’s security posture by combining user behavior data with signals from your existing security tools.
Supported integrations:
-
Identity Providers (IdP): Entra, Okta
-
Endpoint Detection and Response (EDR): Crowdstrike, Microsoft Defender
By integrating these systems, you can enhance risk scoring accuracy and automate security interventions based on real-time insights.
Prerequisites
Before setting up risk score integrations, ensure the following requirements are met:
-
SoSafe Platform Access: You have administrator access to your SoSafe tenant.
-
Integration Permissions: You have the necessary permissions in your IdP (Entra or Okta) and/or EDR (Crowdstrike or Microsoft Defender) environments to create and manage integrations.
-
Licensing: Your organization holds valid licenses for the systems you wish to integrate.
-
API Access: API access is enabled for the relevant platforms (consult your IT/security team if unsure).
-
Network Access: Any required firewall or network settings allow communication between SoSafe and your integrated systems.
Integration setup instructions
To set up a risk score integration, select the relevant system below and follow the instructions:
Note:
If setting up HROS, then the integration of external risk events should occur the day after SCIM setup, as user mapping runs nightly.
4. Managing Integrations
Viewing Integration Status
-
Go to Settings > Integrations in the SoSafe admin portal.
-
Each integration displays its current status (e.g., Connected, Disconnected, Error).
-
Click on an integration to view details.
Editing Integration Settings
-
Find the integration you want to edit.
-
Click Edit to update credentials, permissions, or configuration options.
-
Save changes to apply updates. Some changes may require re-authentication.
Removing an Integration
-
Find the integration you wish to remove.
-
Click Edit and then click Disconnect.
-
Confirm the removal in the dialog box.
-
The integration will be disconnected, and data sync will stop.
Monitoring Integration Health
-
Regularly check the Integrations page for connection errors.
-
If an integration shows an error, try troubleshooting steps.
Screenshot placeholders:
-
[Screenshot: Integrations overview page]
-
[Screenshot: Integration details view]
-
[Screenshot: Remove integration confirmation]
5. FAQs & Troubleshooting
Frequently Asked Questions
Q: What permissions are required for each integration?
A: Admin-level permissions are required in both SoSafe and the integrated platform (Entra, Okta, Crowdstrike, or Microsoft Defender).
Q: How often does SoSafe sync data from integrations?
A: Data is typically synced every 24 hours.
Q: Can I connect more than one IdP or EDR?
A: Yes, you can connect multiple supported integrations simultaneously.
Troubleshooting
Issue: Integration shows as “Error” or “Disconnected”
-
Check that credentials or API keys are still valid.
-
Ensure required permissions have not changed or expired.
-
Verify network connectivity between SoSafe and the integrated platform.
-
Try removing and re-adding the integration.
Issue: Data is not syncing
-
Confirm the integration status is “Connected.”
-
Check the last sync time in the integration details.
-
Review any error messages or logs for more information.
Issue: Unable to authorize SoSafe in the third-party platform
-
Ensure you are using an admin account.
-
Check if your organization’s security policies restrict third-party integrations.
-
Contact your IT/security team if issues persist.
If problems continue, contact SoSafe Support with error details and screenshots.
6. Glossary & References
Glossary
-
IdP (Identity Provider): A service that manages user identities and authentication (e.g., Entra, Okta).
-
EDR (Endpoint Detection and Response): Security solutions that monitor and respond to threats on endpoint devices (e.g., Crowdstrike, Microsoft Defender).
-
HROS (Human Risk OS): SoSafe’s platform for managing and reducing human cyber risk.
-
API (Application Programming Interface): A set of protocols for integrating software applications.