Trust Profiles
|
|
Note - The integration that enables using Trust Profiles in Identity and Trust is currently available only through the Early Availability program. To activate this feature, contact your Identity and Trust Customer Success Manager or local Account Manager. When Trust Profiles are enabled, the Trust Profiles page replaces the Compliance page, and the earlier compliance policy no longer applies. |
Trust Profiles let you define trust-based access conditions for user sessions. Identity and Trust evaluates session attributes such as device posture, user authentication, location, and integration source. Based on these attributes, Identity and Trust assigns one or more Trust Profiles to a session and sends the matched profiles to Security Gateways for policy enforcement.
Trust Profiles replace the earlier Compliance page. The Compliance page evaluated only device compliance from Microsoft Intune. Trust Profiles support a broader Zero Trust model that evaluates multiple trust indicators.
How Trust Profiles Work
-
Create one or more Trust Profiles in Identity and Trust.
-
Configure the conditions that determine when a session matches each profile.
-
Identity and Trust evaluates all active Trust Profiles for each session.
-
A session matches zero, one, or more Trust Profiles.
-
Identity and Trust sends the matched Trust Profiles to Security Gateways for enforcement.
A Trust Profile can include more than one category. When a profile has more than one enabled category, a session must match all enabled categories to match the profile.
For example, if a profile requires MFA and a compliant device, a session must satisfy both requirements to match the profile.
Prerequisites
-
An active Identity and Trust tenant with at least one configured Identity Provider.
-
At least one relevant Identity Integration for the attribute you want to enforce.
-
For device posture and compliance evaulation: Microsoft Intune, Endpoint Security, CrowdStrike Falcon, and/or Microsoft Defender.
-
-
Score thresholds configured in Advanced Settings if you use score-based validations (CrowdStrike Falconn ZTA/SCA thresholds; Microsoft Defender exposure level).
-
A Security Gateway configured as a consumer of Identity and Trust (Identity Awareness receiving sessions from Identity and Trust), so matched Trust Profiles reach the Gateway for enforcement.
Predefined Trust Profiles
Identity and Trust includes predefined Trust Profiles for common Zero Trust scenarios. You can activate or deactivate a predefined profile, but you cannot edit it. Each predefined profile uses the trust categories described in Trust Profile Categories.
High Trust
Use the High Trust profile to allow access only to highly trusted sessions. This profile uses the most restrictive available settings for each supported category. When Check Point adds a new category, Identity and Trust automatically includes it in the High Trust profile.
Typical use cases:
-
Access to sensitive business applications.
-
Access to source-code repositories.
-
Access to administrative or restricted systems.
Non-compliant Devices
Use the Non-compliant Devices profile to identify sessions from devices that do not meet the required device posture. This profile replaces the earlier Compliance-page behavior and can evaluate device posture from more than one source, not only Microsoft Intune.
Typical use cases:
-
Block access to sensitive resources from non-compliant devices.
-
Restrict access until the device completes remediation.
-
Enforce corporate device security policies.
Trust Profile Categories
Trust Profile categories are the building blocks of every Trust Profile. Both predefined and custom profiles use the same categories. When a profile has more than one enabled category, a session must match all enabled categories (AND condition).
Device Posture
Use Device Posture to evaluate device security signals. By default, a profile does not evaluate device posture.
There are two options to evaluate device posture. You can configure a profile to:
-
Match devices that satisfy one or more selected validations.
-
Match devices that fail one or more selected validations.
To evaluate device posture:
-
Select Use specific validations.
-
Specify whether the device must match, or must fail to match, at least one selected validation.
-
Select the validations from the list. Available validations can include:
-
Microsoft Intune compliance
-
Endpoint Securitycompliance
-
CrowdStrike Falcon scores
-
Microsoft Defender exposure level
-
For example:
To create a Trust Profile that matches only devices that are compliant with Microsoft Intune, or that meet a specified CrowdStrike Falcon score threshold, select Device matches at least one validation and select the Microsoft Intune and CrowdStrike Falcon validations from the list.
To create a Trust Profile that will be matched only if a device is not compliant with Microsoft Intune, select Device doesn't match at least one validation and select the Microsoft Intune validation from the list.
|
|
Note - CrowdStrike Falcon and Microsoft Defender validations use the thresholds configured in Advanced Settings. When you modify a threshold, Identity and Trust automatically applies the new value to all profiles that use the corresponding validation. |
User
Use the User category to verify user authentication requirements. This category evaluates whether the session used Multi-Factor Authentication (MFA).
When this category is enabled, a session must satisfy the MFA requirement to match the profile. When this category is disabled, Identity and Trust skips this verification.
Geolocation
Use the Geolocation category to allow or block access based on the country of the session. You can:
-
Allow selected countries.
-
Block selected countries.
-
Apply no location restriction (default).
For example: Allow access only from approved countries, or block access from countries that you consider high risk.
Integration
Use the Integration category to evaluate the source of the identity information. You can configure a profile to match only sessions that arrive through selected integrations. The list can include Identity and Trust integrations and supported third-party integrations.
For example: Match only sessions received through a trusted integration, such as SASE, and exclude sessions from a less trusted source.
Create and Manage Custom Profiles
A custom Trust Profile lets you define your own trust requirements. You can create, edit, duplicate, activate, deactivate, and delete custom profiles.
To create a custom profile:
-
In Identity and Trust, from the left toolbar, click Trust.
-
Click Create profile.
-
Enter a Profile name and optional description.
-
Define requirements in one or more of the Trust Profile Categories
-
Click Create.
A Trust Profile card appears in the Custom profiles area. The card contains a summary of all of the validations entered for the profile. To see the full list of requirements, hover over the number next to the validation name. Sessions will be updated within a few minutes with the Trust Profile data.
To manage a custom profile:
Hover over the relevant card and click the three dots to edit, duplicate, deactivate, activate, or delete the custom profile.
Advanced Settings
Advanced settings define global trust thresholds that apply to all trust profiles. Changes to CrowdStrike Falcon and Microsoft Defender thresholds affect any profile that uses the corresponding device posture validations.
CrowdStrike Falcon Scores
CrowdStrike Falcon provides device trust scores that you can use as device posture validations. Configure the minimum score threshold that a device must meet for these validations:
-
Zero Trust Assessment (ZTA)
-
Software Composition Analysis (SCA)
Each CrowdStrike Falcon score type has an independent threshold.
Microsoft Defender Exposure Level
Microsoft Defender assigns an exposure level to a device. Configure the minimum exposure level that Identity and Trust accepts:
-
Low and above.
-
Medium and above.
-
High only.
When you save advanced settings, Identity and Trust recalculates profile matches. Enforcement updates can take a few minutes to apply.
To modify advanced settings thresholds:
-
Click Advanced settings.
-
For CrowdStrike Falcon, drag the slider to set the minimum threshold for ZTA and SCA.
The selected threshold determines when the validation is considered a match.
-
For Microsoft Defender, select the minimum exposure level.
-
To use the default values, click Reset to default.
-
Click Apply to all profiles.
Wait several minutes while Identity and Trust recalculates session matches and updates Trust Profile evaluations.
Monitoring Trust Profiles
Use the Sessions tab on the Active Sessions page to view the Trust Profiles that match a session. The Sessions tab is available when you select a user or a device.
The Sessions tab shows the session information that Identity and Trust sends to the on-premises Security Gateway, including:
-
Source IP address and user
-
Session creation and expiration times
-
Related integrations
-
Matched Trust Profiles
A session can match more than one Trust Profile. Because a user can connect from more than one device or IP address, one user can have more than one session entry. Identity and Trust shows one session entry for each IP address.
By default, the Active Sessions view shows the most recently authenticated user or device, which is the identity that the Security Gateway enforces for that IP address. Use the available filter to show all active users or all active devices.
Policy Enforcement
Identity and Trust evaluates Trust Profiles and sends the matched profile information to Security Gateways. The Security Gateway uses this information together with existing Identity Awareness information, such as users, groups, devices, access roles, and IP addresses, to enforce access in the Rule Base.
To enforce Trust Profiles in the Rule Base you need to use an Identity Tag and in the Access Role
Access Role objects let you configure network access according to: Networks, Users and user groups, Computers and computer groups, Remote Access Clients. After you activate the Identity Awareness Software Blade, you can create Access Role objects and use them in the Source and Destination columns of Access Control Policy rules.. For more information, see the Identity and Trust Integration section in the R82.10 Identity Awareness Administration Guide.