Identity Sources
The Corsha mIDP integrates with external identity providers to import and synchronize machine identities. These integrations enable organizations to maintain a unified view of machine identities across cloud and on-premises environments while leveraging existing identity infrastructure.
Available Integrations
Azure Entra ID
Integrate with Microsoft Azure Entra ID (formerly Azure Active Directory) to import application registrations, service principals, and managed identities as machine identities in Corsha.
Key capabilities:
- Automated import of Azure service principals and managed identities
- Continuous synchronization with Azure Entra ID
- Support for application registrations and enterprise applications
- Attribute mapping for Azure resource metadata
- Multi-tenant support
Amazon Cognito
Integrate with Amazon Cognito to import user pool clients and identity pool identities as machine identities. Enables machine-to-machine authentication using Cognito credentials.
Key capabilities:
- Automated import of Cognito user pool clients
- Support for identity pool federated identities
- Continuous synchronization with Cognito
- AWS region-aware configuration
- OAuth 2.0 and OIDC credential support
How Identity Source Integrations Work
Identity source integrations follow a common pattern:
- Identity Discovery: The identity provider manages application identities, service principals, or machine credentials
- API Synchronization: Corsha mIDP connects via API to retrieve identity information
- Machine Identity Creation: Each discovered identity becomes a machine identity in Corsha
- Attribute Mapping: Identity attributes are mapped to machine identity properties
- Credential Synchronization: Authentication credentials are synchronized for MFA validation
- Ongoing Updates: Regular synchronization keeps identities current
Benefits
Unified Machine Identity Management:
- Import existing cloud application identities into Corsha
- Maintain synchronized identity information across platforms
- Reduce manual machine identity creation
Cloud-Native Integration:
- Leverage native cloud identity services (Azure Entra ID, AWS Cognito)
- Support modern authentication protocols (OAuth 2.0, OIDC)
- Integrate with cloud-native applications and services
Simplified Deployment:
- Rapidly populate Corsha with existing cloud identities
- Reuse existing service principal and application credentials
- Accelerate time to enforcement
Continuous Accuracy:
- Identity information automatically updates from cloud providers
- Credential changes sync to maintain authentication
- Deleted identities can be automatically removed
Configuration
Identity source integrations are configured through the Console under Integrations > Identity Sources. Each integration requires:
- API credentials for the identity provider
- API endpoint or tenant information
Contact your Corsha Technical Point of Contact (TPOC) for assistance configuring identity source integrations and obtaining necessary credentials.
Best Practices
-
Use Service Principals with Limited Permissions: Grant only the minimum required permissions for identity synchronization
-
Synchronize Regularly: Configure frequent synchronization to ensure Corsha reflects current identity state
-
Map Cloud Attributes to Groups: Use cloud resource tags and attributes to automatically organize identities into groups
-
Combine with Other Identity Sources: Import from multiple cloud providers while maintaining unified policies
-
Validate Imported Identities: Review imported machine identities to ensure accuracy before creating policies
-
Monitor Synchronization Status: Regularly verify integrations are syncing successfully