What is our primary use case?
Before CrowdStrike Falcon Next-Gen Identity Security, I faced challenges in understanding and managing security risks across my SaaS applications due to SaaS products being spread apart and accounts being located all over the place. CrowdStrike Falcon Next-Gen Identity Security allowed us to consolidate all that and gain more visibility into account compromises and different kinds of attack vectors that people use for accounts.
Since implementing CrowdStrike Falcon Next-Gen Identity Security, we have been able to identify and remediate various SaaS misconfigurations and security risks by integrating it with our Microsoft Azure applications, which allows us to gain visibility into misconfigurations and any policies that need to be reset that CrowdStrike identifies.
Having SaaS posture and threat detection within the broader Falcon platform is crucial to my organization's security strategy because it is all about providing visibility to leadership who wants to know what is happening in the organization, where they can focus on, and where the biggest risks are for users.
What is most valuable?
CrowdStrike Falcon Next-Gen Identity Security has changed my visibility into SaaS misconfigurations, identities, and risk activity by identifying those issues and providing recommendations, best practices, and any flaws that they find within our organization.
What differentiates CrowdStrike Falcon Next-Gen Identity Security from other SaaS security or SSPM solutions I have evaluated is the visibility aspect, as CrowdStrike has various data sources they allow to incorporate.
With CrowdStrike Falcon Next-Gen Identity Security, I have discovered previously unknown SaaS applications or services, and that has been a big area we have focused on—discovering and gaining visibility into new SaaS applications and where they are being used.
What needs improvement?
I have expanded usage, and it was easy to incorporate new data sources. If we find any new data sources we need, then CrowdStrike is available to incorporate those.
For how long have I used the solution?
I have been using CrowdStrike Falcon Next-Gen Identity Security for about three years.
What do I think about the stability of the solution?
I have not experienced any downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
CrowdStrike Falcon Next-Gen Identity Security scales with the growing needs of my organization, but we are limited by the log ingestion at the current moment. That is one limit we see, as the 50 gig limit for our Next-Gen SIEM is not reaching what we need in the future.
How are customer service and support?
On a scale from one to ten, I would rate customer service and technical support a ten.
Which solution did I use previously and why did I switch?
Prior to adopting CrowdStrike Falcon Next-Gen Identity Security, I was using another solution to address similar needs.
That solution was a Trellix SIEM, and the factors that led me to consider a change included it being hard to use, not allowing for much correlation, and the amount of data sources they had not being as good as CrowdStrike's. CrowdStrike won us over for better visibility.
How was the initial setup?
My experience with deploying CrowdStrike Falcon Next-Gen Identity Security is that it is very easy to deploy and simple to integrate.
What worked well during the deployment is that no issues were faced.
What was our ROI?
I have seen return on investment with CrowdStrike Falcon Next-Gen Identity Security because it allows us to incorporate different various logs that we have within the organization and use Next-Gen SIEM to correlate those different data sources.
What other advice do I have?
Correlating SaaS activity with identity and endpoint context enhances my ability to investigate threats because correlation is very important as endpoints only receive one type of data, and this incorporates the SaaS data as well with identity protection, allowing me a better picture of what is happening, how the user is interacting with the SaaS application, and which identities are being focused on the threat.
CrowdStrike Falcon Next-Gen Identity Security has changed the amount of manual effort required to assess and manage SaaS security. It has gained better visibility and better ways to correlate the data and allows for faster remediation and faster response.
This discovery has impacted my security operations by allowing us to use correlation more and identify risk within the organization to bring to leadership.
AI applications and agents are changing the way I think about SaaS security because an issue we are seeing is cybersecurity being brought in at the very end of those kinds of conversations for new SaaS applications. This allows us to gain visibility in the early stages of new applications and protect our organization before those applications are brought to the organization.
My advice for other organizations considering CrowdStrike Falcon Next-Gen Identity Security is that identity security is a big aspect, and CrowdStrike allows for better correlation as they have insights into endpoint security as well, which facilitates better correlation into any incidents that come up. I would rate this solution a ten overall.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure