This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Identity Powered Zero Trust

Download resources

About this session

Valentin Bourneuf, a customer success manager at Okta with a background in network security, GRC consulting and cloud security, argues identity belongs at the center of Zero Trust programs, framing the talk as one of few at the conference to focus specifically on identity rather than Zero Trust in general. He opens with fundamentals: authentication versus authorization, the three identity domains (employee, customer, machine), and how role- and group-based access control emerged to tame growing complexity. He walks through pressures reshaping identity: cloud adoption, BYOD and hybrid work, executive pressure to do more with less, compliance frameworks such as Quebec's Law 25, and statistics showing most breaches involve compromised or stolen credentials. He critiques "Zero Trust" as a semantically unattainable name, then reframes it around NIST's principles (least privilege, no implicit trust, continuous monitoring) and CISA's maturity model. He details how identity providers enrich access decisions with user, device and contextual signals, and closes on three implementation challenges: business agility, cross-tool integration and signal sharing, and balancing security friction against user experience.

Key takeaways

  • Build a complete access map (who has access to what, and why) before attempting to automate any Zero Trust policy; you cannot automate what you have not first inventoried.
  • Consolidate identity sources (HR system, Active Directory, LDAP) into one profile so role and project changes can automatically provision or deprovision application access.
  • Move toward a default-deny access model with self-service requests and pre-approval workflows integrated into everyday tools like Teams or Slack to keep the business agile.
  • Adopt continuous signal sharing, for example through the OpenID Shared Signals Framework, so a posture change (expired certificate, unpatched OS) triggers step-up authentication instead of waiting for the next login.
  • Vary re-authentication frequency and session duration based on device and user posture rather than a fixed timer, to balance security against user experience.

Speakers

Valentin Bourneuf
Valentin Bourneuf
Sr. Customer Success Manager · Okta
Diplômé d’un master en ingénierie des réseaux et des systèmes de l’Université de Versailles Saint-Quentin-en-Yvelines en France, je dispose de plus de dix années d’expériences, en France et au Canada, dans la sécurité des systèmes d’informations. Au… Read moreRead less

Diplômé d’un master en ingénierie des réseaux et des systèmes de l’Université de Versailles Saint-Quentin-en-Yvelines en France, je dispose de plus de dix années d’expériences, en France et au Canada, dans la sécurité des systèmes d’informations. Au travers de mes expériences professionnelles j’ai évolué tant dans l’intégration d’architectures, que dans l’évaluation de posture sécurité, ou encore dans la définition des schémas directeurs. Je mets aujourd'hui toutes ces compétences au service d'Okta et de ses clients, afin d'assurer la pleine utilisation de la plateforme.
Certifié AWS Security (SCS-C01), AWS Solutions Architect (SAA-C02), ISACA Cloud Auditing (CCAK), ISACA CISM, ISACA CRISC, Microsoft Certified: Azure Security Engineer Associate (AZ-500), Okta Certified Consultant

Resources

Tags

More from GoSec 2023

Also from Valentin Bourneuf

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.