Video: Discover how Cloudflare and Ping Identity enhance SASE architectures by integrating identity management | Duration: 3724s | Summary: Discover how Cloudflare and Ping Identity enhance SASE architectures by integrating identity management | Chapters: Introducing the Speakers (19.135s), Zero Trust Integration (166.13s), CloudFlare's Connectivity Cloud (361.72s), Ping Identity Overview (603.465s), Partnership and Challenges (869.32s), Zero Trust Journey (1084.895s), Risks and Complexity (1344.925s), Unified Zero Trust Architecture (1634.3351s), Zero Trust Implementation (1970.135s), Demo and Conclusion (2319.3398s)
Transcript for "Discover how Cloudflare and Ping Identity enhance SASE architectures by integrating identity management": And without a further ado, I'd like to introduce our speakers. We've got Mike, principal global alliance manager, partnerships with Cloudflare, and Jason, senior solutions architect with Ping Identity. We also have VB on standby to help answer any questions you have throughout the presentation as well. Alright. You may take it away. Excellent. Thanks, Hailey. Appreciate it. And and good morning, Jason. Great to always be be with you. And and, Bibi, it's always nice to be with you on a webinar versus a, client or partner call, so it's great to have you guys here together. I think it's gonna be an informative session simplifying your SaaS security, how we can sort of help, modernize or help you transform, some of the problems you might be having in your existing zero trust environments. And, Jason, do you wanna, go ahead and introduce yourself? It's Jason Veinot for those of you who do not speak French. And, I think he's coming from, Nova Scotia. But That's correct. Thanks, Mike. Yeah. So my name is Jason Veinot. I'm coming from, Halifax, Nova Scotia, Canada. And, yeah, I'm a a senior solutions architect with, with Ping Identity, coming up on about three years this summer, but a long career in, in IT and security, prior to that. So, yeah, looking to our webinar today. We have a lot of good great information in our slides and a and a really, really cool, tech demo later on in the in the, the webinar as well. So excited to, show it off. Excellent. And, VB, do you wanna say anything about yourself, or are you, good to go in the background? No. All good. I just answered as well that, I'll be here in the chat if anybody has any questions, and looking forward to a great webinar. All the best, Mike and Jason. Yeah. Thanks, Phoebe. And, again, I'm Mike Schrock. I'm with Cloudflare, principal, technology alliances, go to market manager. And I'm here to sort of make sure that folks around the world understand the Cloudflare ecosystem, understand our great partners like Ping Identity, understand how they fit into, our go to market motion and how much value they bring to, our platform and how our platforms together come together in unique and easy ways. But that's a little bit about us. We'll get more into, the agenda, but we wanna know about you. We wanna know who we're talking today and what your role is. So there's a quick poll, that we're putting up here. What is your role in your organization? So we'd love to hear from you, and we'll share those results, coming forward. And in the meantime, as you guys are answering that poll question, I guess, Jason, in your mind, when you think of zero trust and you guys have a very specific role. Ping Identity has been, you know, in the forefront of, conditional access, single sign on, federation since the, early two thousands or earlier. What what what's on your mind? What's on Ping's mind in terms of their role in zero trust these days? Yeah. Thanks, Mike. So so zero trust, zero trust at its core is really never trust, always verify. So and and we accomplish that through through Ping Identity when we do, you know, say an authentication flow, for example. We're able to consolidate and, aggregate a number of, risk signals both from our our products, plus, we work very closely with, with a number of different, tech partners as well. So we can, you know, consume, risk signals and, you know, different, you know, telemetry data from from other sources and basically use that to build, you know, a fine grade authorization policy that, really allows you to craft your your authentication experience and and flow exactly how how you want it to be. Step up and add additional friction when, when you feel is necessary, but also allow, you know, a seamless easy, easy experience for, for for when those times call forward as well. Yeah. That's great. I think, you're right. I think signal integration, I think dynamic enforcement, I think, the ability to to have policies across all the different domains of the zero trust stack is a is a really interesting way to mature, a zero trust model, and just take it to sort of the next level. So I'm glad we're here today to talk about some of that, and we'd love to hear from you audience on this. I I'm not seeing the poll results. I don't know. Hailey, if you wanna step in and show that. Oh, here we are. What is your role? So most of you guys, 30% of you, a good portion, are in the identity security and network architect role, and another 30% are in the operator role the same. And then we have a little bit of sprinkling into the CISO office, and CIO office and then others. So we'll get the others, answered here in the in the, in the chat, if you will. But I think that's a good, a good demographic for us to talk to. I think you guys, will enjoy this presentation. And and with that said, let's go through the agenda here, about us. So we did a little bit about who we are, who you are. We're gonna talk a little bit more about the companies and get the infomercial out of the way, upfront and make sure that we level set on who Cloudflare is today, who Ping is today, and make sure you're sure you guys understand that. Then we wanna get into the challenge that a lot of our customers are seeing and why, they're changing with us both. And then, additionally, let's talk about how we unify IDP and and manage the risk, by bringing our two platforms together in unique ways for both workers' identity management and for customers' identity management and how Cloudflare uniquely brings that together. And we'll also talk about, application solutions with ping, and we'll get into a demo that sort of goes over the worker integration and also a little bit of, customer potential, integration. And, then we'll get to your q and a. So with that said, let's have at it. So Cloudflare. Everyone knows Cloudflare as a CDN or a DDoS provider, and I think that we need to look at copper differently. I came in about nine months ago, but I, you know, worked at f five networks, at Radware, at Thales for over the last two decades. And what I uniquely found and why I came here, is that a lot of the security solutions that we're delivering by boxes at Radware and f five networks and Thales, all of that now is delivered by cloud services. And that's what's unique about Cloudflare is they're really a connectivity cloud. So we operate in 330 cities around the world. We've got over 13,000 now, network interconnect locations to onboard traffic. We see about 20% of the world's, traffic through us. 38 of the top, 100 AI companies, run on top of us. The it gives us a very nice perspective of threats, and we're protecting small companies and small content companies to the largest companies in the world. And so the notion of a CDN is is sort of our first chapter of our business, and the ability to be a good CDN allowed us to apply WAF and and DDoS services and API gateway services. But we moved into about, seven years ago into the zero trust game, and the ability to provide zero trust in a unique way, a way where every one of our services, whether it's our CASB or our zero trust network access or our DLP inside that zero trust solution, it runs from every one of these locations in the world. So when you buy a solution from Cloudflare, you get the whole network. So every service runs on every server, runs in every data center. So wherever the user comes in to connect to, the service, it's not being, brought back to a centralized data center. It's not being, tromboned the traffic on a per service or per module basis. Everything gets delivered for the user directly on the edge. And so we are a connectivity cloud in a major way, and that provides amazing benefits from a performance, security, and reliability perspective. We can get into more of that later, but I wanted to get that out there. So we started off, you know, providing a lot of free and low cost services, pay as you go services, which we are never giving up. We have over 2,000,000, customers. About 200,000 of those customers pay us. And, a a large number of tens of thousands of enterprise companies now use us from the biggest brands, in the world, like Japan Airlines, and Carrefour to, Homeland Security where we have hundreds of civilian agencies, securing their DNS through us. So we've really been sort of an up and comer in the last years and received a lot of accolades from the leading analyst firms. We have over 80, recognitions from the three top, Gartner, Forrester, and IDC, and many others across sort of our three core stacks or application and performance. So that's the CDN, the WAF, and the DDoS protection and and API gateway protection to our zero trust services, our SASE offerings, and our SSE offerings. And now we've moved into our third third chapter, which is sort of developer services. And I I think the developer services are interesting because, it's serverless based, functioning. It also augments the network. So whether you're in the application performance and security services or in the zero trust, all of our workers based, coding is almost like an iRule if you remember big IP. The ability you can script new functionality. You can deal with, incapac you know, inability to get something done by by, having the network perform, application services directly on your traffic or directly on your packets or directly on, the application that you're using to gain more utility. So I think it's a very unique, model that that we're we have here. Go ahead and, Jason, take it from here. Sure. Thanks. Thanks, Mike. Yeah. So from the ping side, so, you know, ping ping at its core and and from our start, we're we're an identity and access management company. But we've added so so much more capabilities over over the years, you know, similar to, you know, Cloudflare. We're we're growing growing and expanding and adding, you know, more and more, capabilities throughout, you know, throughout our stack. So, you know, we operate as a, you know, as a core, you know, secure IDP. We have both, software based solutions that you can host, host yourselves, plus we also, have multi tenant and single tenant, cloud offerings as well. And then part of that as well is we, you know, we have, a number of of products, that we can, that we can, you know, help facilitate your, you know, your security stack as well. So we have, you know, multiple m MFA products, both, you know, CIAM, customer and workforce, geared, products for that. We have, PingOne Protect, which is our identity, protection signals. So we do, you know, risk and protect, signals. So we can do everything from, you know, bot detection, impossible travel, you know, a number of different, predictors that we can, that we can use there. We have identity verification, so we can do, you know, gov ID and and selfie matching, plus, you know, a a whole, you know, slew of other products. And and, really, you know, it at at its core, we have, you know, a couple orchestration platforms. We have DaVinci and Journeys. And, both of those allow us to, really orchestrate and provide, a a seamless customer experience or or workforce experience, to be exactly how you want it to be. So, again, we can step up and add friction when when needed and step back and, you know, allow a passwordless flow if, you know, if if you'd like that as well. So so part of all that, we can we allow you to, to download templates. Our our products are very, easy to to consume and to share those, those, experiences, you know, across multiple, environments. So if you have, you know, a desk a dev and test environment, you wanna promote those changes to production, we make it very easy to to do that. Plus, we can do AB, testing as well. So when you craft your different, your different orchestration flows, you can actually, you know, have multiple flows running in parallel, and then you can actually, you know, review those results later and and see how you're you're coming, with your with your AB testing. We support, you know, we we're we're standards based. We support, you know, all all the all the common standards. We, we integrate with over 400 different, in our DaVinci platform, we have, you know, over 400 different connectors, and we, you know, support, you know, hundreds and thousands of different, tech partners. So we we, you know, we, we we we work with, with the technology you currently have. And, we're also, you know, pioneering new new, technologies as well. Again, fraud protection, identity verification are big areas, but, this new emerging, emerging technology decentralized identity is very exciting, and, we're we're at the forefront, of that as well. And, again, we support everywhere that you need to be. So workforce, customer, partners, and, you know, business to business. And, Ping Identity is enterprise proven. So, you know, we we secure over 8,000,000,000 accounts, across across the world. We're in 69% of the Fortune 100 companies. So we're, you know, we're in the big businesses. We're in the big, big industries, but we also have, you know our our products also support, you know, the small and medium businesses as well. So we have we have an answer and and a solution for, you know, wherever your, whatever your organization may need. And, again, we're trusted in in, again, every of the major industries. So we're nine out of nine of the top US banks, 10 out of 10 of the top manufacturing companies, you know, 10 out of 10 of the top information companies, seven out of 10 of the top health care companies. So, again, we're in we're in the big industries. You know, we support them. You know, they're they're they're happy with our products. And, yeah, we love, we love working with them, and and then, of course, you know, we can support, you know, companies of any size. And, again, similar to, to, Cloudflare, we do have, a % global coverage as well. So we do have, data data residency depending on, where your where your regions are. So this is just a a quick little slide to show where where some of our, you know, data centers and regions are. Thanks, Jason. Okay. Well, we're gonna get a little more into the the meat of the presentations, and this is sort of the the last, infomercial. And we'll start talking about problems and solutions and and looking at demos and and and and getting more into it. But we wanna talk about why we partnered together. We partnered together for many years now in terms of, you know, our, our SaaS solution doesn't work unless it has an IDP associated with it. And we obviously wanted to integrate with the best IDPs in the world, so Ping Identity was one of our first choices when we did that. And so together, our platform is really complementing each other. They they come together very easy, with simple integrations and APIs. Just a few clicks on both sides and a few sharing of of details and keys, and and you're off to the races. You can do this with SCIM integration. It provides a real fast time to value. If you're migrating or transitioning, it provides a lot of flexibility in terms of, as Jason talked about, the use case environments that we can both deliver are pretty broad and and conserve the needs of, the largest enterprises in the world with as many, IDPs as as you might have that you need to pull together. And and we're modernizing those things. So we are continuing as platforms to to grow and to support better standards and to provide rapid deployment innovation and and and have the ability to to flex really well on your digital journey as you onboard new, workers, as you onboard new environments, as you onboard new customers. We can together provide a very composable architecture for you to to to bring those elements together. So let's talk about the challenge. You know, securing access to all applications has gotten really hard because traditional networks, and traditional applications have gone, to the cloud. They've gone to, private data centers, public data centers, SaaS applications. Employees are now, you know, working from home. You also have contractor access you need to deal with that doesn't need the same, privileges. And the hackers are out there attacking both the applications and the users to try to find ways to gain lateral movement across your environments and to go after the data, or to to plant malicious code in your system to do ransomware. You guys all know these problems. You all know the adversaries and, you know, we need as defenders, we've gotta provide a lot of strong solutions. And so companies obviously rely on zero trust and and the ability to to bring together, zero trust in this day and age where applications have gone all over and you and users have gone all over, is very hard to do. And we've had the notion and the idea of zero trust for, you know, almost two decades now, in a in a in a way, but we haven't been able to sort of figure that out now as the application and the perimeters have have changed for for users and applications. And I think that's what we'll talk about today and get into a little more. Yeah. And just to add on to about, about the zero trust, again, you ask, you know, five five different people, and they'll give you, you know, kinda five different answers on on what zero trust means to them. And and that's why having, you know, both Cloudflare and Ping Identity be so, you know, con so consumable and customizable. We can really beat you wherever you are in your journey and, you know, make that experience, exactly how you want it to be with the technology you you have, or the technology you need to acquire down the line. Yeah. And I think we kinda wanna understand where you're on in your journey. So the next poll question, should now be up. Where are you on that, zero trust security journey? You know? Are you just beginning? Are you transitioning? Are you modernizing? Do you feel like you have a cobbled together environment? Do you feel like you have everything together, and now you're just integrating more telemetry and more automation, or do you, feel like you have it all all the way, put together and have a great strategy? So, Jason, I think that when we when we're talking about zero trust, you know, you guys were in it from the beginning. You know, identity was one of the the the key domains and linchpins. You know? You have to, trust who someone is and, authenticate them. And the ways that you can authenticate them have changed a lot over time. And and now I think, we're looking at not just workers, but we're also looking now about customers and and how to better manage, verification and authentication of customers. And I I've noticed this trend in the identity and access management space and the IDP space where almost all of the vendors in this space have gone from, you know, a workers based IDP to having a a SIAM, side of the house. Do you wanna speak to that and and, what you're seeing in in customer base with that? Yeah. You're you're exactly right, Mike. So so, you know, zero trust is is really important in in both the workforce, customer and, you know, business to business, integration. So, you know, you have, you know, contractors that need to access your system. You now have, you know, online, you know, websites or storefronts that you need to allow your customers, to to access, plus your your internal workforce. And you really need to secure all fronts of that. So, again, you know, if somebody is signing up for for an account, for example, you need to make sure that you're doing your your due diligence on, you know, fraud prevention. So you don't have, you know, malicious accounts being take, you know, being raised to take advantage of, you know, a 10% sign up, you know, sign up offer or, you know, make sure that, you know, somebody is who they say they are through Yeah. You know, to eliminate account takeovers and identity verification. So you're seeing customers want to have a uniform way to both, manage their workers' IDP and their customer IDP, essentially. A %. Hundred percent. And and the nice thing and, again, thing with, with Ping Identity, you know, from the workforce perspective is, you know, we'll we'll work with whatever IDPs that you have as well. So we're, you know, we're IDP agnostic. Of course, you know, we're an IDP ourselves, but, you know, if you have, you know, another I IDP that you currently use and are and are happy with, more than, you know, more than welcome to still use, you know, Ping Identity other services, and, you know, we'll happily integrate with, you know, with the the IDP of your choice. And then, again, down the line, if you'd like to, you know, to migrate over or, again, keep them separate, you know, perfectly, perfectly understandable, you know, up to you. And, again, like you said, it, you know, kinda covers, you know, multiple areas. So it really comes down to, you know, you need to verify, those identities are who they say they are. You need to, you know, provide threat protection and, you know, make sure that, you know, it's not a bot trying to, you know, to to to create an account or, you know, you don't you're not in a in a possible, travel scenario. Let's go ahead. If we have the results, let's take a look at at where our audience today is on their journey. Transitioning to modern zero trust practices, I'd love you guys to add in the chat what you feel that modern zero trust practices are. We're gonna go and share, I think, some ideas of what we think they are. But still, it pretty significant amount of people dealing with legacy systems or just starting out. That's over 40% of the population. And I think the statistics, that we have seen is that 15% only feel and this is about right. 15% feel like they actually have everything they need. And so that that's about we're about 15 or 20% depending on how you wanna read it. So that's great, and we'd love to hear from, all of you experts on how you got there and, what you're doing now if you feel like you've already, taken it to a pretty optimal level in terms of your zero trust architecture. Alright. Let's keep moving on. Let's talk about, the risks and complexity for those, folks on their journey that are just starting out. You know, you guys know better than me. The attack services have expanded on both the user side and the application side because of this sprawl and because of the complexity of hybrid environments, because of the the, remote worker, because of the contract worker. And on top of that, just applications. I've heard that some companies have over 1,000 SaaS applications that they subscribe to, and that's a very challenging by a uniform way to audit and secure everything that's going on, in your environment when you're dealing with that many applications. And, we know how we've dealt with those solutions in the past. We've oftentimes, you know, had DMZs back when everything was behind the corporate firewall, And a lot of those DMC services, whether it be a firewall or or a WAF or a DDoS box have been moved out to the cloud as a service. And that's was, at the time, I think, a really good way to scale and a really good way to lower cost. But now it's gotten really complex to manage, a bunch of different security solutions in the cloud, that used to be in your DMZ, and they had to move outside to protect the applications that were no longer in your corporate network. And, this has this has caused a lot of problems. In the meantime, CCLs and and CIOs and and CFOs still want agility out of the IT network and out of the security network, and they wanna modernize and have digital transformation, objectives, that they're trying to deliver on the business to, keep things flowing, to keep transitions happening. And they've gotta provide universal ways and easy ways to do this without driving costs up. In fact, we're seeing a lot of consolidation in the market right now. Lots of, CFOs and and CIOs are saying they're being asked to cut budgets massively, and they're seeing ways to do that is only by eliminating the number of vendors. So I think there's gonna be a big move in the next five years to best of breed platforms coming together, and that's, why we're here talking with Ping Identity, that we think we both have some, some great platforms. So we talked about employees and and users and devices and how there's been a lot of, deprelim deprelimiterization of those of those, devices and the castle and mode architecture is no longer work and how the DMZ is exploded into cloud services and into across the network, and it's extremely hard to build a network now with all these services to support in a uniform way all the applications that you have, which have have moved also, off the corporate, data center and out from behind the corporate firewalls and, and into SaaS and into cloud hosted or hybrid host environments. And so you can see in a zero trust architecture trying to pull together all the components, on a global basis or even just a localized US basis, into one cohesive architecture to deliver service, in a low latency way and in a uniform way can be very difficult. And that's where we think a lot of the the traditional legacy vendors, did not necessarily have the right design approach, and we believe, Cloudflare has taken a a really smart, design approach to delivering zero trust across its connectivity cloud. And that connectivity cloud, you know, as I said earlier, every service, in our SaaS re SaaS stack, whether that's our, our, zero trust network access or it's our CASB or our DLP or our secure web gateway. It runs as a microservice on a server in every data center and every pop, around the world for for, Cloudflare. So you get a global network. You don't have to build a global network anymore. You don't have traffic that's tromboning to these various different services, as the flow of a user or as the, protections of a user, in zero trust need to be enforced. And I think that's, where the connectivity cloud provides a lot of value. I don't think I mentioned it, but we do sit, fifty milliseconds within 99% of the world's populations are fifty milliseconds away from one of our pops. So you're really getting a high performance network to deliver the the service from a zero trust perspective. And, this is really here. We won't spend a lot of time on it, but it's, you know, one programmable interface. So we have, one user interface to deliver all of these services, both network security, and the operational services for analytics. And so this provides a a really uniform way in a very cohesive way to build composable architectures, as you phase into or as you journey with modernizing your stack. You don't have to take everything on at once. You can start simply with improving your VPN experience for your users so they don't turn those off, to gain access to services or systems. We have a very lightweight agent called Warp, that's part of our, SASE solution, that that helps, you know, deliver a uniform way that that, endpoints can connect to our system. We also have warped tunnels, and we have tunnel tunnel, other tunnels and and, c and I connections that to our network that can connect bigger systems or entire data centers, in a highly reliable and, secure way. So let's talk about how we unify, and and, your your how you manage risks today and what Ping Identity and Cloudflare do together. So I wanna talk about this in the larger ecosystem first. We've built a very programmable way that, our services can talk to and be integrated with from an API perspective to the leading, vendors across the entire zero trust domain space. So you have identity, endpoint devices, both users and servers. And, you know, you have leading vendors like CrowdStrike, SentinelOne, Microsoft, Tanium in this environment. And all of those endpoints and the posture of the endpoint, whether it's a user or server, can be shared, state and signals back to, our access environment to make a decision on or to write a policy on. Additionally, as we're talking about here today, obviously, all the leading IDPs, you can have multiple IDPs being used and integrated, just like Jason said, they can do also so that if you have an acquisition or you have a set of applications that use a separate IDP, you still have one uniform place to bring that access policy and the access decision and that identity orchestration together for those varying environments and varying IDPs. And then lastly, obviously, you wanna pull all that telemetry across the network and security stack back to a SIEM, whether that's, Splunk, Datadog, you know, CrowdStrike, SentinelOne, Singularity AI, SIEM, or or whatever it may be. We have that ability to to provide that back in a uniform way. But the beauty, I think, that of this architecture is that this is a is is this is all about, conditional access and and expediting, XDR in my mind. And so when when you do that, what do you ultimately get? I think you get a a, a modernized, zero trust architecture and a modernized SOC. And the policies and the automation and the dynamic enforcement on conditional access that can be programmed into both Ping's environment and our environment provides a really robust way to deliver, value. And so we wanna see more organizations, stepping up and automating, and using, architectures like this, to move forward. And just to add on to Mike's point as well, you know, you'll see it in the demo coming up shortly, how also Ping, you know, consumes those CrowdStrike identity signals. So in our in our demo, we do, you know, we use, you know, CrowdStrike as as one of our, yeah, you know, risk signals that we aggregate and and pull together to make decisions on. So you'll see, you know, how Ping Identity can do that as part of your orchestration flow for your orchestration experience coming up shortly. Yeah. And I I think we need to you go ahead. You you can talk. I think I know we spent a lot of time on this, but, you know, this is the main principle of zero trust is to is to trust nothing and verify everything. So when we look at our solution together, we pull together some of the the core components, that that people need. And and by bringing, you know, our zero trust network access, and, and posture risk scores that we get from CrowdStrike or SentinelOne or Tanium or Microsoft Defender Intune, we can also then layer that, obviously, with the identity flows and and be a access proxy to, deliver, conditional access, and automated enforcement across, varying degree of environments, whether it be worker based or customer based. And, also can could layer in, lots of different, policies beyond these these two modules. So having secure web gateway there to make sure that any links that people are clicking on from email or any links or commanding controls that are trying to gain access to a system, our shutdown can take place, obviously, across our network. And, I think we can keep going here, Jason. I wanna get into your orchestration and how you guys provide this adaptive access. Yeah. So at the core really of of that zero trust model is is that, that continuous adaptive trust. So, basically, that, you know, that never trust always verify. So you'll see again, you'll see coming up in the demo, but every time you try accessing, an application, for example, one of your SaaS applications, we're gonna go through and and perform an analysis on all those signals. So each each subsequent execution of that, of that attempt to log in to your application is gonna go through that check. And every time it'll it'll do it, it'll potentially take you down different paths depending on on where those signals come from. And really, we we kind of break that down into three phases, a detect phase, a decide phase, and then a direct phase. So detect phase is is that aggregation of all those signals, whether it's, you know, CrowdStrike in, information, Cloudflare information, our own PingOne Protect, risk, signals. We basically pull all this together, and then we, put them over into our, into our PingOne authorized, platform. So that is our our fine grain authorization tool that allows us to really have granular control over, what you want those, you know, scenarios to be. So you can say, you know, if crash incidents are on the device and a certain risk score is, you know, is this, you know, plus they're on an anonymous network, you know, and, and, and, you can you can have that be one experience and then another one depending on on really how you want that, how you want that to be. Now when we combine that with, you say, Cloudflare access, for example, we can also further add on where, you know, in order to access an application, you need Cloudflare work before you even get started with that flow. So you can basically have, you know, an extra check before you even are presented the ability to, you know, authenticate and and, log into your application. And, again, the the direct phase is is that output, at the end. Do we block access? Do we allow you to go through? If we are gonna allow you to go through, do we allow you in a passwordless flow? Do we, you know, require you to, step up and do an MFA? Or do we do you know, ask you to do, an ID verification to, you know, make sure that you are who you say you are? You know, things that things of that nature. And, And, again, this comes down to, this particular, demo, but we have, again, we have DaVinci, in our, Penguin multi tenant, platform, and then we have Journeys in our, Penguin AIC platform, which is our single tenant, dedicated, SaaS product. So we have a robust, orchestration tool and, in in all of our products really that allows us to really, have that control over that detect, decide, and and direct phase. Yeah. I think this is one of the bright spots of ping, and, I know customers love this as going to your sales kickoffs and going to your your conferences every year. This is a a a great advantage of the of the Ping platform. And I think we're demoing this later a little bit. So We are. It's it's it's very powerful, and and, it's it's honestly, it's it's a it's a game changer. It's really exciting, and really, really flexible and and honestly easy to use. So it's it's, it's really, really powerful tool. And just as a as a few examples, of of kinda how we progress through that detect aside direct phase. So on the detection, phase, for example, we can do, you know, bot detection and then, you know, maybe bring in a, like, an ID verification if you want to at the at the beginning. So you can do, you know, gov ID, biometric selfie matching, you know, things that's you know, things of that nature. So you can do, you know, that at the very, very beginning of your flow, or later on. Again, depending on on how you want your experience to be, you have you have control over that. And then, for example, with our risk signals, you can get you can you can take, risk signals from a number of, you know, third party, providers, and then, again, make decisions based off off of that. So, you know, if you have, you know, firewall update or if you have disencryption turned on or, again, you know, you're using a possible travel. So you've logged in, you know, in LA at 9AM, and now you're logging in from New York at 10PM you know, 10AM. It's not you're not able to travel that distance in that time. So that could be a, you know, a risk, you know, a risk score. And you again, you have control over what weight you wanna put on those. You know, you have multiple people coming from a single IP. In a customer scenario, that's probably a risky a risky event. But, in a workforce, that's probably not a risky event because, you you know, you'd have people coming from a, you know, a a common building with, you know, one, you know, IP egress point or, you know, coming from VPN. So it really allows you to to control and customize what is important for your particular company and and your and your customers and your workforce. And then we take that to the to the decide phase. So, again, we do that dynamic authorization on policy based control. So you can, you know, you can take all that, again, combine it with, say, Cloudflare access and really control how how you want that experience to be and how you want that to flow for your users. And then, again, we we have that, you know, that, that direction phase at the end of of, you know, where you want them to ultimately, end up. Again, with DaVinci, we allow the ability to do AB testing, so you can actually have, you know, two different, policies running. So if you wanted to, you know, implement a new policy, but you wanted to see how it compares, you know, to your to your existing policy, you can, you can have those flows, set at, you know, say, 5050%. So each time it'll, you know, you you you'll run one flow, and the next time you run another flow. And then you can get an idea of, you know, different abandonment rates or, you know, how long it took a user to get through from start to finish. We have really deep analytics, on on this information as well. So and this is just a sample of what a a DaVinci flow, you know, would look like. It's really just drag and drop. It's a low code, no code orchestration. So, again, we have connectors, for, you know, a lot of, you know, different tech partners, and we have full rest API capabilities. So, you know, if you don't have the current connector, but, you know, they expose APIs, we can integrate with it. Yeah. And I think, you know, we're gonna move really quick over the next few slides. I wanna get to your demo, and let people have time to answer questions or have us answer questions. But, you know, enabling this identity defined security, you know, you can see from all this stuff that, Jason just went through. Their orchestration's amazingly powerful. They have ability to to provide a very, you know, composable architecture for the identity decision process. But I wanted to show kind of how our Ping Identity one and zero trust at the z t and a level for us comes together where we act as an access proxy. So this just kinda demonstrates, one, the, you know, the second first step is to set up your Ping Identity. The second step is to just add Ping Identity one, to your zero trust control plane. And we pull it we pull in all the identity users and and then can make decisions on users as we see them make requests, to various applications. And as we proxy those, requests, we then can can check, various aspects to see if we need to send them back to, and see if they're fully authenticated or not or to force them, in a conditional access environment where we see a risk change on our side happening with the user to force them back to identity to reauthenticate or to be logged out of all the applications potentially that they're already logged into based on on the risk. Go ahead and and move on. I also wanted to show just kind of we talked about how we do cover a lot of use cases. I kinda wanted to to touch base on those use cases to make sure that you guys understood what the key the platforms are both capable of of delivering. So this is a, a reference architecture, from Cloudflare with with Ping Identity involved in it where it's showing, you know, the ability to to, obviously, as Jason talked about, you know, cover standards and protocols that are standard in the industry, single sign on federation, but also, to work across, both the workforce use cases and the customer work cases. So this is, demonstrating, both, you know, workers in office, out of office, contractors, also customers trying to gain access to, various websites. And and and the ability for the zero trust to play a role and also our traditional services on the application sides. So the ability to sort of merge enforcement on ingress and application together. I think that's a unique aspect of Cloudflare. And we have all these great application services, WAF and and DDoS and API gateway, where lots of rules and policies can be deployed. And, the hackers aren't just going after users. They're going after the systems. They don't care which way they gain access to the data, whether it's, you know, through a vulnerability they find on the user side or it's on the the application side. So I think we provide a very, unique way, whether the application is sitting in the cloud or it's a SaaS based application or it's just, the Internet facing applications of a company to take the telemetry we're seeing in those environments and bring them back into, the risk score for the users and and keep that uniform and unique. So sort of zero trust, from ingress to applications. And so together, we provide this future of identity security networking coming together, this composable architecture, for both Internet and Internet existing together, on ramps, off ramps, the ability to enforce policy for all of those, ingress and egress points, and the ability to do that in a in a comprehensive flexible way with just two, single UI environments and and two platforms that are fully integrated and don't need much manual configuration after they're set up unless you're adding, say, a new IDP, into the mix. And so what that brings us to our next quote, which I kinda would love to see what your priorities are. This is kind of the the extension of the where you were on your journey. So as we talked earlier, you know, most of you on your journey were either in the a third of you were in the early phases. A third of you were sort of, in the transitioning phase, and then the rest of you were were sort of in the automation and dynamic enforcement, and optimization phase of of your zero trust architectures. This one, we wanna see that what are your challenges. So, what are you seeing and defining? And you can have, I I think, as many as you wanna choose in this one. So we'll give you a minute here, and then we'll jump into the demo. Jason or VB, do you guys wanna add anything before we get to the demo? Do we feel like we've missed on the presentation because we don't really have much left after this demo? Yeah. No. I think we're I think we've, you know, covered a a good amount of the about good sorry. Good amount of the topics. Yeah. Just looking forward to to getting into the demo and showing how, you know, this stuff works in, in, you know, real world scenarios. So, again, while everyone's filling out the, the poll questions, or your poll answers, yeah, just kinda, you know, teasing what's gonna come up, very shortly with the with the demo. So you're gonna see a, you know, an actual, you know, flow of of, you know, these different, actually, we're gonna go through six different use cases, that that run through these different scenarios. So, you'll see how we get blocked at multiple stages throughout the, throughout the process, and, you know, how we can remediate those, those different actions and, you know, progress through the the authentication experience. That's great. And and there were some of the questions, on the chat overall, but please feel free to send any more Q and A as well. I know there were a bunch of them, and I've answered them. And if there are more, please please keep on sending those. Thank you. Yep. I see a lot about SCIM in there. I see a lot about Cloudflare's, traditional services and how they can be used in front of, you know, identity and customer identity. So I think these are all, you know, great questions that you guys are coming up with, and I hope, BB's answered them too. You're liking it. If not, you know, feel free to to set up calls with, paying our ourselves, to to make sure you guys get your answers, and have any, discovery sessions that you want with us. So do we have answers on this yet, Jason? I think we're getting there we go. Got the results. Okay. So, I mean, it's across the board. Strengthening the the, the cloud access security broker is probably the the least of their concerns or challenges. Biggest challenge is replacing the VPN. Yeah. So I'd I'd love to, you know, hear see in the chat, the specific problems you're having. This is an area where Cloudflare has brought a lot of value to customers. We know some of the incumbents have, with their Internet access, VPN agents have have got a lot of trouble, in terms of maintaining, a consistency of use and a and a consistency of policy enforcement, and, and trouble gaining access to to various systems. And a lot of times, employees turn these systems off. That's not something that we wanna do. We actually provide a a a corporate warp client. It's, akin to actually our free client that we've had for a long time, which is our our, 1.1.1 service, which provides essentially secure and accelerated DNS resolving. So basically providing, you know, clean pipe service to various web applications out there by just basically with DNS. But we take that up a huge next level with our WARP client, and we use that resolver, but we also, allow a lot of customization for the enterprise, in terms of routing and in terms of, access applications and in terms of integrating directly on the endpoint, with, synchronizing endpoint information, browse drive or seven zero one, or gaining other attributes off of the endpoint to bring it into the access decision. And and we see as well that there's a good, a good percentage of, of the attendees are also, you know, interested in, you know, enhancing IDP capabilities and consuming more signals for for fine grained enforcement. So, which is which is exciting because that's, what our our demo is gonna cover. So we'll lead into the into the demo now, and, hopefully, you know, this demo, gives you an idea of, you know, different ways you can integrate with, with different, different partners, use your own signals, and then, again, you know, kinda take that to, to build your out your flows and Yeah. And then get The other one that stands out is the, you know, obviously, implementing zero trust network access in a uniform way and then also reducing the overall risk was pretty high. We're almost half the or 40% of the respondents said that. So I think that, yeah, with these two platforms, you can you can gain a lot of control over that, risk. And I think that risk is that the surface area has expanded so much that it is really hard to control it in a uniform way. And so I think our orchestration, your orchestration, and the composability provides a lot of of, support for trying to get to that direction. Let's go into these demos, though. Great. Yeah. So the demo coming up, we're gonna go through these six use cases. So the first flow we're gonna go through, we're gonna get blocked because we don't have Cloudflare warp enabled. The next case we're gonna run through, we're gonna get, blocked because we have a Cloudflare we're doing a Cloudflare IP check, through our DaVinci tool. And we're gonna simulate a a bad IP. So it's gonna block us before we get any further. Then we're gonna pass that check and then get blocked because we have crash like incidents on our device. And then after we pass all those checks, we're we're gonna gonna take us to the allowed, the allowed flow that'll take us to our application. And then, we'll do another scenario where we can show that, we're also using, the Cloudflare, group membership. So in in the Cloudflare policies, we're actually gonna be sending data as part of our authentication flow and and as part of our OADC, login authentication flow. We're actually sending, groups claims to Cloudflare. So we're gonna send, groups from, from Ping Identity one of, which groups that user is a member of, and our Cloudflare policy states that in order to access that application, you need to be a member of this particular group. So if we don't see that group in in the claim that we send over to, to Cloudflare, then they're gonna get blocked. So you'll see that as a as an additional block as well. And then we'll show, a a final one where if we're running an incognito mode, for example, in our browser, we don't have a lot of that, telemetry, and, information that we've that we discussed. So instead of blocking the user, we're just gonna do an extra step up to username and password and then, and then trigger our our ping ID MFA. Great. Very comprehensive. Can't wait to see it. Okay. So this is the demo. So, I'm just gonna talk through this, while it's running. So I'm just logging into our application portal here. So this is the PingOne application portal. Again, I'm I'm just signing in with, with a test user. So once I get, signed in, you're gonna see a number of applications available to us. In this particular case, we're gonna access, an application that is being protected by CloudFlare access, And you can see that Cloudflare warp is not enabled. So when we first, click this button, we're immediately gonna get blocked because Cloudflare is is saying that in order to access that that Internet site, that protected page on the, the internal Cloudflare website. I'm just gonna pause this here. So that internal protected page on on, that Internet page on CloudFlare is being protected by, by their their zero trust module. So in order for you to access that at a bare minimum, you need to have warp. So once we turn on the warp client, we'll get past that first check, and then we'll you'll see how DaVinci will take over and, and handle the rest of the signals as well. Okay. So we we've turned on Cloudflare warp. You'll notice now that when we try this attempt again, it's gonna now let us through. And now we're at the the landing page, and now we're gonna we're gonna click on our our button here to, to kick off our, PingOne authentication experience. So this is, just some demo screens from DaVinci that we just provided here just for, just for, information purposes. Again, in a in a normal real world scenario, this would all be hidden. You wouldn't, you know, you wouldn't, display these, you know, to the end user, of course. But this is just showing that we have an active session, that we've signed in to to Ping Identity because we've signed into the application portal. Therefore, we have an active session, that we can then use, you know, use that session for, for, authentication throughout the flow. So the next thing we're gonna do, we're we're gonna skip over to the next, and now we're doing a Cloudflare check. So the Cloudflare check is we're simulating, a bad IP. So this is simulating that we're coming from a bad IP address. Again, it's hard to simulate a real bad IP, so I've just configured this in DaVinci to use a sample IP address. And the Cloudflare gives you the option of using this 192020 IP, which comes back as a test net, output. And then I just have in my DaVinci flow that if I have this in my in my output of that, of that, call to Cloudflare, consider this, a bad IP. Again, in a real world scenario, you'd use the actual, you know, person's, IP address. But, again, just simulating this. But you'll see again that we're being, we're being denied, because of Cloudflare. So, again, the the main idea is never trust, always verify. So this is just I'm switching it back to a known good IP, just 111, and I'm just using a variable. So this is our very quickly DaVinci interface where we can define variables that you can actually use throughout your flow as well. So we're gonna execute that application again. We're gonna run through the flow. Again, we're gonna skip over the session data, and now you're gonna see that the Cloudflare, is no longer blocking your IP. So now as according to Cloudflare, we're coming from a good IP, so it's gonna let us through that that Cloudflare check. So that's, you know, the second use case now where we'll be we'll be completing. There's no risks found for for IP, so we're gonna we're gonna continue over to the next screen. Now this next screen is gonna basically be just, again, a displayed screen where we're showing that we're aggregating a lot of signals from, from multiple partners. So in this case, we're consuming our Ping Identity risk signals. Again, normally, you wouldn't, you know, display this, but, just as an example, you know, we're we're pulling in Ping Identity risk signals. We're using our Chrome device trust agent. So we have Chrome device trust running on this browser, which allows us to get some information from the local device itself. In this case, what we're getting from the device is the CrowdStrike agent ID. So we're using our, Google Chrome device trust to get the agent ID for CrowdStrike, which we then send over to CrowdStrike to look up any incidents on the device. And then CrowdStrike responds back with that information, and, we extract some of that information out. So, again, on the left, you can see the large, you know, JSON object of of all of all of our data. And then the right is just, you know, some, some simplified extraction of that data for, you know, for visibility purposes. So you can see that because we have CrowdStrike incidents on the device, we're now gonna get blocked because our policy states that if we have any incidents in CrowdStrike, we're not gonna let them through either. So now you can see access denied. So now I'm just gonna jump over to CrowdStrike. I'm gonna simulate my incidents are no longer open on the device, so I'm just closing them out. And I'm gonna jump back over to my machine. And, again, from the user's per perspective, they have not done anything different. They have not logged out. They have not done anything different. They're just trying to access the application again. And this is that main that main point of zero trust is always verify, never trust. So every time we do this execution of that application, it's gonna run through these, run through all these signals and make sure that every time you access that application, you're coming from a secure trusted device. So now you can see that we have no incidents on the device. So, you know, we still, you know, pulled pulled CrowdStrike. We still have the CrowdStrike information, but it's now saying we're we're clean. We're good. So once we go through, it you'll see that it's gonna drop us, on our final application, which is, again, that that, that comes to the internal Internet site. This is great, Jason. And I I also think one of the great things too is that we also integrate with CrowdStrike. So the WARP client, when when it's on there, it synchronizes and creates a service to service integration that matches the end user, endpoint, to, its identity on our side. And, and then if you guys were to grant it and then say the risk score were to change in flight, meaning as a user is using applications that you've already authenticated them in, you've already checked them through a CrowdStrike. But if that changes over time, the access proxy can then have a policy as it sees this change in score happen to deny it or to remediate it or to send it back to you guys for reauthentication. So I think that's the beauty is that we're both integrated with CrowdStrike, and so it provides us layered security defense, and dynamic enforcement as as risk scores change, even after a user's been authenticated to an application and they're just using it. Yeah. That's that's a great point, Mike. Thanks. And, yeah. So just as as Mike was, you know, talking through through that and, again, how, you know, how CloudFlare can consume the CrowdStrike signals directly as well, we went and removed the user. So this is that, that fifth use case now where we had a a a user group called Cloudflare employee in Ping Identity. The user was a member of that, which is what allowed us to get through. So now we remove that user from that group, and we're gonna try that authentication flow again. So I'm gonna jump back over to the machine, and, I'm just gonna sign back in. Again, just because I I cleared the cache, in between these sessions just to, you know, show a, you know, a clean authentication experience. So I'm gonna sign back in, and you'll see now that because we don't have that active, group required from Cloudflare, Cloudflare is gonna block us now. So this was the previous examples that we showed, was DaVinci blocking us, but now this is going to be showing that Cloudflare is actually gonna block us, based on the, the, the Cloudflare policies that they have in their system. So, again, just to reiterate, the Cloudflare policy that we that we set up for this demo was we need to have WARP active. So you can see in the bottom right that we have, you know, the WARP client still active. But we also made a requirement that you needed to be a member of that group in order to, access the application as well. So after we're we've authenticated, you'll see now that we do not have access to that application. So, again, user hasn't changed anything. We passed all our DaVinci checks, but Cloudflare said, hey. I didn't get that group membership that's required for you to access that application. You passed all the the DaVinci checks, all the the the ping checks, but, you you don't have that group membership that we want. So this is still an, I guess, an extra, enforcement from, from Cloudflare to, to make sure that, you know, you have everything that they that they want as well. So the last thing we're gonna do is we're just gonna add that user back into the group, just so we can we can progress through this last, this last, test. So I'm just adding the user back into the group. Again, you can see how easy it is to, you know, to manage, group membership, and how clean the interface is in Ping Identity. So I've added the user back to the group, and now I'm gonna run, this last test through an incognito browser. And I'm just doing that mainly to turn off the Chrome device trust, check. So, so Google has implemented the Chrome device, the the Chrome device trust agent that, it doesn't, it doesn't work in incognito mode, again, for your for your privacy. So when you're in incognito, we don't have those device signals from the device. Again, specifically, the one we care about, in this particular, scenario is that CrowdStrike agent ID. So, you'll see that, once we get to that, that aggregate signal screen, we don't have a lot of information on the device. We don't have a lot of, we don't have a good picture of the the the trust and security of that device. So, again, in our policy, we said we're not gonna necessarily block them, but we're gonna force them to do an extra username and password check, and we're gonna do an MFA push. So, again, you can see here that we don't have device trust. Therefore, we don't have the CrowdStrike information, so we don't have a, you know, a great picture of the device. So let me just, skip this through a little bit. So you can see here, it's just gonna prompt us again for a username and password, and then it's going to do an MFA push. This is using our Ping Identity app. So I'm authenticating. And then because I've done the extra username, password, and MFA, I'll still let me it'll still let me get to my application. So you can see that we've dropped back on our application now. Awesome. Well, I think we've hit the top of the hour, and I appreciate everyone staying around. We'll walk through these Better Together benefits, you know, but Cloudflare has has done some a lot of research on return on investment, going with us as a unified, control plane and and and data control plane, enforcement control plane. And so if you wanna look at the economic impact for your company and and how we might be able to help, please let us know. I put my email, in the chat, so feel free to reach out direct if you want me to set you up with the proper team. And, happy to do that. I hope VB's answered your questions. I think he's done a great job from what I've been witnessing and, you know, be trusted to, feel feel, confident that you can trust that, you know, you've got two leading companies that really are committed to each other and delivering high value to, to our joint customers. And and, obviously, this this market leadership slide points to that. So, Jason, you wanna say any parting words? I just wanna thank everybody for being patient, staying with us. It's been a great presentation, I think. Thank you. Yeah. I just wanted to reiterate the reiterate the thanks for for everyone for joining. And, yeah, thanks. Hopefully, you got some, some good information out of this. Again, Cloudflare and Ping Identity are, you know, the two leaders in our respective spaces. So, these collaborations, are are really great for both of us. So we're we're excited to, to work with Cloudflare, and it's been a it's been a great partnership.