Identity, SASE, MSSP, Zero trust

Cloudbrink Adds Identity Management and CrowdStrike Integration to Streamline Zero Trust Access

(Adobe Stock)

Managing access in hybrid environments is rarely straightforward. Between internal staff, contractors, vendors, and multiple identity systems, most organizations end up juggling fragmented tools just to enforce consistent security. Cloudbrink’s latest update to its Personal SASE platform tackles this head-on by adding native identity management and CrowdStrike integration - bringing identity, device posture, and policy enforcement under one roof.

At the heart of this release is a shift in how identity is handled within a SASE architecture. Rather than assuming every user sits neatly in an enterprise IdP like Okta or Entra ID, Cloudbrink gives customers the option to manage third-party users locally, directly on the platform. That flexibility can dramatically simplify things for teams trying to onboard and govern external users who fall outside the core directory.

“Traditional identity providers like Okta or Entra ID are still important, but Cloudbrink’s native identity management reduces the operational dependency on them, particularly when managing third-party users who aren’t part of the core corporate directory,” said Prakash Mana, CEO of Cloudbrink to MSSP Alert. “Most SASE platforms assume every user is centrally managed in an enterprise IdP, which becomes a problem when onboarding contractors, vendors, or project-based teams. Cloudbrink lets customers define and manage these users locally on the same platform they use for secure access.”

That includes native OTP, local group mapping, and access policies, all managed from a single console without duplicating users across systems. The result is simpler identity governance for non-employees, without sacrificing policy control or auditability.

Policy Enforcement That’s Built, Not Bolted On

Where many SASE vendors bolt together disparate systems and call it “unified policy,” Cloudbrink built its engine from scratch to apply consistent rules across users, devices, and networks. There’s no second guess on which rule takes priority or whether policies are enforced the same way across tools.

“What’s different is that Cloudbrink built its policy engine and access control logic from the ground up as a single system - not as an overlay of multiple tools,” the spokesperson explained. “A policy applied to a group, whether defined in Entra ID, synced via SCIM, or managed natively in Cloudbrink, behaves the same way. That includes nested groups, multi-group membership, and device-based access. It’s a single pass engine rather than a stitched-together stack, which avoids policy conflicts and reduces drift between what’s defined and what’s actually enforced.”

This architecture pays off in speed and simplicity. Even small IT teams can manage thousands of users and devices, define nuanced access controls, and monitor posture without bouncing between consoles or syncing policy definitions manually.

CrowdStrike Integration: Real-Time Risk-Based Access

The CrowdStrike integration brings endpoint posture into the access equation. Cloudbrink reads Zero Trust Scores directly from Falcon and can immediately block or restrict access from risky devices. That enforcement happens before a session is established, at the edge and on the endpoint itself.

“The time interval by which the integration reads CrowdStrike's Zero Trust Score is configurable, and could be set as low as 1-minute,” the spokesperson said. “If a device is compromised, untrusted, or out of compliance, access can be blocked or limited immediately - before any connection to protected applications is established. In practical terms, that means infected or misconfigured devices can’t pivot inside the network or access sensitive apps, even if the user credentials are valid.”

It’s a clear fit for organizations with distributed workforces, where the old perimeter no longer exists and risk can show up from anywhere, at any time.

Built for Channel Scale, Not Appliance Overhead

Cloudbrink’s platform is designed to be delivered by partners as a managed service, especially for mid-sized businesses that don’t have the in-house resources to run a full security stack.

“Cloudbrink offers a single, multi-tenant management console that partners can use to onboard, configure, and support multiple customers,” said the spokesperson. “There’s no appliance to ship, no hardware to manage, and no need to operate dedicated gateways or PoPs. The software-only model allows partners to deploy in minutes and manage identity, access, and endpoint risk from the same interface.”

For partners, the simplified model means faster rollouts, lower support overhead, and a pricing model that doesn’t get in the way of margin. For customers, it brings enterprise-grade control and real-time threat prevention without the enterprise-grade complexity.

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds