Zero Trusts Given

The Power of Zero Trust Ecosystems: Securing the Tactical Frontline

Episode Summary

In this episode of Zero Trust Given, hosts Tom Tittermary and Tom Gianelos are joined by Okta's Tony Ardura and Bhagya Prabhakar to discuss how identity serves as the foundation of Zero Trust for the Department of Defense, particularly in disconnected, degraded, intermittent, and low-bandwidth (D-DIL) environments. The conversation explores how cloud-native identity and access controls can be extended to the tactical edge, enabling warfighters to securely access mission-critical applications and data even when connectivity is unavailable, while maintaining strong security, resilience, and operational agility. This episode also addresses mission partner access, fine-grained authorization, identity resiliency, and how organizations like Okta and Zscaler are working together to deliver scalable, secure, and mission-ready Zero Trust architectures for the modern battlefield and beyond.

Episode Transcription

[Tom Tittermary]

Well, cool. Hey, everybody. Welcome to another episode of Zero Trust Given.

 

Once again, you've got myself. Unfortunately, Tom Tittermary is your host this week, along with our illustrious, incredible, intellectually brilliant Tom Gianelos. Say hi, Tom.

 

[Tom Gianelos]

Hey, everybody.

 

[Tom Tittermary]

Yeah. And this week, we have some very special guests along with us. We've got two very special folks from the Okta side of the house.

 

So, we've partnered with Okta from a Zscaler perspective for a very long time. There's a lot of similarities between us as companies. You know, we've been in business for a long time.

 

on the enterprise side with cloud solutions for DoD, but also working to cover the tactical side. So, we've got the two folks in the room today, I think, would be just right to handle this conversation. And I'm going to let you guys introduce yourselves.

 

Tony?

 

[Tony Ardura]

Yeah. Hi, all. Tony Ardura.

 

I'm a solutions engineer here for Okta, supporting a lot of the DoD, but not all of it. And then, I also have...

 

[Bhagya Prabhakar]

Hey, everyone. I'm Bhagya. I'm a product manager at Okta, working on the Okta Access Gateway.

 

[Tom Tittermary]

All right. Very cool. So, a very common topic to this conversation.

 

So, guys, welcome to the show. We typically just try to take a number of steps back and have kind of wide area conversations about zero trust and DoD as a whole. Right?

 

So, the long and short of it is, how do I grant the least amount of access to just the right person at just the right time? Right? And the way that we typically end up having this conversation is, there's two main areas of it, where there's typically like an enterprise notion, like there's a bunch of folks sitting around a data center or an office building, but then we also have the conversation, like we had a great episode with Jerry Sheppard from Hyperi, where we talk about the tactical angle at the same time, and all of the different little intricacies that happen out at that edge.

 

[Tom Gianelos]

Absolutely.

 

[Tom Tittermary]

Could you guys talk to us a little bit about... Okta is a company, like Zscaler, kind of started in that big enterprise area. What was the thought process about how you guys were internally working around coming towards that other side of things, that tactical side of things to help DoD?

 

[Tony Ardura]

Yeah. I think I can take that first, but yeah, so obviously Okta is the world's identity company. We are a cloud-first, cloud-native solution for identity, and we are able to support a lot of those enterprise use cases off the bat.

 

So where that kind of ran into a little bit of a rub, obviously the DoD does not always operate in hunky-dory, everything is great, we are fully connected, et cetera. We have to worry about these foreign adversaries that are trying to take down networks, deny us of those resources that we're supplying to that warfighter. So we have always come to that, we need to support that, and that's where we're kind of leaning into today, and at the moment as a company.

 

We've previously done this predominantly with third parties, Tactical ID. We have several different white papers on the Okta environment around how we integrate with Tactical ID. The Tactical Identity Bridge Appliance is their product, TIBA for short, but we are also providing a first-party solution with OAG Offline, which is why we're here today.

 

So we aim to facilitate every identity use case, authentication, authorization, governance, how those users get access to the right resources at the right time, and only those right resources. Obviously, you guys come out from the network side a lot of times, and also the application side. However, it all ties back, in our mind, we're biased, ties back to the identity.

 

You have to know who the person is before you can even start to think about what they should be able to access, when they should be able to access it, under what specific scenarios. So we're biased, but we think identity is critical in a lot of capacities to every other piece of the Zero Trust pillars, network, data, applications, et cetera.

 

[Tom Tittermary]

Yeah, we're constantly coming at the issue where the number of times that I take 19 steps back from the conversation and try to say, hey, let's look at the forest and stop talking about individual trees. We were just talking about, sometimes we talk about what we're going to talk about before we talk about it. And I just came back off of, I was out at Rocky Mountain Cyberspace, out in Colorado Springs, where we saw each other.

 

The week after that, I was at FCA West, so the Air Force and Navy are the two main customers you run into in those contexts. And the number of, Zscaler had a booth there, I'm sure you guys had a presence as well. I think most of the booths is, the two big buzz topics right now are Zero Trust and AI.

 

And of course, the Zscaler booth, and the biggest font that we can get out of marketing is Zero Trust and AI. And it's tough, because I think customers that come to each of these individual booths, they're getting a story that, this is why Zscaler is Zero Trust, and I try very hard not to do that. Or this is why Okta is Zero Trust, right?

 

However, I always kind of pull back and say, no, no, no, it takes a village, right? So on our side of things, we're kind of the network and the PEP, like Policy Enforcement point, angle of things, where based upon users validating identity and validating posture and validating any number of the attributes, geolocation that they do, they're granted some amount of data or application access, right? We're the- Enforcement of that.

 

[Tony Ardura]

Yeah. The enforcement point.

 

[Tom Tittermary]

At the end of the day, I'm the bouncer at the door, and you get and you don't get, and this is the context of that, right? You guys on the identity side of the house, I think it gets interesting where, for us, we tend to be the path between the user and the thing, and when the user's not supposed to get that thing, we cut the path. On your side of the house, we're desperately in need of- people ask all the time, there's a little confusion of, so Tom, Zscaler, you guys do identity, right?

 

And I go, no, no, no, we're a consumer of it, but it's always hand in glove that we do that together. And I think the single biggest policy decision point signal that we get is around the identity piece. Yeah.

 

Have you guys seen that on your side as well, or how are you guys coming at the issue relative to your exact space relative to the broader conversation? How do you take a step back and then dial it back in?

 

[Tony Ardura]

Yeah. I think you realize that it takes a village, right? And we would agree.

 

We don't think that Okta as a whole does zero trust. We don't think Zscaler as a whole does zero trust. We have a piece to play, we have a part to play.

 

We think it's a rather important part, but obviously, as I mentioned earlier, we're biased. We see that demand signal from identifying who that person is and then passing it on to the relevant, I guess, zero trust partner in that realm, right? If it's a data provider, if it's an MDM, if it's an EDR solution, if it's a Zscaler, right?

 

We would pass on that identity, identifying who this person is, and then obviously allow that zero trust partner to make those necessary controls of whether that person should be able to do what they're trying to do at that moment in time, which as we go into the point of this whole discussion is, well, what happens if you can't reach Okta, right? As I mentioned to the whole, Okta, we're a cloud service provider. So if that is denied to us, being able to reach us, how do you still provide that clear signal of who that identity person is and understand should they be able to perform this while missiles are falling on this forward operating base, right?

 

And they need to authenticate or authorize into the system to fight back, right? So that's obviously a very clear demand signal from our customers across the DOD of being able to support that mission. I'm sure you guys have seen that too.

 

[Tom Tittermary]

I mean, one of the big points that we ran into, I got to be involved on the Zscaler side of the house on the design of the product specifically, right? So one of the things we ran into is the first question we ran into, hey, as a cloud service, what happens when the internet goes away or I can't reach Zscaler? So that's the architectural piece of it, right?

 

Now Zscaler side, we said, I have to build some mini format of our cloud that needs to be able to live locally that can grab that interaction so that things flow the way that they should. And again, the conversation we talk about, we're going to talk about the design principles for us where it's got to be Nokia brick phone resilient and it's got to just work. Like I can't ask somebody at the forward edge to be firing off complex Linux commands to issue some kind of failover.

 

So this just has to work in that scenario where that connectivity drops. But the big conversation I end up having now that, so we've had this capability in Zscaler for about a year, but the number of conversations I get into with individual DOD personnel where I go, great, what is your local identity? And they go, what do you mean?

 

And they go, we're using, I'm not going to rattle off vendors, but there's some level of, I need connectivity to get to dot, dot, dot. And I go, I can't help you until you sort that piece out. And they go, what do you mean?

 

Well, I need identity for zero trust, right? So once they find Zscaler in that tactical pocket, there has to be a redirect or a bounce somewhere to at least validate what the identity is. Because otherwise, how would I, of all scenarios, like that's not the scenario where I'm going to allow somebody in if I can't validate identity.

 

So what did that, so did you get to be involved in kind of the development process on the Okta side? Like what did that look like? Because I had a very interesting time talking tactical scenarios to software developers in California, as we sometimes do in this industry.

 

[Tony Ardura]

So I'll pass it off to Bagia here in a second. So the answer is yes. Because as a solution engineer, we hear firsthand that signal, that demand signal from customers of like, hey, these are the exact issues I'm running into.

 

And very clear to what you said. What happens when I can't authenticate because I can't reach Okta? And that's why we reached out to Bagia and her team to do that.

 

[Bhagya Prabhakar]

So we have a product called the Okta Access Gateway, which is present to protect on-prem applications. So applications that not necessarily live in the cloud. And because we already have this product which currently talks to Okta, but now we're building in the intelligence so that it can also, when Okta is not available, do a local authentication.

 

And use the same authenticators that the users end up using on Okta. So it has the same security that you would get during Okta authentication, but not really when even when you're disconnected from Okta.

 

[Tony Ardura]

And the thing that, going back to Zero Trust, as you mentioned earlier, is we found a lot of customers come to us saying, yes, I need to do identity at the edge, I need to do authentication at the edge. They were just sharing passwords for the most time. Or sharing passwords, using a password in some scenarios for legacy, legacy applications that didn't support CAC.

 

But if they supported CAC, then yeah, they would probably typically do that. So you had this varying of controls, I guess is what I'd say. You had this demand signal of, I need to authenticate into this mission system to do X, right?

 

Because bombs are falling and something needs to happen. And then I also need to accomplish that mission as quickly as possible. So then they ran into this issue of, well, that's not very secure if I'm sharing passwords and sharing accounts for users.

 

And but it's also, it's at the tip of the spear, as we also talk about, what we're talking about, the tip of the spear of where that mission needs to happen. So nothing else matters, we just need to get that warfighter what they need. So from our perspective, how can we make this better?

 

As a whole, as a company, we are trying to make things more secure, make things more accessible, but never have a compromise for security for how users get access to specific sets of data. So being able to have that comprehensive pipeline, we'll go into this a little bit later, I think, but that comprehensive pipeline for the identity from the enterprise, that identity level security for at the enterprise, but also down to the tactical edge. So while they're disconnected, you still have the same, as Bagia mentioned, authenticator strength.

 

You still have the same identity strength, you still have that same clear signal of who this person is. And it's not necessarily shared accounts across many different people. All the same attributes, all the same authenticators, all the same authorization control.

 

So this soldier operating on this base has this MOS and they have this clearance level. Well, what does it allow them to do while they're connected? What does that allow them to do while they're disconnected?

 

Both from an application perspective, a network perspective, an endpoint perspective, again, that identity is pretty clear across all those user address use cases.

 

[Tom Gianelos]

Yeah.

 

[Tony Ardura]

Great.

 

[Tom Tittermary]

Yeah. One of the big, it was interesting having the conversation out in California with the folks, I came at it, I'm going to own up and say I came at it the wrong way. Sure.

 

And I started talking about warfighter and OODA loops and these guys in the striker need to, and they just glass, just absolute glass rolled over. And then I think where we really started getting somewhere, one, there was like a major opportunity we're going to lose track of if we didn't do something quickly. And then the other side of things was the way that I kind of pivoted some of this talk track was there are enterprise solutions from a cloud perspective, right?

 

And then there's a reason nobody's using exchange servers anymore, right? And they're using enterprise workflow with, there's this interesting thing of if I need to travel with the intelligence for complex solutions, then I'm, it just drastically reduces agility number one. And then there, but there's the fear on the other side of, it was interesting that I think the biggest uptick we've seen in a business perspective at Zscaler outside of DoD for these detail like solutions are manufacturing healthcare.

 

And there was a major supermarket chain that actually like came back around. Because these are scenarios where it's like I can't, I don't trust my ISP and I don't trust my local connectivity enough to lose access to these local applications in this scenario. So like this was kind of the way that I had to come back and sell this to Zscaler to go build these things out is like, no, this is the big missing piece.

 

This is what gives you that enterprise global capability with one, you know, one ring that controls them all relative to a enforcement perspective, an identity perspective, but also gives you all the pockets at the same time without the admins that go along with all these pockets at the same time.

 

[Tony Ardura]

And I'll extend that like pharmacies, home improvement stores, right? If a hurricane comes through Tampa, Florida, right? People need to buy tarps.

 

People need to buy plywood, right?

 

[Tom Tittermary]

Where do they go for that? You can't say, can you come back tomorrow? My system's down.

 

[Tony Ardura]

Exactly.

 

[Tom Tittermary]

It's just not a viable approach to that.

 

[Tony Ardura]

Yeah. And sorry if I'm talking over you, but so the, I always say it's like the 99.999% of the time. Yes, you're going to be able to reach Okta.

 

You're going to be able to reach Zscaler in the cloud. But that 0.01% of the time is probably when you're going to need to do things as quickly as possible. And things just need to, as you mentioned, Nokia phone need to work.

 

So yeah, it's incredibly important use case. And I think I applaud both of our companies, right? Being identity and cloud first companies, being able to support those use cases, one of the enterprise, but also meet that use case down at the edge is where we're kind of creating that comprehensive, cohesive portfolio of how we can facilitate that mission.

 

[Tom Tittermary]

Yeah. So what did, to get to, I don't want to go way, way in the weeds relative to it, because I know we've done that. We've talked high level about how the Zscaler side of things works.

 

Could you guys talk about what you have built on the Okta side a little bit? And then if there's cross-pollination for me and Tom to say, oh, and that would connect over to what we did in that place, but I'd love to hear a little bit more about it.

 

[Bhagya Prabhakar]

Yeah. Yeah. So on the Okta side, we have the Okta access gateway that has the intelligence to know, is it good for me to go to Okta to authenticate the user or, oh, the connection to Okta is broken.

 

So let me redirect the user to authenticate locally. And that intelligence is built into the gateway product. And this gateway product would be set up as the IDP for all the applications that need this intelligence.

 

So the applications always talk to this OAG and then decide, OAG then decides, I want users or users can authenticate at Okta, or the users have to do a local authentication. The admins will have control, of course, to say, how often do we do the health checks to decide if Okta is reachable or when do we fail back? We don't want them flip-flopping between like when the connection is intermitted.

 

So these controls are available. And additionally, OAG syncs data, like user data from Okta down. So you have user information and also the authenticator information only where public keys are involved.

 

So you would have, the user would use the same smart card or the same Okta FastPass that they're used to using on Okta will work even when they're doing a local authentication.

 

[Tom Tittermary]

Got it. And how many days are, people always ask like, hey, how many days, how long will you be down, like that sort of a thing. Are there any hard boundaries that folks need to know when they're thinking about the Okta side of the solution?

 

[Bhagya Prabhakar]

We have a max of one year, so after that, it would just not work after that, so yeah.

 

[Tom Tittermary]

Gotcha. So the one-year boundary, the Zscaler side of the house, I always say that, you know, knock wood, take-two Advil number is 90 days, like I can guarantee you no matter what. It's a certificate rotation thing for us on our side.

 

So like with appropriate certificate rotation, we're sitting at 180 days on our side. But yeah, it's funny, the conversation I'll get into is if I'm not talking about Zscaler DDL local and I'm not talking about a, like Okta solution for local identity, the options are literally shared password, open networks. Like let's just, hey, let's trust everything within this little boundary right here for now until we get back into a better state.

 

And I'm just seeing, I'm noticing a lot more, I don't want to say oversight, but a lot more interest in driving more compliance down into those individual compartments specifically.

 

[Tony Ardura]

And going back to what I mentioned earlier, I think that's where the rubber meets the road because you're always going to have that contention between what is easy to use, obviously easy to use would be open doors everywhere, everyone has access to everything, it's all good, right? Everyone can do what they need to do. But security is always going to have that other part in play, but they're always going to have that contention of what's easy to use is not always secure, what's always secure is not always easy to use.

 

So we like to live right in that boundary of making things easy to use but also secure as possible, as much as possible at least.

 

[Tom Tittermary]

The other angle that comes up a lot, and I'm noticing a big, a lot of discussion around policy for this area specifically, and I'm going to have to obfuscate out here a little bit. However, talking about a lot of the tactical use cases where identity and really quick granular access is critical is in that mission partner space, or the desire is in that mission partner space, right? So the use case would be, hey, I am in a forward scenario, I am purposefully disconnected for this reason, we run into three folks that can aid the mission that are part of a 5I.

 

And I want to give them access to the chat function of the TAC server, but I can't allow them on the network because they're a foreign national and it's a dot, dot, dot network. So that's like one of the individual core use cases. What I have seen though is, when people are talking about policy here, I've got to make sure I say this just the right way.

 

The notion is, hey, I can't put a mission partner on that network because that network is this classification. And what I'm seeing now finally is I think all the data talk we've been doing over the last five years is working because people are going, well, wait, the network isn't that classification, that just happens to be where we collocate a bunch of the data that meets that classification. It's got nothing to do with the network.

 

The network's like layer three structure, that. And if I have strong identity, I have strong posture, I have validation, human in the loop, that this user needs access to this piece of data for this mission set, well, now I'm not putting a foreign national on the network, I'm giving them access to critical mission data, right? And I'm validating that they have that individual use case.

 

I'm seeing the talk track shift that way specifically.

 

[Tony Ardura]

Yeah. And I think that kind of goes back to zero trust, moving away from the edge, right? Only at the edge.

 

Obviously, the edge is always going to be important. But you have to think about all the steps in that chain of that specific user and the Five Eye Nation mission partner, as an example, getting access to the data. So that identity throughput is saying, OK, this user is able to access the network, yes, but the user is able to access the application that that data is contained therein.

 

And within that application, they're able to access that specific set of data, whatever it may be. That's an API call, that's a document upload, or whatever it may be as a use case. So I think it's going back to, obviously, we are all zero trust companies as a whole.

 

Zero trust is obviously incredibly important for how users are able to access appropriate systems across the entire DoD as a whole.

 

[Tom Tittermary]

Yeah. Well, I think the additional criticality, right, here's where the chocolate and peanut butter become the Reese's of Okta and Zscaler, making a terrible analogy as I also look at the camera. Where it comes together is, if you think about that individual scenario, like Zscaler is going to do the blocking and tackling to say, hey, it's critical I get the mission partner this data, but it's also important that I obfuscate out everything else in this network so the mission partner doesn't even get to know it exists.

 

Like that's a key core critical function that the Zscaler side of the house is going to handle. On the Okta side of the house, however, that granular identity in that pocket, like you're not just mandating and letting us know, hey, letting them know what they see and not see. There's a secondary piece there where you're going to give granularity of identity to systems to allow, now that I'm in the data set, hey, they're allowed only this folder structure or I'm going to actively obfuscate out text in this document based on an individual identity.

 

There's another layer of depth there that we're not trying to do on the Zscaler side, but it's a critical function in the mission set.

 

[Tony Ardura]

Absolutely. I mean, and that's done not only through us, that can be done in concert with other Zero Trust partners that are protecting either specific API calls to other services or protecting specific application calls within the actual user interface. But yes, typically from just an Okta, like just extracting all that out, just from an Okta perspective, we absolutely can say this person is a 25 Bravo where they have this domain space for mission radar.

 

They should be able to do X, Y, and Z. Well, what if that X, Y, and Z removes them from being able to upload a document or download a document or removes them from being able to fire a weapon system, right? You can control that piece appropriately based on the identity.

 

So it's a cohesive model of, yes, this user is this user. And that's typically, in my opinion, where the DoD has done a lot of their identity of, hey, here's all the attributes for this person. You as an application are going to figure it out.

 

Well, that works if you have one application. If you have 30 apps, 50 apps, 3,000 apps as a whole, being able to uniquely identify what that specific attributes or the attribute-based access control for that user should allow that person to do is incredibly difficult, right? Because how do you, as an enterprise, even down to the tactical edge, right?

 

As an enterprise, from the enterprise down to the tactical, how do you understand, okay, yes, this 25 Bravo at domain space radar should be able to do X, Y, and Z. Well, what if X, Y, and Z isn't pertinent to this other application? Or what if X, Y, and Z is pertinent to that application?

 

So how do you make that determination as a whole? And Okta has those tools in place to allow that authorization to occur appropriately.

 

[Tom Tittermary]

Yeah, it's that right church, wrong pew scenario.

 

[Tony Ardura]

Absolutely, yeah.

 

[Tom Tittermary]

Where it's like we know this user intimately, but they haven't been in this sort of scenario before. Sure. So what kind of individual permission should they have in this context?

 

I go, and I go down the data route as well. Two jobs ago, like all we did was talk about data authorization specifically, and I've been an advocate for, and I'd be happy to be involved if there's anybody listening. I feel like on the data side, like we need a taxonomy for, a universal taxonomy for DOD data.

 

[Tom Gianelos]

Yeah.

 

[Tom Tittermary]

Right? Like kingdom file, class order, family, gene, and species, where you hand me a new piece of data, and I go, no, it goes here. Or I know to add a subcategory at this layer for that.

 

And I think that's part of the confusion too. I think between services, between co-coms, obviously between mission partners, there's going to be different ways that we associate these needs based upon, you know, that user in the situation.

 

[Tom Gianelos]

Yeah.

 

[Tom Tittermary]

What they should have access to. There's not a uniformity to that. So you're going to need in those cases to be able to account for, you know, known user new role to be able to change those individual permissions on the fly.

 

[Tony Ardura]

Yeah.

 

[Tom Tittermary]

Is that something you guys are doing in the tactical set specifically, or?

 

[Tony Ardura]

So I can speak from the enterprise perspective. And yeah, so the enterprise perspective, yes. I don't know if that's being detailed down to the tactical edge at the moment.

 

But for us, that's fine grained authorization. So FGA. So the paradigm I just mentioned of user authenticates into Okta, we federate them, creates a SAML assertion not to get too far in the weeds, or an OIDC token, OAuth token of here's this person.

 

Here's what they should have access to. You had an application or Zscaler. You be an enforcement point and filter what that user should be able to do based on what I tell you about them as an Okta, as I'm Okta in this scenario.

 

But from an FGA turns it on its head, right? That user authenticates, we can still give that application or that enforcement point the right assets or attributes about that person. But what if the application then wants to reach out to another third party to check other details about that person?

 

So yes, this person authenticated, they have this clearance level, they have this MOS. But maybe I need to reach out to some intelligence community partner or 5i partner or whatever it may be to check something authorization on this specific document, right? Or this document has this read in or this document has this program, right?

 

Well, maybe Okta as a whole, we don't want to store that. Potentially we can, but we don't want to store that. So FGA serves as that queryable actor where the application itself can out of band of that authentication experience reach out and query and say, does this user have access to read this specific set of data?

 

And it's more or less related to relation-based access control, REBAC for short, versus attribute-based access control. So Okta can do all those, right? ABAC, RBAC for role-based access control or REBAC, which is relationship-based access control.

 

There's no right answer. There's no wrong answer. It really just depends on what the application supports, what the mission capability requires, as well as what that user should or should not be able to do.

 

They all could be in play at once, right? But that's from the enterprise perspective. Is FGA going, thinking about going OAG offline yet?

 

[Bhagya Prabhakar]

Not yet. No. OAG offline is primarily focused on providing that authentication resiliency and identifying the user with utmost security.

 

So that's the focus of...

 

[Tom Tittermary]

I will say, like, just because... So I've been having this conversation probably weekly for seven months now. Like, this individual, Heywinter, all these...

 

You and all the other cloud companies are going to do DDEL. Like, we've been in the mix in the middle of it, right? Because there's...

 

Again, since it takes a village, it's not enough that I'm there. It's like all my friends have to be there at the same time, right? But I think that, very specifically, I think you guys are about where...

 

You're ahead of a lot of other folks I've talked to in that space individually. And I think that there's going to be a significant amount of a transition as new architectures are getting built, understanding where the products are. There's going to be places, unfortunately for us too, right?

 

From the Zscaler side, where I just can't help you today because I don't have the product that fits the solution space. By the way, guys, we get it. We understand.

 

[Tom Gianelos]

We're learning.

 

[Tom Tittermary]

We want to do the most good as quickly as humanly possible. But the minute we hit an architectural impasse... Here's one of the big ones that you guys tell me if you run into this too.

 

We run into a scenario, and it's somebody in DoD or IC, and they go, no, it's fully air-gapped. And I'm noticing people conflate the terms air-gapped, DDL, disconnected, and intermittent constantly, right? Because somebody said air-gapped.

 

Like, it's got to work like it's air-gapped. Air-gapped, to me, is like it's a cyber range. Or, like, there are hard, fast walls where there are no places RJ-45 touch.

 

Like, in any direction, right? There's that one. And I would include...

 

Careful what I say here. But I would include environments and subnets that are kind of, like, boundaried by cross-domain solutions in that category at the same time, right? Like, if I got to print it to a DVD to get it across, or you put it across XML or something, I would fit in that same category.

 

But the number of times that somebody presents to me in a, quote-unquote, air-gapped environment where I ask three more questions, and it's not quite, is almost infinite. I don't know if you guys have run into the same thing where, well, no, I've got... There's an individual call-out that happens over 443 on this one channel, and, oh, yeah, that's fine.

 

Like, there are scenarios like that where suddenly it's not so... They would have you believe it's a hot air balloon of a network, where it's not. There's, like, some level of connectivity there.

 

Absolutely.

 

[Tony Ardura]

I hear that a lot, right? So they say, oh, it's air-gapped. Well, it's on one of the...

 

I won't name that. I don't know if we can name the networks. But it's one of the networks, right?

 

It's, like, one of the big networks, right? And you're like, oh, okay, well, that's not air-gapped. That's on a major network.

 

So, yeah, I think it's more of a nomenclature thing, obviously, from customers. But everyone wants to... Going back to, like, the most secure.

 

They want to make sure that they are not in the headlines. They want to make sure they're not in the news for something bad going wrong. And I think a lot of things...

 

That air is on the side of denying access everywhere from a lot of the capacities. So the air on the side of this needs to be completely air-gapped, no matter what, right?

 

[Tom Tittermary]

I think we've landed on, like, one of the core issues, though, too, where it's, like, the number of times where I say, hey, here's everything Zscaler could do. And they go, your cloud, right? And I go, yeah.

 

And they go, yeah, we can't. I can't possibly. There's this core...

 

There's this notion of... There's a reason why the entire Fortune 500 and everybody going through these major... Most of the civilian government, most of the FSI space is kind of into this cloud migration, digital data modernization phase, right?

 

Where everybody realized that it's not good to have a local mail server anymore. It's better if I have a workspace environment relative to a cloud, right? Now, in any and all of those, like, I want to make sure I'm meeting all your cases where in every scenario where you need to work, I can help you work.

 

But there's this balance between... I think a lot of times when I hear air gap, people say, because I don't trust the cloud. And there's almost like a shutting of the ears around the scenario in which the cloud can work in that individual small compartment, right?

 

But then at the same time, like the number of zero trust... I've mentioned this gentleman on the show before. He's a friend of mine out in St. Louis now at one of Tommy's customers. But a gentleman named Wes Schooley used to run the zero trust team at Transcom. He's moved on to a different agency. But it was two and a half years ago.

 

And he said to me, he goes, Tom, there's a lot of Leroy Jenkins style zero trust pilots going on out here. And I went, that's the greatest thing I ever heard. Because people would grab tools and run.

 

And if you haven't seen Leroy Jenkins, pause, YouTube, two words. It'll be a great two minutes. And then come back in.

 

But there's this notion of, let me grab all the tools that I can go throw in a virtual environment. And let me test out 10 users. And then, mission accomplished, claim victory, end.

 

But so many times it's, I can't use cloud because. But I'm watching these programs fall down because they don't have that centralized backplane that allows the scaling. And I think that if two companies are known in this space as cloud companies that are anchoring the zero trust conversation, it's us on the enforcement side and you guys on the identity side.

 

It's just interesting to see now try to cross some of this philosophical boundary to get some of that goodness over to DoD at the same time.

 

[Tony Ardura]

Yeah, I think we, going back to our use cases, we are the world identity company. And we aim to facilitate identity authentication, authorization, whatever it may be, governance at the largest scales of customers. I'm not gonna reference specific customers, but very, very large Fortune 100, Fortune 500, Department of Defense customers as a whole.

 

So being able to facilitate that authentication, that authorization is critical, right? Nothing happens if you don't know who the person is and that person can't get access to something. And that also pertains to getting access to the front door, right?

 

Getting access to that specific network at that specific instances where we fit with Zscaler as a whole. So I think being able to scale is very easy, quote unquote, if you are a cloud native, cloud first company, right? Because it's born in your DNA of what you do, right?

 

If it's born and built in the cloud, it has those capabilities in it using cloud services, but also using those engineering paradigms that come from those cloud services. But being able to bring that same mindset to those tactical scenarios where, yeah, okay, you're not going to need to scale to a million users at a forward operating base, right? I mean, potentially not, but it could be tens of thousands of users, 40,000 users, 50,000 users, et cetera, right?

 

So being able to still meet that mission need from a scalability perspective of cloud service, but not be relying on legacy applications. I guess I'll use the term fondly, legacy applications, legacy identity products or legacy network products at the edge that aren't built for that, right? So it's bringing that modernization mindset, as you mentioned, of let's use the technologies and tools that the cloud services have brought to us, but bring that same mindset to the tactical edge and have those same capabilities.

 

[Tom Tittermary]

I think the scaling is one huge piece of it. I think the other one, I don't know if I'm inventing a word here, but like composability. The number of environments I've seen where it used to be that that forward operating base would show up on 16 pallets and guys would build and patch and construct and define.

 

And it's like building a small business in an individual scenario to go forward spot where now I'm seeing that the de facto mechanism is, no, I want descriptive delineative container-based builds for this. So when these systems start up, right? So one, they're largely hyper-converged architecture.

 

So there's not like server network storage. It's like, no, no, the nodes come on, the nodes are on. Most of the code is just composable code where it says, hey, if I have less than six containers, run six containers.

 

They connect together in that way. And then cloud services at the edge have that extra piece of, I don't have to have people populate these things with or patch them based on whatever level they were on out of the depot. They come on, they hit the cloud, and they catch policy out of the cloud.

 

And then it's that whole, like, the way that we'll have the conversation is, I want to fight tonight, not patch tonight scenario. But I think that's the other, the agility of it very specifically is the other basis of that. And we're having the detail conversation, but the ability, if the mission set requires it where I have internet connectivity, but I can't get hardware out there, to have a solution that is just there is the other big component of that.

 

From Oconus, I got to come Oconus for aisle five, but it's always there. There's always those nodes there for you.

 

[Tony Ardura]

Yeah. And I think it also, if you turn that on the other side, just being able to stand it up fast is incredibly important. But being able to equally, as you said, grunt foolproof, right?

 

I think what the actual term was. But you need to be able to, on a dime, flip over to leverage the local environment in that detail scenario. So it needs to be stood up quickly.

 

It needs to be flexible in that nature to be able to scale in that nature, composable in that nature, but it also needs to be ready to go at a moment's notice. And so from our perspective, those applications, as Bhagia mentioned earlier, trusting that local OAG offline in our scenario as that IDP, it's always there ready to go and authenticating users, even while Okta's connected. And that 99.9% of the time when it is connected, it's still authenticating users through that local appliance. On the 0.01% of the time when it's not connected, it just locally authenticates them. So it's very, very helpful in that capacity of just being able to authenticate users on the same paradigm of what they're already doing. They just don't realize it.

 

But from an Okta perspective, we will always be able to focus on flexibility. So going back to your use case of, we need to deploy these things quickly, whatever it may be, right? Okta is very flexible in that nature.

 

So we can, using standards-based solutions from an authentication perspective, a lifecycle management perspective, being able to integrate with any system, whatever it may be, either at the edge, on the enterprise, but if you're standing up this environment in a container or forward operating base quickly, you can obviously deploy those environments and they're just ready to go at a moment's notice. So yeah, it's meeting that need, meeting that DoD customer where they are as a whole.

 

[Tom Tittermary]

Yeah. On our side, we even got down to the, one of my favorite phrases that I get to use in my work life is the, and it comes up in these detailed conversations all the time, is silence, violence, silence, right? So you're at base camp poster station, you have full connectivity, you're kind of downloading the mission set.

 

And then as you are getting ready to move onto an individual mission target, you want to cut all signal that is making its way out into the air, right? So you self-imposed detail in that scenario. I think everybody thinks about it of like, I hear, I'm on Diego Garcia and a typhoon rolls.

 

Well, yeah, sometimes. For the immediate failover, one of the things we have come in short term in the product on the Zscaler side too, and we've got to frame everything in the commercial context, right? So it's a disaster recovery test tool, but it's a toggle switch on our side that basically is just like, no, no, no, no.

 

We're forcing local for a period of time. And when I was having the conversation, I told folks, I said, if there's a physical toggle, that's not too much. If you can give me a physical toggle to be like, oh, it's off, I can look and see that it's off.

 

But all of those different individual components play when it comes down to the edge, for sure. It's a different set out there.

 

[Tony Ardura]

Yeah, same is true for us.

 

[Bhagya Prabhakar]

Right, so OAD can function in that temporary offline where it decides I have to do authentication with Okta or I have to do local authentication, or like what you said, the admin says, you do local authentication now. You're in the detail situation and then it will not go up to Okta in that time.

 

[Tony Ardura]

It's kind of clear. It's interesting to see how, obviously, the demand segment, we're talking to the same people as a whole, right? So the silence, violence, silence is very clear to us.

 

And it's obviously been clear to you guys, but we've been generating the same thing out of band of each other, I guess, which is kind of interesting to see. But bringing the cloud services to the edge, I think we've both approached it in the same capacity, right? Being able to have that, it's a little backwards, right?

 

It's a little backwards of you have other solutions where they were legacy or older solutions that used to be deployed on-prem or in some other cloud environment that was self-hosted, but they were deployed on-prem and now trying to move into that cloud service environment. Well, we're doing the opposite, right? As two companies, we're cloud-first, cloud-native, moving back to be able to support these distinct niche use cases.

 

That's, it's uniform, right? It's not only a DoD, but it's also across the civilian space, as we mentioned a few of those, but being able to meet that need as a whole. And we both kind of grew in that direction, which is kind of interesting.

 

[Tom Tittermary]

So we used to work with an engineer who was on my team, Sam Richman. I always, whenever I'm about to say something that I stole from somebody that's really, really smart, I'll give credit where credit's due, so kudos to Sam Richman. But I watched him give a presentation once, and he was trying to describe like why Zscaler being cloud-native was better.

 

And this goes to the, I think a lot of people have tried to take these individual tactical implementations and then just jam them in a cloud IS and call it a cloud, right? And it just doesn't, it consistently has the same issues that the individual pieces of hardware do, because it's not constructed to be native for an individual SaaS or cloud service, right? And it's tried and tried and tried and tried and tried, and people are like, well, we'll just try it again.

 

But the metaphor he gave me was that a fish is ocean-native, and a scuba diver is ocean-pivot, where you're taking a thing that doesn't belong in the ocean, and you're giving it things that allow it to act in the ocean, right? And just that little difference of, and it's like you can't take all this kit that you shipped out to the FOB and then virtualize it and stick it in an AWS and like get the same, it's just, it's not that way. The dagger is, this is gonna be a funny graphic mentally, but like taking that fish now and making it available to walk on land, because that's what we're all doing with our product management groups every day, to have these cloud operations operate in these tactical scenarios, and these deprived, intermittent-type scenarios.

 

But it's basically, we're doing basically land pivot from our side. But it's interesting to watch. It's fun that we're all kind of evolving in this in the same way, because the moment we finished, we were close to finishing our piece, it was like, great, who are we working with from the identity side?

 

And a lot of interesting conversations happened, because people were at different stages of development. But it's fun to watch all this development happening on that side too.

 

[Tony Ardura]

And I think you just hit a string for me, I guess, a little bit, where you have the DoD also trying to centralize identity as a whole, right? The individual departments, the Army, Navy, Air Force, et cetera, they're all trying to centralize their identities, but beyond that, even DISA's trying to centralize their own identity too. So going back to, that all works, right?

 

When you're talking about an enterprise scenario, but the biggest crux of that is, what are we doing at the edge, right? And the, you just, what are we doing for identity at the edge? Well, you just brought up, you didn't reference any specific vendors, but that's gonna be as varied as there are fish in the sea, I guess, to use another analogy here.

 

So how do you unite that from a DoD perspective of we want to make sure there's uniform control pieces, uniform set pieces, I guess is what I'll say, from a zero trust perspective. But it all breaks down when we have, on this base, we have this system, on that base, we have this system. If that's an Air Force base, then we have that system, right?

 

So it's gonna be a whole varied slew of different products, and there's gonna be no uniformity of like, how would we grant this specific five eye user mission partner access to that application system? Well, if that person gets on a helicopter and goes over to this base, what if it's a completely different system that they don't talk to each other, and there's no uniform enterprise control, but to unite those. So you kind of have to think down from the enterprise to the tactical edge, because it all needs to flow appropriately, right?

 

Either from DISA or from all the individual services, but they need to flow that identity across, and not just have silos of information. And a lot of times we see customers where, well, we deployed this solution, and it worked out for this use case. Great.

 

What if you deploy a new application that can't talk to that system? Or what if you have this other system in another base that needs to also be detailed, but they don't talk to each other? So it's kind of that uniform control from the enterprise down, but also being able to flexibly and neutrally connect to anything as a whole.

 

[Tom Tittermary]

I think the main difficulty that DOD's gonna run into is in the past, the way that that's been done, the way that that's universally been done from the top down has been at layer three, right?

 

[Bhagya Prabhakar]

Yeah.

 

[Tom Tittermary]

Because the way that we had to, or the way that the DOD had to manage that was they had DISA, who is a universal network manager relative to ISV, and they would attune and they would adapt relative to that individual component, right? So it's just fascinating. Tom and I did a podcast with two of the guys that wrote the, this is Zero Trust Reference Architecture V2.

 

The guy from, okay, so I'll cut that out because I didn't remember who went to the place. True Zero Trust. True Zero Trust.

 

The guys from TZT from True Zero Trust, Joe Brinker and, and I forgot the other names. I'll cut this part too. But we'll go back to that.

 

Yes. Okay. Let me think of what I just said where I patched that together.

 

Okay. I think what's really interesting is DISA's always had layer three to manage this from. So it's, you can go on this network or you can go on that network.

 

And if I'm going to inspect anything, it's going to be, I'm going to watch the ones and zeros that go along these individual pipes, right? That's not how identity works. Like, I think a lot of these new PDP pieces that we need to make clean enforcement decisions, the dagger is that there's not a way to cleanly pick those up on a standard, you know, ones and zeros style line.

 

And there need to be more centralized repositories around what is universal posture management across a set of tools? What is universal identity that goes from enterprise down to tactical? How do I integrate that relative to mission partners?

 

Like none of these are things where I could, I could put a device that lives on a wire to solve those. They require centralized repositories with flow downs and tactical components. So I think that's going to be a really interesting piece of this too.

 

[Tony Ardura]

And as you mentioned, and that's also looking at things from the edge, right? Or like from the perimeter, from a zero trust perspective. Yeah, you could stick something on the wire and be looking at the ones and zeros, but you should really be looking at that user's access to the device, user's access to the application, user's access also to the network, right?

 

User's access to themselves as the identity. So it's kind of uniting that whole story that we just mentioned earlier. But there was an interesting piece you mentioned there what is the scenario for that mission partner?

 

I'm not even going to bring up any potential use cases of why you do this, but say, hey, we need to rip this person out, right? Something happened and this person had access. Well, we need to rip them out.

 

Well, in the old legacy way of doing things, as I just mentioned a use case earlier, we have this system here, that system there, this system here, they don't talk to each other and none of them do. Well, how do you ensure that that person actually is deactivated? Or how do you ensure that person doesn't have that access anymore?

 

So it's an even bigger problem from a security perspective. It's all hunky-dory when you're like, hey, this person is a valid person. They need to get access to this weapon system to fire a missile, fire this weapon system, et cetera.

 

Well, what happens when you don't want them to do that anymore? If you have an identity portfolio, that's a very scattered, from our perspective, a very scattered identity portfolio, you could potentially go to five, 10, 15 different systems to try and block that user from having access to this specific app or service. And it may or may not work, because it might be something, there's some database you forgot, right?

 

Where that's storing that identity isn't that authorization, so they can just authenticate there and do it. So yeah, having that scalability and flexibility to push that identity down is important to grant access, but it's equally, if not more important from a security perspective to remove that access as a whole.

 

[Tom Tittermary]

I think me and Tom were sitting in a conference room with a systems integrator somewhere, I'll just say somewhere in the Midwest. Sure, yeah. And we came to the realization at that time, we've had it forever now, but at that time, we didn't have a big red button style effect for Zscaler and ZPA, where it was like, this person, it's not one of us anymore.

 

How do I hit this one button and everything that Zscaler touches across the board very specifically disappears for that individual identity? And then we went and got it built, which was fun.

 

[Tony Ardura]

And it's not, I guess I would say, from an identity perspective, it's not hard to do. But I think the really cool part from a zero trust perspective, taking my Okta hat off and just taking it like, hey, I'm a taxpayer, I want to see my nation succeed. But being able to protect those things is important because yes, you can protect the network, incredibly important, but you really should be protecting it everywhere, at the endpoint, at the network, at the application level, that's the whole reason about zero trust, because you don't know what other backdoors exist, especially when you get down to the tactical edge, because frankly, it's been the wild, wild west.

 

Because if we loop this all back around to my original comment is, that is the tip of the spear for the Department of Defense. And it is all gone out the window to protect the warfighter and ensure that they have access to do what they need to do. And so bringing those tools to allow that centralized control from a security perspective to heighten that security, incredibly important, but also making sure that that warfighter can still do what they need to do.

 

Wow.

 

[Tom Tittermary]

The last bullet I'll say there, right, is like we've all been doing security for a while. And we know it's a doors and windows game, where a house with 50 doors is very accessible, but not very secure. And a house with no doors is totally secure and totally unusable.

 

So I've seen, just in working with DOD in the time that I've worked with them, right, that conversation at the edge gets very door heavy, where, no, you don't understand. We don't understand so many times, like we have to do this, and it needs to be this way out at the edge for, and there's a very low tolerance when it contradicts the mission set of additional security that anybody at the edge would see as redundant, too much, it's gonna impact the mission, et cetera. So part of this conversation, and this isn't like a sales pitch, I think this is actually how we help, is I can add agility to that mission set, right?

 

Like I can increase, I could step up the security, but at the same time, add agility to that same mission set. But it's all the same conversation, it's not, well, I'm gonna do one, and then I'm gonna do the other, it's like, no, implementing the zero trust in this way gives you both out at the edge. Like it reduces the impact you have to have at the edge and increases your resiliency, it improves your security posture, and if you need more agility to be able to pivot the mission set or add additional folks to the context of it, we're giving that at the same time.

 

[Tony Ardura]

Yeah, yeah. But people like their shared accounts. I wanna share my password.

 

It's who moved my cheese.

 

[Tom Tittermary]

At the end of the day, it's like, wait, change? I don't like how, do you know we're about to go? Yeah, we know, we know.

 

I know, but yeah. Well, anyway, so one, I wanna thank you guys both for coming out. I think this has been a really good conversation.

 

Tom, any route you wanna take this conversation? No, it's good. Yeah.

 

But yeah, so how can folks interact and engage with you folks at Okta? Do you guys have any interesting content online you'd like to point people to, contact with you guys on LinkedIn? What's the best way to engage?

 

[Tony Ardura]

Yeah, so we have a lot of content it's Okta supporting the D-Deal environment. So we have several different papers around OAG offline. Also our other product, our other partner product, Tactical Identity Bridge Appliance from TIPA for short.

 

But definitely reach out to us, find your local Okta sales or account executive as a whole to be able to talk with people like me, as well as Bagia to support that mission set. But we are solving these problems today for the Department of Defense. Just welcome to be able to support you guys as necessary and also interact with Zscaler as a whole.

 

[Tom Tittermary]

So yeah. Awesome. So for all of us here, for me and Tom, everybody thank you for sitting through and enjoying very much another episode of Zero Trust given with us.

 

One last thing for those of you out there, we're watching this email inbox very closely for questions to potentially read on the show. But if you have a question you think might be interesting for us to address on the show, zerotrustsgiven at gmail.com. So zerotrustsgiven at gmail.com.

 

If you fire a question in there, we were just talking to our marketing folks. We have stickers coming. We have hilarious Zero Trust given style swag for the show now.

 

So please drop a question in there and that would actually, it would make my day to give somebody a care package based on that. But again, for me, for Tom, for Tony, Bagia, thank you guys so much for doing the show. Thanks for having us.

 

Thank you very much. And we'll catch you next time. Thank you.