Menu
Skip to main content
Table of Contents
<All topics
Print

Use cases for reports from Authentication Insights

For audits, internal reporting, or further analysis, you can export or print the data displayed in the journal in various formats (Excel, CSV, PDF). But which data is suitable for which purposes? And how can it be combined with other modules?

Use cases for reports from Authentication Insights

The data collected in Authentication Insights provides valuable insights into the behavior and security of your IT environment. Based on the available parameters, the following reports can be generated:

Compliance and audit reports (proof of adherence to guidelines):

  • Purpose: Proof to auditors (e.g. for ISO 27001, NIS2) that multi-factor authentication (MFA) is enforced for critical systems.
  • Data used: Relying Party ID (service called), user, date and time, and the authentication method.

Security incident and forensic reports (threat hunting):

  • Purpose: Investigation of potentially compromised accounts or systems.
  • Data used: Frequent failed authentication attempts (authentication status), unusual end devices, or suspicious application paths.

Rollout and usage analyses (adoption reports):

  • Purpose: Monitoring the successful implementation of new security keys within the company.
  • Data used: Device, serial number, and user. This allows administrators to immediately see which departments are already actively using the new YubiKeys, NitroKeys, or iShield keys and where further training is needed.

Added value through combination with other Appterix modules

Appterix Authentication Insights provides the "who, when, and how" of logins. By correlating this data with information from other Appterix modules, you gain a significantly more powerful, proactive zero-trust ecosystem.

YubiKey Management & Security Key Management

  • The added value: Lifecycle and inventory correlation.
  • Example report: While Authentication Insights shows that a key with a specific serial number was used for a login, YubiKey Management and Security Key Management provide the lifecycle status. You can generate reports that reveal whether revoked, reported lost or expired The key will continue to be used (unsuccessfully) for login attempts.

Zero Trust Application Access (ZTAA)

  • The added value: Context-based access control after authentication.
  • Example report: Successful FIDO2 authentication does not automatically guarantee secure access. The combined effect shows that while a user successfully logged in (Authentication Insights), access to sensitive applications was blocked by ZTAA because the applications did not meet compliance requirements (unknown hash values, outdated software version, etc.).

Zero Trust Storage Access (Removable Storage Access)

  • The added value: Data Loss Prevention (DLP).
  • Example report: You can track user behavior end-to-end. A report might show that a user logged into a sensitive system at an unusual time (Authentication Insights) and immediately afterward attempted to copy data to an unencrypted USB drive. Such patterns are strong indicators of insider threats.

Awareness Management

  • The added value: Linking human risk and technical countermeasures.
  • Example report: Correlate awareness data with real-world behavior. A report could reveal whether users informed about phishing campaigns through awareness management are involved in anomalous authentication events (authentication insights). This enables targeted, retraining measures for at-risk groups before actual incidents occur.