Solution Brief
New Ponemon Report: The Hidden Security Threat of Disconnected Apps | Download Now

How the Cerby and Okta integration brings instant logout and access revocation to the applications your identity provider cannot reach.
Okta Universal Logout can instantly end a user's active sessions and revoke access the moment an account is compromised, but only for the applications Okta can reach. The Cerby and Okta integration extends that same instant logout to disconnected applications: the apps that do not support SSO, SAML, or APIs and normally fall outside Okta Identity Threat Protection. No app changes and no custom API work are required.
When Okta Identity Threat Protection detects risk, the logout action extends through Cerby to the disconnected app, eliminating all active tokens and session data so no lingering access remains. Every action is audited and fed into your SIEM, creating a closed loop that confirms the remediation actually completed. The response is deterministic and policy-triggered through Okta's Post-Auth Actions and Entity Risk Policy, not an autonomous agent making its own decisions.
What the integration does:
One-click access revocation across all devices and supported apps, including apps without SSO or APIs.
Eliminates all active tokens and session data and dismantles the full chain of authorization inheritance, so a compromised session cannot be reused.
Responds to changes in device context automatically, and can trigger logout even on out-of-band signals.
Works natively with Okta Post
Auth Actions and Entity Risk Policy, completing Identity Threat Protection rather than replacing it.
Read the full integration brief "Expanding the Reach of Universal Logout"