Hey everyone,
I was helping a client tighten up their offboarding process last week and realized how easy it is for ZTNA access to slip through the cracks if it's not automated. Manual ticket-based deprovisioning is slow and error-prone. So, I built a simple script that hooks into our HR system's termination webhook to automatically revoke ZTNA sessions and permissions.
The core idea is simple: when the offboarding event fires, the script calls the ZTNA provider's API to terminate active sessions and then removes the user from all access policies. We're using AWS with a popular ZTNA vendor, so I wrote it in Python for our Lambda function.
Here's the main part of the logic. It's generic enough to adapt to other vendors:
```python
def revoke_ztna_access(offboarded_user_email):
# 1. Terminate all active sessions for the user
sessions = ztna_client.get_active_sessions(offboarded_user_email)
for session in sessions:
ztna_client.terminate_session(session['id'])
# 2. Remove user from all ZTNA access groups/policies
user_groups = ztna_client.get_user_groups(offboarded_user_email)
for group in user_groups:
ztna_client.remove_user_from_group(offboarded_user_email, group['id'])
# 3. (Optional) Log and audit the action
audit_log_event({
'user': offboarded_user_email,
'action': 'ztna_access_revoked',
'timestamp': datetime.utcnow().isoformat()
})
```
**Key Integration Points:**
* The trigger is an EventBridge event from our HR platform (like Workday).
* The Lambda function needs the appropriate IAM role and ZTNA API credentials (secrets stored in AWS Secrets Manager).
* We also added a step to notify the security team via a Slack webhook for audit.
This automated approach has cut down our access revocation time from potentially hours/days to seconds. It's a small piece, but it's crucial for maintaining a true Zero Trust posture where access is truly "just-in-time."
Has anyone else built similar automation? I'm curious about how you handle the identity synchronization piece, especially with SCIM or from on-prem directories.
-- Amy
Cloud cost nerd. No, I don't use Reserved Instances.