Skip to main content
Versa Networks

Configure Unified Risk Scores

Versa-logo-release-icon.pngFor supported software information, click here.

The integration of Versa Unified Endpoint risk scoring with third-party Endpoint Detection and Response (EDR) vendors creates a dynamic security framework where endpoint security posture directly influences network access policies. This enables the Versa SASE platform to make real-time, risk-based access decisions that automatically adjust network permissions based on endpoint threat intelligence and security compliance status.

This integration enhances security in the following ways:

  • Detects malicious activity through the EDR vendor at the endpoint and enforces Versa SASE security policies.
  • Enforces in-transit network security policies using the EDR vendor's overall assessment for end-to-end security enforcement.
  • Performs security actions through Versa SASE, such as:
    • Allow, block, or redirect to a captive portal.
    • Run a network IPS scan.
    • Trigger a network sandbox or isolate to a remote browser session.
    • Check for sensitive data leakage.
  • Builds better correlations with network logs from the the EDR vendor. 

The Versa Unified Entity Risk Profile uses the EDR vendor's composite risk score or key attributes as input in security policy enforcement for internet applications, secure access policies, and private applications. Versa Networks derives a unified entity risk score from the following: 

Versa SASE queries the EDR vendor at regular intervals based on the security posture assessment interval, which you can modify. For more information, see Configure Endpoint Detection and Response.

Architecture Overview

The architecture diagram below shows the components involved in the integration of EDR vendors with Versa SASE.

 crowdstrike-integration-workflow.png

Versa SASE includes the following components for the EDR vendor integration:

  • Management plane—Uses Versa Concerto to configure security policies based on risk scores. 
  • Control plane—The building block that controls how users connect to Versa SASE and performs EDR vendor integration. This includes the Versa Controller that communicates with Versa Messaging Service (VMS) to share logs with Versa Analytics.
  • Data plane—The layer that enforces security policies in the network. Versa Advanced Security Cloud (ASC) in the data plane receives scores from third-parties, and continuously evaluates the endpoint posture. 
  • Users connect to Versa SASE using the Versa SASE client installed on user devices, branch edge devices running Versa Operating SystemTM (VOSTM), such as Versa CSG devices, or cloud edge deployment such as AWS running VOS. 
  • Versa Analytics integrates with Next-Gen SIEM to stream and receive logs.

Configure a Unified Entity Risk Profile

The unified entity risk profile in Concerto allows you to weigh the importance of different categories of device risk. You do this by assigning a weighting value, given as a percentage, for each category. If you have multiple products in a category, you can also specify the weight given to each product within the category. Concerto sends the unified entity risk profile configuration to the ASC, which assigns weights to scores received from various sources such as EDRs, vulnerability and threat management (VTMs), and UEMs. The ASC then calculates the unified entity risk score and distributes it to SASE gateways through VMS.

You can create only one profile per tenant. Once you configure a profile, you cannot add another profile or clone the existing profile. Once configured, you can use the entity risk scores when you configure policies  and rules. You can see the results of these calculations on the View tab.

To configure a unified entity risk profile:

  1. In Tenant view, select Configure > Security Service Edge > Profiles and Connectors > Unified Entity Risk Profile.

    unified-risk-scores-left-nav-border.png

    If you have not yet configured a unified entity risk profile, the following screen displays.

    Unified-Entity-Risk-Profile-landing-v2-border.png
     
  2. Click the Add Unified Entity Risk Profile button. Go to Step 3.

    If you have previously configured a unified entity risk profile, the following screen displays when you select Configure > Security Service Edge > Profiles and Connectors > Unified Entity Risk Profile in the left menu bar:

    unified-entity-risk-profile-configured-profile-v2-border.png

    Click the add-icon-black-on-white-22.png Add icon.
     
  3. The Add Unified Entity Risk Profile screen displays.

    Note: You can configure EDR attributes and VTM attributes, or both, and assign an overall attribute weight to each of them. If you configure both EDR and VTM, their combined attribute weight should equal 100%.

    add-unified-entity-risk-profile-home-page-border.png
     
  4. Enter information for the following fields.
     
    Field Description
    Configure Endpoint with EPP/EDR Click the slider bar to enable you to configure an endpoint with Endpoint Protection Platform (EPP)/EDR. The default is disabled.
    Attribute Weight Enter the total attribute weight as a percentage for all EDR products. The total of all configured attribute weights for the EDR products must be 100%.
    Do you want to integrate with your EDR partner? To integrate with EDR partners, click add-icon-blue-on-white-thin.png Configure EDR. The Configure EDR screen displays with CrowdStrike selected by default. To configure EDR, see Configure Endpoint Detection and Response.
    EDR   
    • CrowdStrike
    To include CrowdStrike in the unified entity risk score, enter the attribute weight as a percentage.
    • Microsoft Defender
    To include Microsoft Defender in the unified entity risk score, enter the attribute weight as a percentage.
    • SentinelOne
    To include SentinelOne in the unified entity risk score, enter the attribute weight as a percentage.
  5. Go to Step 3, Review & Submit.


add-UERP-Review-full-border.png

  1. Enter a name for the unified entity risk profile in the Name field. 
  2. Click the pencil-icon-blue-on-white-22.png Edit icon make changes to any section of the configuration.
  3. Click Submit.

Configure Entity Risk Bands for Security Policies and Rules

You can configure the entity risk score to attribute a specific weight to an application's risk score. You can then use this score as an input for Versa unified endpoint risk profiles to enforce network policy rules. This score helps determine the credibility and the likelihood of activities being legitimate or malicious. You can use this risk score while creating security policies and rules for internet applications, secure access policies, and private applications. Versa’s score ranges from 0 to 100, with 100 indicating the highest risk level, and these ranges are used to define entity risk bands.

To configure an entity risk score:

  1. Go to Configure > Security Service Edge > Real-Time Protection > Internet Protection.

    internet-protection-menu.png
     
  2. In the Internet Protection Rules List screen, click + Add to create a rule. The Create Internet Protection Rule screen displays.

    internet-protection-rule-add.png
     
  3. Select step 3, Endpoint Posture, and then click Customize in the Entity Risk Bands section.

    internet-protection-endpoint-posture-customize-1.png
     
  4. In the Entity Risk Bands field, select one or more entity risk scores from the list. The options are:
    • High Risk (81–100)
    • Suspicious (61–80)
    • Moderate Risk (41–60)
    • Low Risk (21–40)
    • Trustworthy (0–20)

      internet-protection-endpoint-posture-risk-bands-v2-cropped-border.png
       
  5. Select step 7, Review and Deploy, and click Save to deploy the new internet protection rule.

Enforce Protection Based on Unified Risk Score

You can configure secure client-based access rules and internet protection rules that use the risk scores of users or devices to control traffic. This allows you to deny or authenticate traffic from users who have high risk scores and allow trustworthy or low-risk traffic.

This section describes the following configuration examples to:

  • Configure client-based access policy rules to deny or allow user traffic based on entity risk score band. In this example, we configure a rule to deny and a rule to allow traffic. For example, you can configure a rule that routes connections from employees (such as contractors) with a high or suspicious unified risk score, when using specific devices (for example, Windows OS), to the SASE gateway for additional authentication and inspection. Also, you can configure rules to allow traffic from users who have risk scores that are trustworthy or low-risk. You apply these to endpoint devices, such as laptops and mobile phones that run the Versa SASE client, and apply these traffic actions to traffic originating from these devices.
  • Configure an internet protection rule to control user traffic based on entity risk score band. In this example, we configure a rule for users connected to the SASE gateway to do the following:
    • Ask before connecting to website for games, gambling, and sports.
    • Block all social media network access.
    • Justify access to financial services sites.
  • Configure a private application protection rule to reject non-web applications such as RDP, VNC, and SSH from high-risk and suspicious users.    

Note that traffic from an entity placed under protection rules due to a high-risk score is not subject to scrutiny once the score improves to a satisfactory range.

Configure Secure Client Access Rules Based on Risk Score

This section describes how to configure two rules, one to deny and one to allow, for traffic based on risk score. For a SASE connection, if the user risk score is not in the allowed range, that user is denied permission to connect to the gateway. 

To configure a secure client-based access rule to deny traffic based on risk score:

  1. Go to Configure > Secure Services Edge > Secure Access  > Client-based Access > Policy Rules.

    client-based-access-rules-main.png
     
  2. Click the add-icon-blue-on-white.png Add icon to configure the policy rule or select an existing rule. The Create/Edit Client-based Access Rule screen displays.
  3. Select step 1, Operating System. The following screen displays.

    edit-client-based-access-rule-os-tab.png
     
  4. Select the operating system (here, Windows).
  5. Select step 3, Endpoint Posture. The following screen displays. This example uses a predefined Endpoint Information Profile and device/endpoint risk score as match criteria.

    edit-client-based-access-rule-endpoint-posture-tab.png
     
  6. Under Entity Risk Bands, click Customize. The following screen displays.

    internet-protection-endpoint-posture-risk-bands-v2-cropped-border.png
     
  7. Select the risk bands as match criteria for the rule. Here, we select the risk banks above 40 [High Risk (81–100), Suspicious (61–80), and Moderate Risk (41–60)]. 
  8. Select step 5, Traffic Action. The following screen displays. 

    edit-client-based-access-rule-traffic-action-tab.png
     
  9. Select Deny to drop all traffic that matches the rule. Note that if you select the Deny option, the workflow steps for Gateways, Client Configuration, and Agent Profile from EIP are removed. The next workflow step becomes Review & Configure.
  10. Enter the message to display when the connection is blocked.
  11. For information about configuring other parameters, see Configure SASE Secure Client-Based Access Rules.
  12. Select step 6, Review and Configure.
  13. When adding a rule, enter a name for the rule. 
  14. If required, click the edit-pencil-icon-blue.png Edit icon for any section to edit the configuration.
  15. Click Save to save the secure client-based access rule.
  16. When the rule in this example (r07-win-eip-crowdstrike-above40-reject) is applied to a user in an entity risk bank above 40, the user is denied access to the SASE gateway when attempting to connect using the Versa SASE client. 

To configure a secure client-based access rule to allow traffic based on risk score:

This rule allows traffic from users or devices that have risk score below 41.

  1. Go to Configure > Secure Services Edge > Secure Access  > Client-based Access > Policy Rules.
  2. Click the add-icon-blue-on-white.png Add icon to configure the policy rule or select an existing rule. The Create/Edit Client-based Access Rule screen displays.
  3. Select Step 1, Operating System. The following screen displays.

    allow-client-based-access-rule-os-tab.png
     
  4. Select the operating system (here, Windows).
  5. Select Step 3, Endpoint Posture. The following screen displays. 

    allow-client-based-access-rule-endpoint-posture-tab.png
     
  6. Under Entity Risk Bands, click Customize. The following screen displays.

    allow-entity-risk-bands-v2-border.png
     
  7. Select the risk bands as match criteria for the rule. Here, we select the risk bands above Trustworthy (0–20) and Low Risk (21–40). 
  8. Select Step 5, Traffic Action. The following screen displays.

    allow-client-based-access-rule-traffic-action-tab-1.png
     
  9. Select Allow to allow all the traffic that matches the rule criteria. 
  10. For information about configuring other tabs and parameters, see Configure SASE Secure Client-Based Access Rules.
  11. Select Step 9, Review and Submit.  
  12. When adding a rule, enter a name for the rule.
  13. If required, edit the configuration for a given section by clicking the edit-pencil-icon-blue.png Edit icon.
  14. Click Save to save the secure client-based access rule.

Configure Internet Protection Rules Based on Risk Score

Similar to secure access client access rules, you can configure internet protection rules to allow, deny, or authenticate traffic based on user or device risk scores. 

In this section, we configure a sample internet protection rule for users who meet the criteria when connected to the SASE gateway: prompt before allowing access to gaming, gambling, and sports websites, block all social media access, and provide justification to access financial services sites. 

To configure internet protection rule match criteria:

  1. Go to Configure > Real-Time Protection > Internet Protection.
  2. In the Internet Protection Rules List screen, click + Add to create a rule or select an existing rule. The Create/Edit Internet Protection Rule screen displays.
  3. Select Step 3, Endpoint Posture. The following screen displays.

    edit-internet-protection-rule-endpoint-posture-tab.png
     
  4. Under Entity Risk Bands, click Customize and select the required risk band. Here, we select Moderate (41-60), Suspicious (61-80), and High Risk (81-100).
  5. Select Step 5, Network Layer 3-4. The following screen displays.

    edit-internet-protection-rule-network-layer-tab.png
     
  6. Here, under Source and Destination (Layer 3), we select Internet, SD-WAN Zone, and Versa Client under Destination Zone.
  7. Select Step 6, Security Enforcement. The following screen displays.

    edit-internet-protection-rule-security-enforcement-tab.png
     
  8. Click Security Profiles and select the required profile. Here, we select a user-defined URL Filtering profile, which has a default action Allow, and for has these actions for the following URL categories:
  9. For information about configuring other tabs and parameters, see Configure SASE Internet Protection Rules.
  10. Select Review and Deploy.
  11. When adding a rule, enter a name for the rule.
  12. To modify the information in a section, click the pencil-icon-blue-on-white-22.png Edit icon, then make changes to the configuration.
  13. Click Save.

After you deploy this rule, when a user who matches the rule criteria is connected to the SASE gateway via SASE client and tries to:

  • Access a games, gambling, or sports website, the following captive portal screen asking for confirmation displays:

    internet-protection-rule-games-ask-portal-example.png
     
  • Access a social media site or application, the following captive portal screen blocking the social network displays:

    internet-protection-rule-social-media-block-portal-example.png
     
  • Access a financial service, the following captive portal screen asking for justification displays:

    internet-protection-rule-fin-services-justify-portal-example.png

Configure Private Application Protection Rules Based Risk Score

This section describes how to configure a private application protection rule to deny access to non-web applications (here, RDC, RealVNC, and SSH) to users whose entity risk bands fall under high risk or suspicious. For more information, see Configure SASE Private Application Protection Rules.

To configure a private application rule based on risk score:

  1. Go to Configure > Real-Time Protection > Private Application Protection. The Private Application Protection Rules List screen displays.
  2. Click + Add to create a rule or select an existing rule. The Create Private Application Protection Rule screen displays, with the Application Group tab selected by default.

    add-private-app-protection-rule-applications-tab-v2-full-border.png
     
  3.  Click the Applications tab in the submenu and select the applications to which to deny (for this rule) access to users. Here, we select RDP, RealVNC, and SSH.
  4. Select Step 3, Endpoint Posture. The following screen displays.

    add-private-app-protection-rule-endpoint-posture-tab-v2-border.png
     
  5. Under Entity Risk Bands, click Customize. The following screen displays.

    internet-protection-endpoint-posture-risk-bands-v3-border.png
     
  6. Select the risk bands as match criteria for the rule. Here we select Moderate Risk (41-60), Suspicious (61-80), and High Risk (81-100).
  7. Select Step 6, Security Enforcement. The following screen displays.

    add-private-app-protection-rule-security-enforcement-tab.png
     
  8. Select Reject to deny access to users to the selected non-web private applications to users who match the entity risk band criteria. 
  9. For information about configuring other tabs and parameters, see Configure SASE Private Application Protection Rules.
  10. Select Review and Deploy.
  11. When adding a rule, enter a name for the rule.
  12. To modify the information in a section, click the pencil-icon-blue-on-white-22.png Edit icon, then make changes to the configuration.
  13. Click Save. 

Licensing and Deployment

You need to acquire a Versa Secure Private and Internet Access (VSPIA) or a Versa Secure Access Fabric (VSAF) Professional license to use risk scoring.

You can include one or more of each of the following types of categories to form the composite score:

  • Endpoint Detection and Response (EDR)
  • User Entity Behavior Analytics (UEBA)
  • User Entity Manager (UEM)
  • Vulnerability Threat Manager (VTM)

Note: An additional UEBA license is required to use the UEBA category.

You must also have your own license for each third-party vendor, for example:

  • EDR—CrowdStrike, SentinelOne, Defender
  • UEM—Intune, Ivanti Mobileiron

 To deploy risk scoring, you must have the following:

  • Advanced Security Cloud (ASC) with Versa Messaging Service (VMS)
  • Versa Hosted ASC+VMS preferred and suggested for hosted SASE gateways and private SASE gateways

Use Cases

The following use cases show examples of Versa's integration with unified risk score providers (any supported EDR/UEM/Versa UEBA).

Use Case 1: Internet Protection: Additional Security Inspection for Risky Users/Devices

When the Unified Risk Score falls to high or suspicious, enforce Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) for additional protection, as follows.

Anusha-1-border.png

​​​​​​For more information, see Configure SASE Internet Protection Rules.

Use Case 2: Enhance Secure Access Policies

This use case involves a high-risk contractor user using  Windows OS. When this user’s Unified Risk Score falls to high or suspicious, send the user traffic to the SASE gateway for additional inspection.

use-case-3-border.png

For more information, see Configure SASE Secure Client-Based Access Rules.

Use Case 3: Contain Malicious User in a Private Network

This use case isolates infected or risky users accessing private/DC applications, for example:

  • Developers accessing WebSSH or their on-prem source code repository in gitlab – Isolate
  • Reject non-web applications like RDP, VNC, SSH from infected users

use-case-3-border.png

For more information, Configure SASE Private Application Protection Rules.

Use Case 4: Actions Based on the EDR Agent Check

Detect that the CrowdStrike agent is installed and is enabled in the endpoint. If the agent is not installed, reject the user.

  • New EIP objects to check for the presence of CrowdStrike Falcon
  • Eip-object-endpoint-security-installed-any—Check for any EDR
  • Eip-object-endpoint-security-CrowdStrike—Check specifically for CrowdStrike EDR, whether it is installed and running

For more information, see Integrate Versa SASE with CrowdStrike Falcon.

View Risk Score-Based Logs and Statistics

You can view entity risk scores, EIP user profile logs, and rule logs from the View tab in Concerto to monitor and analyze entity risk score-based traffic updates.

To view entity risk score:

  1. To view information about security risk scores, select View > Dashboard > Security >  Entity Risk Score. For more information, see View Risk Score Information
    For example:

    view-entity-risk-score.png

    To monitor entity risk score, go to Monitor > Appliance > Services > NGFW > Entity Risk Score. For more information, see Monitor Concerto Orchestrator.
    For example:

    monitor-entity-risk-score.png
     

To view EIP log profiles for the secure access client-based rules you configure for CrowdStrike:

  1. Go to View > Dashboard > Secure Access > Logs > Endpoint Information Profiles Log > Logs. For more information, see View Concerto Security Dashboards.
    For example, the following image displays the EIP user profile logs for the profile eip-profile-endpoint_security_crowdstrike:

    view-eip-profile-logs.png

To view firewall information for internet protection rules based on risk score:

  1. Go to  View > Dashboard > Security > Internet Protection > Firewall Overview. For more information, see View Internet Protection Information.
    For example, the following image shows the rule usage information for a few risk score-based rules (highlighted):

    view-internet-protection-firewall-rules.png

Supported Software Information

Releases 12.2.1 and later support all content described in this article.

  • Was this article helpful?