Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

Zero Trust Entra ID Okta Intune n8n Sentinel Defender

Last commit Repo size

Zero-Trust Onboarding Automation (ZTOA)

A phased reference architecture for automating identity, SaaS, and device provisioning — built on Zero Trust principles — for ExampleCo's global offices.

From day-one: verified identity → least-privilege access → compliant device. Entirely automated from a single IT approval.


Vision

Enable every new hire to start securely on day one with verified identity, least privilege, and compliant devices — no manual provisioning, no standing over-permission, no unmanaged endpoints.


Zero-Trust Principles

flowchart LR
    subgraph ZT["Zero-Trust Principles"]
        direction LR
        P1["🔍 Verify explicitly<br/><i>identity · device · location · risk</i>"]
        P2["🔐 Least privilege<br/><i>JIT · JEA · adaptive policy</i>"]
        P3["🧨 Assume breach<br/><i>segment · monitor · contain</i>"]
    end
Loading
# Principle How ZTOA applies it
1 Verify explicitly Phishing-resistant MFA + risk-based Conditional Access on every sign-in
2 Use least privilege PIM (JIT) admin access, per-app SCIM scoping, compliant-device grants
3 Assume breach Device compliance + EDR, Sentinel/XDR telemetry, automated offboarding

📘 Full blueprint: docs/zero-trust.md


Overall Architecture

flowchart TD
    classDef src fill:#e0f2fe,stroke:#0284c7,color:#0c4a6e
    classDef n8n fill:#fdf2f8,stroke:#db2777,color:#831843
    classDef idp fill:#eef2ff,stroke:#4f46e5,color:#312e81
    classDef saas fill:#f0fdf4,stroke:#16a34a,color:#14532d
    classDef dev fill:#fffbeb,stroke:#d97706,color:#78350f
    classDef skip fill:#f1f5f9,stroke:#94a3b8,color:#475569

    subgraph SRC["🗂️ Source & Approval"]
        HR["👤 HR<br/>Submits Notion form<br/>(all offices)"]:::src
        NDB["📋 Notion DB — new hire page<br/><i>Country · Approval Status = Pending Review</i>"]:::src
        IT["👨‍💻 IT Admin<br/>Reviews & approves"]:::src
        HR --> NDB --> IT
    end

    IT -->|"⚡ Approval = Approved"| N8N

    N8N["⚙️ n8n<br/>Detects via Notion Webhook<br/>claims run · Automation State = Running"]:::n8n

    subgraph IDP["🔐 Identity Provisioning"]
        EID["<b>Entra ID — Primary IdP</b><br/>• Create user<br/>• Assign M365 license<br/>• Add to Intune group (USA/DE/FR)<br/>• Apply Conditional Access"]:::idp
        OKTA["<b>Okta — Secondary IdP</b><br/>• Create/sync user via API"]:::idp
        SCIM["📦 Okta SCIM provisioning<br/>• Google Workspace · KnowBe4 · Box<br/>• RingCentral · Shopify Plus · Zendesk<br/>• Basecamp (Okta-exclusive)<br/>• FrontApp · ProcessMaker"]:::saas
        N8N --> EID
        N8N --> OKTA
        OKTA --> SCIM
    end

    subgraph DEV["💻 Device Enrollment"]
        EMAIL["✉️ n8n sends enrollment guide email"]:::dev
        JOIN["👤 User joins Entra ID<br/>+ automatic Intune enrollment"]:::dev
        DETECT["🔔 n8n detects via Graph Webhook<br/>→ Update Notion"]:::dev
        EMAIL --> JOIN --> DETECT
    end

    EID -->|"USA / Germany / France"| EMAIL
    EID -->|"Korea / China / Japan"| EXIT["⏭️ No device step"]:::skip
Loading

The workflow is fully event-driven: a single Notion approval fans out to identity, SaaS, and device provisioning — then loops back to update the source of truth.


Identity & IdP Structure

flowchart TD
    subgraph IDP["Identity Providers"]
        direction LR
        E["Entra ID<br/><b>Primary</b><br/>M365 · Intune · CA"]
        O["Okta<br/><b>Secondary</b><br/>non-Microsoft SaaS"]
    end
    E -->|"user creation"| ALL["All new hires"]
    O -->|"SCIM provisioning"| SAAS2["SaaS apps"]
Loading
Layer System Role
Primary IdP Microsoft Entra ID User creation, M365 license, Intune device group, Conditional Access
Secondary IdP Okta Non-Microsoft SaaS provisioning only

Six Pillars of Zero Trust

mindmap
  root((Zero-Trust))
    Identity
      MFA / FIDO2
      Conditional Access
      PIM (JIT)
    Endpoints
      Autopilot / ADE
      Intune
      Defender for Endpoint
    Data
      Purview
      DLP
    Apps
      CASB
      SSPM
    Network
      ZTNA
    Analytics
      Sentinel
      XDR
Loading
Pillar Key Controls
🪪 Identity Phishing-resistant MFA, risk-based Conditional Access, PIM
💻 Endpoints Windows Autopilot / Apple ADE, compliance policies, EDR
🗂️ Data Purview sensitivity labels, DLP, encryption
📦 Apps Defender for Cloud Apps (CASB), OAuth governance, SSPM
🌐 Network ZTNA (Global Secure Access), microsegmentation
📊 Analytics Sentinel (SIEM/SOAR), Defender XDR, UEBA

SaaS Provisioning Flow

sequenceDiagram
    autonumber
    participant N8N as n8n
    participant EID as Entra ID
    participant OKTA as Okta
    participant SAAS as SaaS Apps
    N8N->>EID: Create user + assign M365 license
    EID-->>N8N: User object + Intune group
    N8N->>OKTA: Create/sync user (Okta API)
    OKTA->>SAAS: SCIM provisioning
    Note over SAAS: Google Workspace · KnowBe4 · Box<br/>RingCentral · Shopify · Zendesk · Basecamp
    OKTA-->>N8N: Provisioning status
Loading

Device Enrollment Flow

sequenceDiagram
    autonumber
    participant N8N as n8n
    participant USER as New Hire
    participant INTUNE as Intune
    participant NT as Notion
    N8N->>USER: Enrollment guide email
    N8N->>NT: Device Status = Pending Enrollment
    USER->>INTUNE: Entra ID join + enroll
    INTUNE-->>N8N: Graph webhook (enrolled)
    N8N->>NT: Device Status = Enrolled
Loading

🚀 Recommended upgrade: move from user-driven enrollment to Windows Autopilot / Apple ADE for zero-touch, hardware-identified provisioning. See docs/device-enrollment.md.


Implementation Phases

gantt
    title ZTOA Implementation Roadmap
    dateFormat  YYYY-MM-DD
    section Foundation
    Phase 0 Foundation            :p0, 2026-01-05, 14d
    section Identity
    Phase 1 Identity & Approval   :p1, after p0, 21d
    section SaaS
    Phase 2 SaaS Provisioning     :p2, after p1, 21d
    section Device
    Phase 3 Device Enrollment     :p3, after p2, 21d
    section Verify
    Phase 4 Continuous Verify     :p4, after p3, 14d
    section Zero-Trust
    Phase 5 Zero-Trust Hardening  :p5, after p4, 28d
Loading
  • Phase 0: Foundation — Notion DB, n8n, Entra ID/Okta one-time setup
  • Phase 1: Core Identity & Approval Gate — HR form → IT approval → Entra ID user creation
  • Phase 2: SaaS Provisioning Automation — Okta sync + SCIM apps + Adobe UMAPI
  • Phase 3: Device Enrollment & Compliance — enrollment guide emails, Intune enrollment, detection
  • Phase 4: Continuous Verification & Maturity — reminders, monitoring, hardening
  • Phase 5: Zero-Trust Hardening — MFA, compliant-device CA, EDR, Purview DLP, CASB, Sentinel, offboarding

📘 Full roadmap: docs/phases.md


Recommended Services

Pillar Recommended Service Purpose
Identity Entra ID P2, Identity Protection, PIM Risk-based CA, JIT admin
Identity Authenticator + FIDO2, Windows Hello Phishing-resistant / passwordless MFA
Endpoints Windows Autopilot, Apple ADE, Intune Zero-touch device provisioning
Endpoints Defender for Endpoint EDR
Data Purview Information Protection, DLP Classification + exfiltration control
Apps Defender for Cloud Apps, Entra Permissions Mgmt CASB, CIEM
Network Global Secure Access, Entra Private Access ZTNA
Analytics Sentinel, Defender XDR SIEM/SOAR, XDR
Lifecycle Entra ID Lifecycle Workflows, Access Reviews On/offboarding + certification

Documentation

Document Contents
docs/project-charter.md Goals, scope, stakeholders, IdP strategy, success criteria
docs/architecture.md Overall architecture, SaaS automation matrix, n8n roles
docs/device-enrollment.md Laptop enrollment policy, user-driven procedure, guide email, detection
docs/compliance.md Regulatory compliance by country
docs/zero-trust.md Zero-Trust blueprint (6 pillars, lifecycle, maturity, services)
docs/phases.md Phased implementation roadmap

Repository Structure

zero-trust-onboarding/
├── README.md                  # Overview, vision, architecture, infographics
├── note.md                    # Notes index
└── docs/
    ├── project-charter.md
    ├── architecture.md
    ├── device-enrollment.md
    ├── compliance.md
    ├── zero-trust.md
    └── phases.md

Final Summary

Item Details
IdP Structure Entra ID (Primary) + Okta (non-Microsoft SaaS only)
Device Enrollment USA/DE/FR: User-driven enrollment (Entra ID join → auto Intune enrollment)
Device Provisioning (ZT) Windows Autopilot / Apple ADE recommended — zero-touch, hardware-identified
Device Management Excluded Korea / China / Japan
n8n Role Orchestration + alert hub + Adobe UMAPI workaround + device enrollment guide/tracking
Fully Automated Tools Google Workspace, KnowBe4, Box, RingCentral, Shopify Plus, Zendesk, Basecamp
Plan Upgrades Required Slack (Business+), Notion (Enterprise)
Okta SCIM Not Supported Adobe → n8n + UMAPI maintained
Regulatory Compliance Germany Works Council consultation, France CSE consultation required

With this structure, once IT admin approves, the entire process — account creation → SaaS provisioning → laptop enrollment guide → enrollment tracking — is automated.

About

Zero-Trust Onboarding Automation (ZTOA) — reference architecture for automating identity, SaaS, and device provisioning under Zero Trust: verified identity, least-privilege access, and compliant devices from day one.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors