# From IPs to people Page: https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/from-ips-to-people Text version: https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/from-ips-to-people.md Podcast: [Threat Talks - Your Gateway to Cybersecurity Insights](https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159) Published: 2026-01-27T08:17:18+00:00 Episode link: https://share.transistor.fm/s/a50a793d Audio file: https://2.gum.fm/op3.dev/e/pdcn.co/e/pscrb.fm/rss/p/pdst.fm/e/dts.podtrac.com/redirect.mp3/media.transistor.fm/a50a793d/7841bf85.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/threat-talks-your-gateway-to-cybersecurity-insights-6755159/episodes/from-ips-to-people Duration seconds: 1092 ## Resource Detection fails without identity. When activity isn’t tied to a person, anomalies stop telling a story - they’re just signals without context. And when your logs only show IP addresses, your security team is left responding to shadows, not real risk. In this Threat Talks Deep Dive, Rob Maas (Field CTO, ON2IT) and Nicholai Piagentini (Technical Enablement Engineer, ON2IT) show how identity-based firewalling fixes that-by enforcing policy based on who the user is, not where they connect from.The result: stronger network access control, cleaner zero trust firewall enforcement, and better enterprise security decisions. (00:56) - Intro - Detection fails without identity (01:02:07) - Identity signals - users, devices, tags (02:15:43) - Why identity-based firewalls win - zero trust & threat detection (04:48:01) - Why teams skip it -“as-is” migrations & fear of complexity (07:08:13) - Terminal servers - a network access control blind spot (08:17:11) - NAT & service accounts - who is the real identity? (10:15:12) - When user ID feels impossible - the wireless workaround (11:12:12) - How to start safely - turn it on, validate, tighten policy (14:16:30) - Not optional anymore - zero trust firewall due diligence (15:30:01) - Best advice - start imperfect, identity data wins (17:09:58) - Wrap - stop guessing, know who’s acting Key Topics Covered • Why anomaly detection breaks without identity correlation in firewall logs • How identity-based policy improves network access control and reduces lateral movement • Common failure points: terminal servers, NAT, service accounts, AD timeouts • A low-risk rollout: enable for visibility first, then enforce zero trust rules Related ON2IT content & explicitly referenced resources https://threat-talks.com/ https://on2it.net/ ht… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/threat-talks-your-gateway-to-cybersecurity-insights-6755159/episodes/from-ips-to-people/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/from-ips-to-people.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.