🛡 Identity Risk Assessments

See and fix identity risk
across every IdP you use.

Connect Microsoft Entra ID, Okta, and hybrid (on-prem AD + cloud) environments. Get a clear risk score, MFA coverage, privileged-access exposure, device posture, and framework-aligned recommendations (NIST · CIS · ISO) — all in one console.

✓ IdP-agnostic✓ Hybrid ready✓ Framework-mapped findings✓ E5 deep coverage
Risk Score● LIVE
94
3Critical
2High
3Medium

Connect your identity provider

Pick an IdP. Pull a snapshot. See the risk. Add another anytime — the console combines them.

Microsoft Entra ID
Cloud · Hybrid ready

Users, MFA registration, risky identities, Conditional Access, privileged roles, service principals & on-prem AD sync.

Checking…
Okta
Cloud

Users & factors (MFA), admin roles, app assignments, and access policies via the Okta API.

Checking…
Hybrid Identity
Entra + on-prem AD

Cloud identities synced from on-premises Active Directory — with sync health and stale-sync detection.

Checking…Connect
Other IdPs
Coming soon

Google Workspace, Ping Identity, Keycloak, Microsoft Entra B2B and more on the roadmap.

Planned

What you get

A security assessment, not just a dashboard.

🎯

Risk Score

One 0–100 posture score computed from every signal, with trend over time.

🔐

MFA Coverage

Who has MFA, who doesn't, who's privileged without MFA — surfaced automatically.

👑

Privileged Access

Global Admins, overprivileged service principals, and role hygiene.

🕵️

Risk Signals

Risky sign-ins, failed sign-ins, risky service principals, and Identity Protection exposure (E5).

🔎

Drill-down Findings

Every finding expands to affected users & maps to NIST CSF 2.0, SP 800-63B, SP 800-207, CIS v8 & ISO 27001 controls.

🏗

Hybrid Ready

Cloud + on-prem AD sync detection with stale-sync alerts.

How it works

Connect → Analyze → Act.

1

Connect

Add an IdP connector (Entra ID, Okta, hybrid). App-only credentials — no per-user sign-in required.

2

Analyze

One click pulls a normalized snapshot and runs the risk engine across all signal categories.

3

Act

Review drill-down findings, filter by severity, export CSV/JSON, and track your score over time.

Connect your tenant in minutes

A read-only app registration. No per-user sign-in. Revocable anytime.

1

Client registers an app

Follow the onboarding guide (portal or a single CLI command) to create the read-only Entra app and grant admin consent.

2

Share 3 values

Send the Tenant ID, Client ID, and Client secret to the Identity Risk Assessments team over a secure channel.

3

Assess & improve

The connector runs assessments — your team gets the risk score, findings, and framework-mapped recommendations.