Close the door first

Fix the four exposures worth fixing, not the fourteen hundred.

Posture, identity security posture management

Findings ordered by how far each one reaches, with what the top one reaches drawn beside it
01Where it goes wrong

Nobody breaks the door down. They sign in as the admin who never turned on MFA, and that finding has been open since June.

For the security engineer who has to pick.

02What the industry reports

What the industry reports

  • 92%of identities with sensitive permissions never used them in 90 daysSonrai, enterprise cloud tenants
03What changes

What changes

Findings rank by what they reach

A service principal holding Directory.ReadWrite.All outranks a dormant guest, because the blast radius says so. Severity alone puts them side by side.

A finding is a standing condition

The scan opens it and the scan closes it when the misconfiguration is gone. A person can acknowledge it in between, which records who and when.

What the consent cannot reach is reported as unevaluated

A check the current permissions cannot run is marked unevaluated, so the gap is visible instead of showing as a pass.

04What it covers

Everything this covers.

Risk findings led by their state, with one being acknowledged while the scan keeps checking it
01Posture assessment
01

Posture assessment

  • Users, groups, applications, service principals and domains
  • Re-scanned every six hours, and every open finding re-confirmed
  • A check the current consent cannot run is reported unevaluated
Risk findings led by their state, with one being acknowledged while the scan keeps checking it
02

Risk prioritization

  • Findings ranked by what the affected account can reach
  • An impact score weighted by reach as well as severity
  • Paths from a low-risk account into a privileged group, found before anyone uses them
What one compromised account reaches, drawn as rings: its groups and roles, then the applications behind them
03

Remediation

  • Remediation guidance on the rule, with a script where one applies
  • Acknowledging a finding records who did it and when
  • The scan closes what the scan opened, on a stable dedup key
One finding through its three states, who or what moved it each time, and the rule's remediation steps
05What does the work

The parts of the product this uses.

Risk findingsA finding opens when the condition appears and closes when it is gone
Identity graphFollow the path from any person to everything they can reach
Blast radiusSee everything one compromised account can reach
Attack pathsTrace the route from an entry point to anything privileged
06On your own tenant

See it on your own tenant.

Book a demo

Connect your directory and see findings the same day.

The graph behind it