Identity security
What this is
Identity security is the practice of treating the directory as infrastructure rather than as an application. Active Directory, Entra ID and the cloud identity providers decide who is allowed to do what across every server, share and backup in the estate. Securing them means knowing their configuration continuously, and knowing which paths through that configuration lead to full control.
Why it matters
Ransomware cases converge on one step. The attacker raises privilege inside the directory. After that point every server, every backup and every account is reachable, and the incident stops being a malware problem and becomes a rebuild. The directory is not one more product to secure. It is the floor the rest of the security estate stands on.
This is also why a one-off audit is the wrong instrument. A directory drifts through ordinary administration. A group gains a member on Monday. A delegation is granted for a migration and never withdrawn. A service account is given rights it needed once. Each change is defensible on its own, and the path they add up to is visible to nobody who is not looking for it continuously.
What it solves
- Privilege paths nobody designed and nobody can see from the admin console
- Delegations and exceptions granted for one project and never withdrawn
- Estates where the directory and the cloud identity providers are reviewed by different people at different times
- Service accounts, tokens and automated agent identities, which outnumber staff and get reviewed least
- Audit evidence that the directory's configuration is reviewed, not only its user list
In our portfolio
Not covered yet
Privileged access management and multi-factor authentication belong in this area and we do not carry a product for either. When we do, it will be listed here.
Next to this
Deception sits next to identity in practice. A decoy account is one of the few ways to see an attacker who has already reached the directory and is looking around inside it.