: Assess Identity Security
Focus
Focus

Assess Identity Security

Table of Contents

Assess Identity Security

Use the Identity Security component of SSPM to identify misconfigurations in your identity posture.
SaaS Security Posture Management includes an Identity Security component to help you identify misconfigurations in your identity posture. Specifically, the Identity Security component gives you visibility into the following problems:
  • Issues with your multi-factor authentication (MFA) implementation. The Identity Security component of SSPM uses information from your identity provider to give you visibility into these problems, which include MFA enrollment and sign-in issues.
  • Issues with Salesforce or Office 365 accounts. The Identity Security component of SSPM uses information from your Salesforce or Office 365 instance to display risks for human accounts and also for non-human accounts. The risks that the Identity Security component displays will vary depending on the application type (Salesforce or Office 365). The risks include dormant accounts, overprivileged accounts, guest accounts, and accounts that have not had their credentials rotated for a specified period. The Identity Security component also uses information from your identity provider to identify local accounts, which are accounts that were not created through your identity provider.
You can integrate the Identity Security component with either the Microsoft Azure or the Okta identity provider. To integrate the Identity Security component with Okta, complete the onboarding instructions for Okta. To integrate the Identity Security component with Microsoft Azure, complete the onboarding instructions for Microsoft 365. Completing these onboarding steps enables SSPM to scan your Microsoft 365 or Okta instance for misconfigured settings, and also enables scans for the Identity Security issues.
  1. To navigate to the Identity Security dashboard, select Posture SecurityIdentity.
  2. Inspect the information displayed on the dashboard to understand the problems that the Identity Security component detected. Take action as needed to resolve these problems.