Know your identity risk. See your Azure resource risk too.
ID Posture scores your Microsoft Entra ID identity posture, 4 pillars, weighted, 0 to 100. It also checks how your Azure databases, networks, Key Vaults, and storage accounts are configured, alongside identity, not instead of it. The identity score stays a pure identity signal either way.
Admin consent
Your Entra ID admin grants read-only Graph permissions in a few clicks. No agents, no infrastructure to deploy.
Nightly scan
We check identity hygiene, Conditional Access, and privileged roles automatically every night.
Weighted posture score
45 findings across 4 pillars roll up into one 0-100 score you can track and report on.
Guided remediation
Every finding ships with plain-language impact and numbered steps your team can action today.
Every scan evaluates your tenant across the identity controls attackers exploit most.
Your organisation's own accounts
Stale accounts, missing MFA, standing privileged roles without PIM, and incomplete Conditional Access coverage.
Apps, service principals, and managed identities
Expiring or already-expired application secrets, over-privileged Graph permissions, apps with no owner, and inactive registrations.
External accounts with tenant access
Stale guest accounts, guests excluded from Conditional Access, guest RBAC assignments, and guests with no access expiry.
Azure subscription-level access
Subscription-level Owner assignments, Contributor sprawl, and User Access Administrator grants at subscription scope.
Your Azure resource configuration too
Tenant-wide settings that affect everyone
Security Defaults, guest invite policy, risky app consent, and more.
Azure SQL Server authentication
Whether Azure SQL Server requires Entra ID authentication instead of SQL logins.
Cosmos DB authentication
Whether Cosmos DB accounts allow key-based access instead of Entra ID.
Redis authentication
Authentication on Azure Cache for Redis and Azure Managed Redis.
Virtual network subnet security
Network security groups, DDoS Protection Standard, and NSG rule hygiene (unrestricted inbound access, wildcard rules, unused NSGs) on your virtual network subnets and public IP addresses.
Key Vault configuration
Soft-delete, purge protection, permission model, and network access on your Key Vaults.
Storage account configuration
Shared key access, public blob access, network access, and transport security on your storage accounts.
AKS cluster configuration
Entra ID integration, Azure RBAC, local account exposure, API server access, and network policy on your AKS clusters.
Virtual machine configuration
Entra ID sign-in, local password authentication, Trusted Launch, encryption at host, and public IP exposure on your virtual machines.
Already using Microsoft's built-in tools? See how ID Posture compares to Identity Secure Score, Purview Compliance Manager, and the Azure portal.
Also worried about AI agent sprawl? See how ID Posture governs AI agent identities as part of Non-Human Identity.
Connect through Microsoft admin consent in a few minutes, no credit card required.