Posture

Close the door first

Fix the four exposures worth fixing, not the fourteen hundred.

Findings ordered by how far each one reaches

What the industry reports

  • 92%of identities with sensitive permissions never used them in 90 daysSonrai, enterprise cloud tenants
The moment

Nobody breaks the door down. They sign in as the admin who never turned on MFA, and that finding has been open since June.

For the security engineer who has to pick.

Findings rank by what they reach

A service principal holding Directory.ReadWrite.All outranks a dormant guest, because the blast radius says so. Severity alone puts them side by side.

A finding is a standing condition

The scan opens it and the scan closes it when the misconfiguration is gone. A person can acknowledge it in between, which records who and when.

What the consent cannot reach is reported as unevaluated

A check the current permissions cannot run is marked unevaluated, so the gap is visible instead of showing as a pass.

What you get

Everything this covers.

  1. Posture assessment

    • Users, groups, applications, service principals and domains
    • Re-scanned every six hours, and every open finding re-confirmed
    • A check the current consent cannot run is reported unevaluated
    Risk findings with what each one affects, its severity and its state
  2. Risk prioritization

    • Findings ranked by what the affected account can reach
    • An impact score weighted by reach as well as severity
    • Paths from a low-risk account into a privileged group, found before anyone uses them
    What one compromised account reaches, through every group and role in between
  3. Remediation

    • Remediation guidance on the rule, with a script where one applies
    • Acknowledging a finding records who did it and when
    • The scan closes what the scan opened, on a stable dedup key
    One finding in each of its three states, and what moved it there

See it on your own tenant.

Connect your directory and see findings the same day.