Identity Risk Posture
Identity Risk Posture provides an overview of your current identity posture, including your current score and rating, as well as the number of identities, groups, devices, and applications, or service principals, we're monitoring. In addition, you can view the top risky users, top findings, and credential leak metrics.
Note
Posture checks are performed in Sophos cloud infrastructure against data collected from your identity provider. No posture assessment processing occurs on your on-premises network.
Identity Risk Posture Score and rating
The Identity Risk Posture Score is an organization-level score based on the count and risk level of open findings across your environment. The score is updated daily and will move up or down based on whether findings are remediated, dismissed, or new ones are discovered. In addition, you can see how the score changed from the previous day by using the percent change and arrow.
The Identity Risk Posture Score is separate from the per-identity Risk Score, which reflects the likelihood of an individual identity being compromised. See Identity Risk Score for details.
The following are possible ratings and associated scores:
- Critical: 75-100
- High: 50-74
- Medium: 25-49
- Low: 0-24
Click the Identity Risk Posture score to open the Risk Posture Score details. For more information, see Risk Posture Score.
Your environment statistics
Next to the score and rating, find counts of identities, groups, devices, and applications we're monitoring from your connected identity provider integrations. Click one of these counts to go to the associated section of the Directory page. For more information, see Directory.
Top Risky Users widget
The Top Risky Users widget shows the identities that combine a high Risk Score with open findings, which is the highest-priority group for daily triage. Each entry shows the identity name, open finding counts by severity, and the current score.
Identities show in the widget when they have at least one open finding and are sorted by descending Risk Score. An identity with a high score but no active findings will not show in the widget. Click View All Users at the bottom of the widget to go to the Identities table to see scores across all identities regardless of finding status.
Take the following actions from this widget:
- Click the user name or icon to go to the Identity Details page for that user. For more information, see Identity Details.
- Click View All Users to open the Identities section of the Directory page. For more information, see Directory.
Top Findings widget
The Top Findings widget displays the top ten findings sorted by risk, combining multiple instances of the same finding with an occurrence count. Take the following actions from this widget:
- Click More from a recommendation to expand the row and view the full recommendation. Click Less to collapse the row again.
- Click View Related Findings to go to the Identity Findings page, which is filtered by the check that identified the issue.
- Click View All Findings from the bottom of the widget to go to the Identity Findings page.
Credential Leaks widget
The Credential Leaks widget shows the count of open leak-related findings sorted by risk level, as well as metrics related to leaked credentials found for the domains configured within your environment. Where applicable, it also shows the trend of this activity over the last 30 days.
The statistics in the widget include all known active credential leaks. This could include data for users who are no longer with the organization or old leaked data matching the selected domains. We only generate findings for what we consider active leaks that include an active matching identity, so the following statistics may differ from what you see within the Findings view.
- Leak-Related Findings: The number of open credential leak findings with counts by risk level.
- Sources: The number of active unique leak sources where data for your domains has been observed.
- Plaintext Passwords: The number of active leaks where plaintext passwords were found in the leak data.
- Hashed Passwords: The number of active leaks where hashed passwords were found in the leak data.
- Emails: The number of active unique email accounts that have been observed in the leak data.
- Unique Passwords: The number of active unique passwords that have been observed in the leak data.
- Admin Emails: The number of active accounts identified as an admin that have been observed in the leak data.
Take the following actions from this widget:
- Click Leak-Related Findings to go to the Identity Findings page filtered by dark web intelligence findings. For more information, see Findings.
- Click a metric to view matching leak data on the Dark Web Intelligence page. For more information, see Dark Web Intelligence.




