Microsoft Defender for Identity
Identity protection

Cloud identity assessments in Microsoft Defender for Identity

In brief

The documentation now describes Microsoft Defender for Identity assessments for Okta, CyberArk Identity, and SailPoint Identity Security Cloud, including connection prerequisites and revised remediation guidance.

What Defender admins need to know

Administrators can use the linked setup instructions to connect each supported identity platform before reviewing its assessments.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

SecurityMicrosoft Defender for Identity security assessments for cloud identities

This article describes the various security assessments available in Microsoft Defender for Identity relatedprovides security assessments for cloud identities in Okta, CyberArk Identity, and SailPoint Identity Security Cloud. Use these assessments to cloud identities, specifically Okta. Each assessment highlightsidentify potential security risks and provides recommendations for mitigating these risks.review recommended remediation actions.

Prerequisites

ToBefore you use these security assessments, you must first connect your OktaOkta, CyberArk Identity, or SailPoint Identity Security Cloud instance in the Microsoft Defender portal.

For setup instructions, see see:

Assign multifactor authentication to Okta privileged user accounts

Description:

This report lists anyassessment identifies Okta privileged accounts that don't have anya multifactor authentication (MFA) methodsmethod assigned.

AllEnable MFA for all privileged accounts should have multifactor authentication (MFA) enabled to strengthen security. By ensuring that privileged accounts such as Super Admin or Org Admin roles are secured with MFA, organizations can significantly reduce the risk of unauthorized access from compromised credentials. This strategySecuring accounts with roles such as Super Admin or Org Admin helps prevent attackers from gaining elevated access, safeguardingaccess to sensitive resources and protecting critical administrative functions from abuse.functions.

Implementation:

To address this assessment, take the following actions:

  1. ReviewOn the recommended actionRecommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions for, select the "Assign multifactor authentication for Okta privileged user accounts" security assessment.
  2. Review the list of exposed entities to discover which of youridentify Okta privileged user accounts that don't have anyan MFA method assigned.
  3. Assign and enforce a multifactor authentication (MFA)an MFA method tofor the privileged accounts.

Change password for Okta privileged User accounts

Description:

This recommendation lists anyassessment identifies Okta privileged accounts that use outdatedwith passwords that were last set overmore than 180 days ago.

Impact:

Privileged accounts with oldOld passwords create a significant security risk, as older credentials are more likely to be exposed through data breaches or other attack vectors. Enforcing regular password updates for privileged accounts reducesincrease the likelihoodrisk of unauthorized access and strengthens overall security. Applying stringent password policies tobecause the credentials might have been exposed in a data breach or by another attack method. Regularly updating passwords for privileged accounts with elevated privileges protectshelps protect sensitive resources and lowers the risk of exploitation.resources.

Implementation:

To address this assessment, take the following actions:

  1. ReviewOn the recommended actionRecommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions for, select the "Change password for Okta privileged User accounts" security assessment.
  2. Review the list of exposed entities to discover which of youridentify Okta privileged user accounts have anwith old password.passwords.
  3. Take appropriate action onReset the passwords for those accounts by resetting their password.accounts.

High number of Okta accounts with privileged role assigned

Description:

This article describes the security risks associated with having a high number ofassessment identifies Okta accounts with privileged roles assigned and provides recommendations for mitigating these risks.

Description

This report lists Okta accounts with administrator roles -roles, excluding Super Administrator, where the number ofwhen more than 25 accounts assigned tohave these roles is greater than 25. roles.

User impact:

A high number ofMany users with privileged roles increasesincrease the risk of misuse or unauthorized access to critical systems. By reducingReducing the number of users assigned to roles such as Super Admin or Org Admin, organizations can better limitAdmin limits access to sensitive resources and reducereduces the attack surface. Maintaining a smaller, set of privileged accounts ensures more effective governance and minimizes potential security vulnerabilities.

Implementation:

To address this assessment, take the following actions:

  1. ReviewOn the recommended actionRecommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions for, select the "High number of Okta accounts with privileged role assigned" security assessment.
  2. Review the list of exposed entities to discover which of youridentify Okta accounts havewith privileged roles assigned.roles.
  3. Reduce the number of users assigned to administrator roles (otherroles, other than Super-Admin)Super Administrator, to the minimum necessaryneeded to ensure better control and align withfollow the principle of least privilege best practices.privilege.

Highly privileged Okta API token

Description:

Okta’sOkta API tokens inherit the permissions of the user who creates them. If a user with sensitive permissions generates an API token, it carries those permissions. AnyAn API token created by a Super Admin has the same level of access as the Super Admin account. ThisA stolen highly privileged token can exposegive an attacker access to sensitive data and functionality to unauthorized users. If the token is stolen, it can grant the attacker access equivalent to the original user.features.

Implementation:

To address this assessment, take the following actions:

  1. ReviewOn the recommended actionRecommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions for, select the "Highly privileged Okta API token" security assessment.
  2. Review the list of exposed entities to discover which of youridentify highly privileged Okta API tokens are highly privileged.tokens.
  3. If theDelete API token istokens that are no longer required, delete it to eliminate unnecessary exposure.needed.

Limit the number of Okta Super Admin accounts

Description:

This report listsassessment identifies Okta accounts with the Super Administrator role, where the number ofrole when more than five users assigned tohave this role is greater than 5.role.

User impact:

A high number ofMany users with privileged roles increasesthe Super Administrator role increase the risk of misuse or unauthorized access to critical systems. By reducingReducing the number of users assigned to roles such as Super Admin or Org Admin, organizations can better limitwith this role limits access to sensitive resources and reducereduces the attack surface. Maintaining a smaller, set of privileged accounts ensures more effective governance and minimizes potential security vulnerabilities.

Implementation:

To address this assessment, take the following actions:

  1. ReviewOn the recommended actionRecommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions for, select the "Limit the number of Okta Super Admin accounts" security assessment.
  2. Review the list of exposed entities to discover which of youridentify Okta accounts havewith the Super Admin role assigned.Administrator role.
  3. Limit Super Administrator access to the minimum number of users necessaryneeded to maintain control overmanage the highest level of privileged access.

Remove dormant Okta privileged accounts

Description:

This assessment describes the security risks associated with dormantidentifies Okta privileged accounts and provides recommendations for mitigating these risks.that haven't been used in the last 90 days.

User impact:

Dormant privileged accounts represent a significant security risk, as they can become targets for undetected unauthorized access or misuse without detection.misuse. Deactivating or removing unused privileged accounts ensureshelps ensure that only active, monitored users have access to critical administrative capabilities.access.

Implementation:

To address this assessment, take the following actions:

  1. ReviewOn the recommended actionRecommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions for, select the "Remove dormant Okta privileged accounts" security assessment.
  2. Review the list of exposed entities to identify Okta privileged user accounts notthat haven't been used in the last 90 days. This inactivity indicates
  3. Deactivate or remove accounts that the account might be a dormant account orare no longer needed.
  4. If

Change password for CyberArk Identity privileged user accounts

Description:

This assessment identifies CyberArk Identity privileged accounts with passwords that were last set more than 180 days ago.

Impact:

Old passwords for privileged accounts increase the account isrisk of unauthorized access because the credentials might have been exposed in a data breach or by another attack method. Regularly updating passwords for privileged accounts helps protect sensitive resources.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "Change password for CyberArk Identity privileged user accounts" security assessment.
  2. Review the exposed entities to identify CyberArk Identity privileged user accounts with old passwords.
  3. Reset the passwords for those accounts.

Remove stale CyberArk Identity privileged accounts

Description:

This assessment identifies CyberArk Identity privileged accounts that are inactive or haven't been used for an extended period.

Impact:

Stale privileged accounts retain elevated access without active oversight. Removing or deactivating unused privileged accounts reduces the attack surface and helps maintain least-privilege access.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "Remove stale CyberArk Identity privileged accounts" security assessment.
  2. Review the exposed entities to identify inactive CyberArk Identity privileged accounts.
  3. Remove or deactivate stale privileged accounts that are no longer required, deactivate or remove it to eliminate unnecessary exposure.needed.

Limit the number of CyberArk Identity accounts with system admin role

Description:

This assessment identifies CyberArk Identity accounts with the system admin role.

Impact:

Many system admin accounts increase the risk of unauthorized access and misuse of privileged permissions. Limiting the number of accounts with this role strengthens governance and reduces the attack surface.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "Limit the number of CyberArk Identity accounts with system admin role" security assessment.
  2. Review the exposed entities to identify CyberArk Identity accounts with the system admin role.
  3. Remove unnecessary system admin role assignments and keep the number of accounts to the minimum needed.

High number of CyberArk Identity accounts with a privileged role assigned

Description:

This assessment identifies CyberArk Identity accounts with one or more privileged roles when the number of accounts exceeds the recommended threshold.

Impact:

Too many accounts with privileged roles increase the risk of misuse or unauthorized access to critical systems. Reducing the number of accounts with elevated privileges supports the principle of least privilege and improves security posture.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "High number of CyberArk Identity accounts with a privileged role assigned" security assessment.
  2. Review the exposed entities to identify CyberArk Identity accounts with privileged roles.
  3. Reduce the number of privileged role assignments to the minimum necessary.

Change password for SailPoint Identity Security Cloud privileged user accounts

Description:

This assessment identifies SailPoint Identity Security Cloud privileged accounts with passwords that were last set more than 180 days ago.

Impact:

Old passwords for privileged accounts increase the risk of unauthorized access because the credentials might have been exposed in a data breach or by another attack method. Regularly updating passwords for privileged accounts helps protect sensitive resources.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "Change password for SailPoint Identity Security Cloud privileged user accounts" security assessment.
  2. Review the exposed entities to identify SailPoint Identity Security Cloud privileged user accounts with old passwords.
  3. Reset the passwords for those accounts.

Remove stale SailPoint Identity Security Cloud privileged accounts

Description:

This assessment identifies SailPoint Identity Security Cloud privileged accounts that are inactive or haven't been used for an extended period.

Impact:

Stale privileged accounts retain elevated access without active oversight. Removing or deactivating unused privileged accounts reduces the attack surface and helps maintain least-privilege access.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "Remove stale SailPoint Identity Security Cloud privileged accounts" security assessment.
  2. Review the exposed entities to identify inactive SailPoint Identity Security Cloud privileged accounts.
  3. Remove or deactivate stale privileged accounts that are no longer needed.

Limit the number of SailPoint Identity Security Cloud accounts with system admin role

Description:

This assessment identifies SailPoint Identity Security Cloud accounts with the system admin role.

Impact:

Many system admin accounts increase the risk of unauthorized access and misuse of privileged permissions. Limiting the number of accounts with this role strengthens governance and reduces the attack surface.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "Limit the number of SailPoint Identity Security Cloud accounts with system admin role" security assessment.
  2. Review the exposed entities to identify SailPoint Identity Security Cloud accounts with the system admin role.
  3. Remove unnecessary system admin role assignments and keep the number of accounts to the minimum needed.

High number of SailPoint Identity Security Cloud accounts with a privileged role assigned

Description:

This assessment identifies SailPoint Identity Security Cloud accounts with one or more privileged roles when the number of accounts exceeds the recommended threshold.

Impact:

Too many accounts with privileged roles increase the risk of misuse or unauthorized access to critical systems. Reducing the number of accounts with elevated privileges supports the principle of least privilege and improves security posture.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "High number of SailPoint Identity Security Cloud accounts with a privileged role assigned" security assessment.
  2. Review the exposed entities to identify SailPoint Identity Security Cloud accounts with privileged roles.
  3. Reduce the number of privileged role assignments to the minimum necessary.

Assign multifactor authentication for SailPoint privileged user accounts

Description:

This assessment identifies SailPoint Identity Security Cloud privileged accounts that don't have an MFA method assigned.

Impact:

Enable MFA for all privileged accounts to reduce the risk of unauthorized access from compromised credentials.

Implementation:

To address this assessment, take the following actions:

  1. On the Recommended actions page in Microsoft Secure Score at https://security.microsoft.com/securescore?viewid=actions, select the "Assign multifactor authentication for SailPoint privileged user accounts" security assessment.
  2. Review the exposed entities to identify SailPoint Identity Security Cloud privileged user accounts that don't have an MFA method assigned.
  3. Assign and enforce an MFA method for those privileged accounts.