Skip to content
Avanet

Evaluate the Sophos ITDR Identity Overview and Risk Posture Score

The Identity Overview is the starting point for the daily review of identity security in Sophos ITDR. It shows which identities and devices have been recorded, how the organization-wide Risk Posture Score is changing, and where open Findings, MFA gaps, dormant accounts, or Credential Leaks require attention.

The direct path is My Products > Identity > Identity Overview. A quick review starts with Identity Risk Posture Score and Risk Over Time, followed by Recommendations & Actions, Top Findings, and Top 5 Risky Users. The remaining widgets then provide context on coverage and the types of accounts affected.

It is important to set the right expectations: A high score or an unusual metric prioritizes an investigation, but it is not proof of a successful compromise. Conversely, a low score does not prove that no identity threat exists. The overview summarizes the data and open Findings captured by ITDR; the assessment itself must be based on the details and underlying evidence.

Understand data freshness and the assessment cycle

Posture Checks run in the Sophos cloud using data collected from the identity provider by the Entra ID integration or ITDR sensor. The posture assessment itself does not run on the local network. Entra ID Posture Checks and Dormant Resource Checks run every two hours.

In contrast, the organization-wide Identity Risk Posture Score is updated once a day based on changes from the previous day. Consequently, a change in the identity provider, the next data synchronization, a Posture Check, and the daily score update may reflect different data states. A configuration that has just been corrected will not necessarily change the organization score immediately.

For a traceable handover, record the observation time, visible score, rating, daily change, and affected widgets. This helps distinguish an expected update delay from a genuine new discrepancy.

Read the organization-wide Risk Posture Score

The Identity Risk Posture Score widget rates the organization on a scale from 0 to 100. The score is based on the number and risk level of open Findings. A higher value indicates a higher assessed risk:

RatingScore
Low0–24
Medium25–49
High50–74
Critical75–100

The widget also shows the percentage change from the previous day and a direction arrow. The score can rise or fall as Findings are discovered, resolved, or dismissed. However, the percentage change alone does not explain which Finding caused the movement. To investigate, use the New Tab icon to open the Risk Posture Score page and select the relevant day.

The rating is a prioritization aid, not a seal of approval. Movement matters even within the same rating band: An increase from 26 to 48, for example, remains Medium but indicates a significant deterioration. Conversely, a decrease after dismissing a Finding must not automatically be interpreted as a technical fix. The reason for dismissing the Finding must be traceable.

Risk Over Time in the overview

Risk Over Time shows the average monthly Risk Posture Score for the last six months. Each point represents the average of the daily scores for that month. Hovering over a point displays the monthly average. The widget supplements the trend with:

  • Current: the latest daily Risk Posture Score.
  • Change: the percentage change from the previous period.
  • Peak: the highest score in the displayed period.

This makes the widget useful for assessing the longer-term direction. However, a monthly average can smooth out brief spikes. Always compare Current and Peak with the trend before concluding that a flat curve indicates a stable state.

Risk Posture Score in detail

The New Tab icon in Identity Risk Posture Score or Risk Over Time opens the detail page. By default, it shows the last 14 days. The Date Picker lets you select a predefined or custom date range. There is no fixed limit on the period; the history extends as far back as data is available.

The following steps are useful on the detail page:

  1. Select a period that includes the suspected change. For a recent jump, the default 14-day period is usually more useful than a very long date range.
  2. Hover over a point. The score, rating, and percentage change for that date appear.
  3. Click the point. The table updates to show Findings that were created, reopened, dismissed, or resolved on that day.
  4. Open a Finding in the table and review its status change and operational context.

The daily table is not a complete inventory of all Findings that were open on that date. A Finding that was opened earlier and remains active will not appear if it did not undergo one of the specified status changes on the selected day. Therefore, if a known open Finding is absent from the table, this does not automatically indicate a data error. The transitions on the selected day are relevant when interpreting a score change; the Findings view is authoritative for the complete open inventory.

Export the trend as a PNG

On the Risk Posture Score page, open the three-dot menu and select Download as PNG. This exports the displayed graph as a PNG file. First check the date range and visible trend to ensure that the graphic covers the period under discussion.

The PNG file is useful for status reports or a point-in-time handover, but it replaces neither the Finding details nor the documentation of status changes. The report should include the score, period, and export date. Before sharing the file, also check whether the graphic or the way it is embedded exposes internal security information.

Interpret every widget in the Identity Overview

Identity Breakdown

Identity Breakdown shows three cards for the objects recorded by the identity provider and monitored by ITDR:

  • Humans: active human identities.
  • Non-Human Identities (NHI): active Service Principals, applications, and other machine identities.
  • Devices: registered devices.

Applications are included in Non-Human Identities (NHI) and are not shown as a separate fourth card. Clicking a card opens the corresponding section in Directory. The figures are useful for checking plausibility against the expected scope, but they are not sufficient on their own to prove that the integration is complete. First compare unexpected jumps with onboarding, offboarding, and changes in the identity provider.

Recommendations & Actions

Recommendations & Actions derives specific work priorities from current open Findings. Examples include enabling MFA for privileged accounts, addressing accounts that have been inactive for an extended period, and responding to accounts with compromised credentials. Each recommendation shows an Impact rating and provides a button to the relevant page, such as Directory or Findings, with the appropriate filters already applied.

A recommendation is a starting point, not authorization to make an automatic change. Before removing a role, deactivating an account, or taking password-related action, verify the owner, business purpose, and available recovery options. High Impact helps determine the order of work, but it does not replace change and incident processes.

Aggregate of Open Findings

Aggregate of Open Findings summarizes open Findings from the last seven days. Group by lets you organize the chart from three perspectives:

  • Severity: risk level.
  • Category: data source or category of the check that generated the Finding.
  • Type: type of Finding.

Below the chart, four cards show the latest activity: Total, New this week, Resolved this week, and Dismissed this week. Clicking a bar opens the Findings page with the selected Severity, Category, or Type filter.

Review at least Severity and Type. Severity indicates urgency; Type reveals whether a recurring configuration problem is becoming more common. A high value for Dismissed this week should be justified and spot-checked, because dismissing a Finding is not the same as implementing a technical fix.

Top Findings

Top Findings shows the five Findings with the highest risk level. Clicking an entry opens the Findings view filtered to that Finding. This widget serves as a short triage list, but it does not represent all open Findings. After reviewing the top five, you must therefore still inspect the aggregated inventory.

MFA Coverage

MFA Coverage shows the percentage of identities with multi-factor authentication configured, both overall and for Admin Users, Internal Users, Guest Users, and VIP Users. Clicking an identity type opens Directory with the appropriate filter.

Prioritize MFA gaps for privileged and particularly exposed accounts. A percentage alone does not indicate whether the method in use is phishing-resistant or whether an exception is required for business reasons. If coverage is unexpectedly low, also check the data path: Missing Entra P1/P2 data, a recent license change, or certain older configurations of external MFA providers may prevent the status from being reported as expected.

Top 5 Risky Users

Top 5 Risky Users shows the five user identities that have a high personal Risk Score and open Findings. Each entry displays the identity name, number of open Findings by Severity, and current score. Clicking the name or icon opens Identity Details; the New Tab icon opens the Identities section in Directory.

To determine the order of work, review open Critical and High Findings first, followed by the other contributing factors and the identity’s business context. The personal Risk Score and the organization-wide Risk Posture Score are different metrics and must not be treated as equivalent.

Dormant Accounts

Dormant Accounts shows accounts whose last sign-in was more than 90 days ago. In addition to the total, it displays Members, Guests, Admins, No MFA, Compromised, and VIP. These categories are independent and not mutually exclusive: The same account can be Admin, No MFA, and VIP, for example. Therefore, do not add the categories together to calculate a total.

Clicking a segment opens Directory with the corresponding filter. Before deactivating an account, determine whether it is an emergency account, an account used seasonally, or an identity with a technical dependency. The Dormant status describes inactivity; it proves neither misuse nor that the account is no longer needed.

Credential Leaks

In addition to open credential-compromise Findings, Credential Leaks shows leak metrics for the configured domains. If available, it also shows the trend for the last 30 days. It includes:

  • Leak-Related Findings: open credential-compromise Findings, also broken down by risk level.
  • Sources: active, unique leak sources containing data for the monitored domains.
  • Plaintext: active leaks in which plaintext passwords were observed.
  • Hashed: active leaks containing hashed passwords.
  • Breached Email Accounts: active, unique email accounts in leak data.
  • Unique Passwords Breached: active, unique passwords in leak data.
  • VIP Account Leaks: leaks involving identities configured for VIP Monitoring.

The metrics include all known active Credential Leaks. They may include old leak data or addresses belonging to former employees if they match the monitored domains. In contrast, a Finding is generated only for a leak assessed as active that matches an active identity. Consequently, the widget metrics and the number of Findings do not have to match.

Clicking the total for Leak-Related Findings opens the appropriately filtered Findings view; clicking another metric opens the corresponding leak data in Dark Web Intelligence. Discoveries of plaintext or hashed passwords are initially only signals for investigation. Determine whether a current account is actually at risk based on the identity status, leak date, most recent password change, MFA, and Finding details.

VIP Users

VIP Users shows the total number of users configured for VIP Monitoring and a Top Risky VIP Users list. Each entry displays the name, open Findings by Severity, and current Risk Score. Clicking the name or icon opens Identity Details; clicking the Finding count opens the Findings tab there.

The widget helps you focus your review on particularly exposed people. However, an empty or unexpectedly short list is not automatically a sign of a healthy state: First check whether all expected people have been configured for VIP Monitoring.

Practical daily review

The following sequence prevents the largest number alone from determining the response:

  1. Record data freshness: Note the tenant, date, and time. Check whether Identity Breakdown is plausible in light of known changes.
  2. Check the score: Record the rating, score, and daily change. If there has been a relevant movement, open the 14-day history and investigate the change using the daily data points.
  3. Explain transitions: For the affected day, review Findings that were created, reopened, dismissed, or resolved. In the open inventory, also consider Findings that have been open for longer.
  4. Determine urgency: Read Top Findings, Top 5 Risky Users, and Recommendations & Actions together. Assess Critical/High Findings, privileged accounts, and VIPs first.
  5. Check coverage: Investigate unusual MFA gaps, dormant admin accounts, and unexpected changes in Humans, NHI, or Devices.
  6. Assess Credential Leaks: Do not equate leak metrics with Findings. Navigate to the active identities and Finding details before initiating response actions.
  7. Document actions: Record the owner, Finding, rationale, target date, and expected success criterion. Dismissals require a traceable operational justification.
  8. Plan follow-up: After a fix, first check the Finding status and affected detail view. Check the effect on the organization-wide score again after the next daily update.

Used this way, the score is a prioritization and trend tool. The operational goal is not to reduce a number without context as quickly as possible, but to resolve the riskiest, genuinely relevant causes in a traceable way.

Validation after an action

After making a change, validate data collection, the Finding, and the organization score separately:

  1. Confirm in the identity provider that the intended change is actually active, such as MFA registration, role removal, or account deactivation.
  2. After the next applicable data synchronization and Posture Check, reopen the affected identity or Finding. Posture Checks run every two hours; this cycle is not the same as the daily score calculation.
  3. Check whether the Finding has the expected status. A manually dismissed Finding is not automatically considered technically resolved.
  4. After the next daily update, check Identity Risk Posture Score and Risk Over Time.
  5. On the detail page, click the relevant day and verify that the expected resolved or dismissed transition appears in the daily table.
  6. If the score remains unchanged, also consider other open Findings and their risk levels. Resolving one Finding may not produce a clearly visible overall change when the inventory is large.

This check confirms how the information and status changes appear in ITDR. It is not proof that an account was never compromised or that all identity attacks have been ruled out.

Troubleshoot unexpected values

The score does not change immediately after a fix

The organization score is updated daily, while Posture Checks run every two hours. First check whether the Finding is actually resolved and whether the change is visible in the identity provider. Then wait for the next daily update and inspect the relevant day in the history. Other open Findings can keep the overall score stable.

The score drops after a dismissal

This may be consistent with the documented calculation behavior, but it does not mean that the technical cause has disappeared. Recheck the dismissal rationale, Finding evidence, and approval. If the Finding was dismissed only to reduce the score, the case must be reassessed on its merits.

A known open Finding is missing from the daily table

The table shows only Findings that were created, reopened, dismissed, or resolved on the selected date. As expected, a Finding that was opened earlier and remains active will be absent. Check the complete open inventory in Findings and select the date of the actual transition in the history.

MFA Coverage is unexpectedly low

First inspect individual affected identities using the widget link. Then verify that the required Entra ID data is available. After a change from Entra ID Free to P1 or P2, Microsoft may provide updated account information only after a delay; Sophos indicates that delays of up to one week are possible. With older configurations of external MFA providers such as Okta or Duo, Microsoft may not provide the status at the user level. The displayed value must therefore not be treated prematurely as proof that MFA is disabled.

Identity Breakdown differs from the expected inventory

Check whether only active identities are counted and whether applications are consolidated under Non-Human Identities (NHI) as expected. Then check known additions and removals in the identity provider and the state of the integration. An unchanged score does not prove that object coverage is complete.

Dormant categories appear to total more than the overall number

This is possible because Members, Guests, Admins, No MFA, Compromised, and VIP overlap. Do not add them together. Instead, open each segment separately and inspect the actual identities in Directory.

Credential Leak numbers do not match Findings

The leak metrics include all known active leaks for the configured domains, including potentially old data or data relating to former employees. Findings require a matching active identity and a leak assessed as active. Use Leak-Related Findings and the individual metrics to open both views separately; a difference is not automatically an error.

The monthly curve looks flat even though the score changed sharply on one day

Risk Over Time represents monthly averages and can smooth out brief spikes. Use New Tab to open the detail page, select a narrower date range, and hover over or click the daily points. Export the relevant section as a PNG for the report instead of relying only on the six-month average.

Widgets remain implausible after the expected update windows

First document the observation time, affected widgets, expected values, and identities already checked. Then cross-check the integration or sensor status and the data in the identity provider. An escalation should include the tenant, period, screenshots without unnecessary personal data, affected objects, and the specific discrepancy. A delayed or empty widget alone must not be taken as evidence either of an attack or of its absence.