- Related Products
- ADAudit Plus
- ADSelfService Plus
- EventLog Analyzer
- Exchange Reporter Plus
- AD360
- Log360
The Identity Risk Assessment report in ADManager Plus identifies the potential identity risk indicators in your organization. It offers visibility into the health and risk posture of both your Active Directory (AD) and Microsoft 365 environments. ADManager Plus implements the guidelines of NIST SP 800-30 to assess the likelihood of occurrence and impact level of risk indicators to compute a risk score. It locates the plausible risk indicators in your organization, offers insights on why they could be a risk indicator, and what can be done to secure your organization from them. ADManager Plus also computes and displays a risk score to summarize the significance of the identified risks.
In a nutshell, ADManager Plus assesses your AD and Microsoft 365 environment, identifies the potential risk indicators, evaluates them, provides remediation measures, and helps you keep risks at bay with this report.
In this document, you will learn the following:
The following are some terms that you will come across in this report and it is imperative to know them:
Term | Description |
---|---|
Risk Score | An indicator of your overall risk posture. It can be low, medium, high or critical. It is recommended to have a low risk score to secure your organization. |
Risk Exposure | It signifies the percentage of objects vulnerable to a particular risk. |
Likelihood of occurrence | The possibility of an occurrence for the identified risk indicator along with insight on the potential damage that it could cause. |
Remediation measures | Actions that can be taken to eliminate and avoid the identified risk indicator. |
Dashboard view | A comprehensive one-stop view of all the identified risk indicators categorized based on the objects identified, along with a graphical risk score indicator. |
Tile view | A tile-view of all the identified risk indicators categorized based on their severity along with graphical indicators. |
Note: Only technicians delegated with the Identity Risk Assessment role can view this report and only in the delegated OUs. To delegate this role, Delegation > Help Desk Roles > Edit a help desk role/Create a new role > Administration > General > Check Identity Risk Assessment.
ADManager Plus assesses active risks in your identity-environment. All risk indicators go through three phases of computation. This assessment blends qualitative and quantitative techniques, making it semi-quantitative. The ultimate output is to derive a risk score that represents the security posture of your AD.
What follows is an explanation of the risk scoring methodology, the factors used to calculate the risk score, and the rationale behind it.
In the first phase, each risk indicator is assessed by following a three-step calculative process: Likelihood determination, Impact analysis, and Severity determination.
Likelihood of occurrence is the probability or chance that a particular threat event or risk will happen or materialize. The overall likelihood is determined by correlating "Likelihood of Attack Initiation" and "Likelihood of Initiated Attack Succeeds."
Likelihood of Attack Initiation: The probability that a threat source initiates an threat event or vulnerability-exploit. Factors— pertinent to capability— considered under likelihood of attack initiation are:
Likelihood of Initiated Attack Succeeds: The probability that an initiated attack or threat event will result in an adverse impact on the organization's assets, operations, or aims. The factors considered under Likelihood of Initiated Attack Succeeds are "Capability" and "Vulnerability Severity."
Capability: Alludes to the skills, resources, and opportunities at the disposal of potential attackers that they can leverage to exploit vulnerabilities, escalate privileges and orchestrate subsequent malicious activities within the AD or identity environment. Capability factors are mentioned under Likelihood of Attack Initiation.
Vulnerability Severity: The degree or level of harm that could result from the exploitation of a specific risk indicator. Factors considered in deriving the vulnerability severity are:
For every risk indicator, a numerical value is assigned to each capability and vulnerability severity factors. The average of all capability factors will result in overall capability while the average of all vulnerability severity factors will result in overall vulnerability severity.
Subsequently, the overall capability and vulnerability severity are averaged to derive the Likelihood of Attack Initiation.
Overall likelihood: An assessment output derived by correlating the results of Likelihood of Attack Initiation and Likelihood of Initiated Attack Succeeds for each risk indicator using a 4x4 correlation matrix.
This step assesses potential consequences of a risk or vulnerability-exploit. Potential consequences can include damage to a company's business operations, financial loss, reputational damage, or any other aspect deemed relevant by the organization. Factors considered under impact analysis are:
Similar to the preceding step, for every risk indicator, a numerical value is assigned to each impact analysis factors and the average of all those factors will result in the overall impact.
This step determines the severity of risks based on their likelihood and impact using a 4x4 correlation matrix.
Risk Matrix: Likelihood vs Impact
*Vertical scale is likelihood and Horizontal scale is impact
In the second phase, each risk indicator is assigned a weightage based on their impact and risk severity. The weightage scale ranges from 1 to 10.
After the weightage has been assigned, the next step is to calculate the risk exposure for each risk indicator. This involves using the formula: number of risky objects related to a specific risk divided by the total number of objects within the scope of that risk in the environment. An example of this would be:
Risk exposure= Number of disabled users/Total number of AD users
In the final phase, the overall risk score for your identity environment is calculated using a weighted average method that is comprised of weightage values and risk exposures as variables.
Note: The risk score and report become obsolete when a newer report is generated. Only risk indicators included in the assessment are scored, and failed to run indicators are not included in the final risk score. It's advisable to include all domains in the selected forest before assessing for an accurate analysis of your identity environment.
ADManager Plus analyzes the severity of risks in AD and Microsoft 365 using risk indicators such as privileged and non privileged users, computers, and groups.
Privileged users
Non-privileged users
Privileged Users
Non-privileged Users
General
*The threshold value for these risk indicators can be configured by clicking the Settings button.
Note: When ADManager Plus accesses the domain objects' details for analyzing the risks through LDAP queries, it might trigger security alerts in your existing security systems.