Identity Exposure Management Overview
Overview
What is Identity Exposure Management?
By pairing industry-leading coverage of exposed credentials and session cookies with simple, actionable, automated validation and remediation workflows, Identity Exposure Management enables you to proactively tackle identity exposures, shrink response times, and drastically reduce the chances of a business-disrupting breach.
Core Concepts
Identity Identifiers
Identity Identifiers are a new type of Identifier designed to represent a person and their associated attributes.
Identity identifiers replace these existing types: Email, Name, and Username. Email, Name and Username Identifiers have been transitioned to Identity Identifiers.
Authorized vs. Unauthorized Identities
Authorized Identities are Identifiers that have been synced with an Identity Provider. This enables the various functionality such as Identity Profiles, Credential Validation and Remediation.
- These identifiers are automatically created through syncing with your Entra ID instance. One-to-one coverage for all employees within your Entra ID instance is the default configuration motion.
- Authorized Identity Identifiers enable additional platform functionality, including enriched Identity Profiles, “Blast Radius” visualizations, and automated validation and remediation of exposed identities.
- Authorized Identity Identifiers require additional permissions within your Entra ID’s connection with Flare.
- Authorized Identity Identifiers are fundamentally different and separate from Identity Identifiers and all other standard Flare Identitifiers. They are available at an additional cost within your Flare subscription. Reach out to your Flare Customer Success Representative for more information.
Identity Identifiers Creation
There are two ways to create an Identity Identifier:
- Sync your identities from Entra ID (Authorized)
- Manually create an Identity Identifier (Unauthorized)
Impact on subscription: Confirm you have the proper number of identifiers for the number of Identity Identifiers you want to create
For additional configuration details, please refer to Configure Identifiers
Once Identity Identifiers are set up, Identity ProfilesIdentity Profile are available to view their attributes, exposure level indicators, and blast radius.
Creating & Managing Identities
- From the Identifiers page
- You can select Create Identifier.
- Select Identity as "Type". Fill the rest out appropriately.
An Authorized Identity Identifier requires the Identity to be imported from EntraID. Manually creating Identity Identifiers will result in an Unauthorized Identity Identifier unless the user is within Entra ID and within the scope of the import.
- Merging Identities
- To merge Identity Identifiers, you can go to the Identifiers tab. Select the three dots (hamburger menu) on the left-hand side and you can merge with a specific identity.
- From the Integration Hub
You can enable the Identity import from the Integrations Hub. This will import Identities from Entra ID and create associated Identity Identifiers.
Note: You must be an Organization Admin to access the Integrations Hub
If you import a group, only users from the group will be imported, if there is no group everyone will be imported
- Consider creating a dynamic group in Entra ID with appropriate include or exclude conditions to maintain this integration.
- Credential Browser Enabled Features:
- Select the desired validation and remediation capabilities. You can select multiple. Confirm the app registration has the appropriate application permissions to be able to perform these operations.
- Note: Remediation action occurs if the credential is confirmed valid.
- Finally test and save the integration
- Identity Identifiers will be imported from Entra ID identies and created
- Automated pasword validation will occur for any credential found in the last 24 hours