Identity Profile
Overview
The Identity Profile is a central location for evaluating the exposure posture of monitored identities. You can find the Identity attributes, Severity level indicators, Exposure details, and Blast radius. The profile is accessible from the Credentials browser details panel, the events details when they affect an Identity, and the Identifiers list.
An Identity Profile requires an Authorized Identity Identifier.

Attributes & Data Sources
An Identity can contain multiple attributes, to monitor for exposures of multiple email addresses, usernames pertaining to the same Identity.
The following context information are currently collected from Entra ID:
- Last password change date
- Sign in Session Validity date
- Token Validity date
- Job Title
- Department
- User Type
- Account Enabled
Severity Level
The Severity Level represents the risk level of an identity. It is composed of:
- Current Severity
- Highlights what needs to be resolved right now.
- It is determined by the highest severity level among non-remediated events (Info, Low, Medium, High, Critical).
- This helps you focus on immediate threats that need resolution.
- Severity Level Timeline
- A visual timeline of the Severity Level to track the evolution of an identity's exposure level over time. From there, you can easily spot when an identity's exposure level spiked or dropped due to remediation.
- Identity Posture Tags
- To give you better context during investigations, you will see Identity Posture Tags on the profile. These tags provide a snapshot of the identity's status gathered from the Idp integrations and Flare context, such as:
- IdP account Status: Active, Inactive, Member, or Guest.
- VIP status
Continuous Evaluation
The system continuously evaluates severity levels as new events (like leaked credentials or stealer logs) are detected for an Identity.
- Integration with Entra ID: If you have Entra ID integrated, the system automatically adjusts severity with this additional context. For example:
- if a leaked credential corresponds to an inactive Entra ID account, its severity will be automatically lowered.
- if a leaked credential is tested as valid via Entra ID, its severity will be automatically increase.
- VIP Status: Identities marked as "VIP" in your Flare configuration may trigger higher severity rules for better protection.
Remediation Workflow
- Manual Remediation: When you remediate an event (e.g., reset a password and mark the leak as remediated), the Identity Severity Level will automatically recalculate, potentially dropping down to the level of the next highest non-remediated event.
Exposure Summary
These counts and tables provide an overview for these types of exposures:
- Passwords
- Stealer logs
- PII information
- Illicit network events
- Open Web events
Blast Radius
The blast radius shows the sprawl an attacker could reach with the user's Entra ID permissions and leaked credentials and cookies.

- Severity levels:
- Critical: Cookie or credential that matches a domain identifier or tied to a service that is designated as Critical based on their popularity and prevalence online.
- High: Cookie or credential that is tied to a service that is designated as High based on their popularity and prevalence online.
- Medium: Cookie or credential that is tied to a service that is designated as Medium based on their popularity and prevalence online– these are more common.
- Low: Everything else.
- Info: Expired or tracking cookies.