Identity Risk Posture๐
The Identity Risk Posture Overview provides an overview of your current identity posture, including your current Risk Posture Score and rating, as well as the number of identities, groups, devices, and applications (service principals) Secureworks is monitoring. In addition, you can view the top risky users, top findings, and dark web intelligence metrics
Note
Posture checks are performed in Sophos cloud infrastructure against data collected from your identity provider by the ITDR sensor or Entra ID integration. No posture assessment processing occurs on your on-premises network.

Identity Risk Posture Score & Rating๐
The Identity Risk Posture Score is an organization-level score based on the count and risk level of open findings across your environment. The score is updated daily and will move up or down based on whether findings are remediated, dismissed, or new ones are discovered. In addition, you can see how the score changed from the previous day by using the percent change and arrow.
The Identity Risk Posture Score is separate from the per-identity Risk Score, which reflects the likelihood of an individual identity being compromised. See Identity Risk Score for details.
Risk Ratings:
- 75 - 100 = Critical
- 50 - 74 = High
- 25 - 49 = Medium
- 0 - 24 = Low

Tip
Select the Identity Risk Posture Score to open the Identity Risk Posture Score page.
Directory Counts๐
Next to the Identity Risk Score and rating, find counts of identities, groups, devices, and applications (service principals) Secureworks is monitoring from your connected identity provider integrations (Microsoft Entra ID and/or On-Premise Active Directory). Select one of these counts to navigate to the associated section of the Directory page.

Top Risky Users Widget๐
The Top Risky Users widget shows the identities that combine a high Risk Score with open findings: the highest-priority group for daily triage. Each entry shows the identity name, open finding counts by severity, and the current score.
Identities show in the widget when they have at least one open finding and are sorted by descending Risk Score. An identity with a high score but no active findings will not show in the widget. Click View All Users at the bottom of the widget to go to the Identities table to see scores across all identities regardless of finding status.
Take the following actions from this widget:
- Select the user name or icon to go to the Identity Details for that user.
- Select View All Users to open the Identities section of the Directory.

Top Findings Widget๐
The Top Findings widget displays an aggregated view of the top findings based on risk level. Take the following actions from this widget:
- Select More from a recommendation to expand the row and view the full recommendation. Select Less to collapse the row again.
- Select View Related Findings to navigate to the Identity Findings page filtered by the check that identified the issue.

Credential Leaks Widget๐
The Credential Leaks widget displays the count of open Dark Web Intelligence findings by risk level as well as metrics related to leaked credentials found for the domains configured within your environment. Where applicable, it also shows the trend of this activity over the previous 30 days.
Note
The stats outlined below include ALL known active credential leaks. This could include data for users that are no longer with the organization or old leaked data matching the selected domains. We only generate findings for what we consider Active Breaches including where there is active matching identity, and as such, the stats may differ from what you see within the findings view.
- Findings โ The number of
OpenDark Web Intelligence findings with the counts by risk level - Sources โ The number of
activeunique leak sources where data for your domains has been observed - Plaintext Passwords โ The number of
activeleaks whereplaintext passwordswere identified in the leak data - Hashed Passwords โ The number of
activeleaks wherehashed passwordswere found in the leak data - Emails โ The number of
activeuniqueemail accountsthat have been observed in the leak data - Unique Passwords โ The number of
activeuniquepasswordsthat have been observed in the leak data - Admin Emails โ The number of
activeaccounts identified as anadminthat have been observed in the leak data
Select a metric to view matching breach data on the Dark Web Intelligence page.
Select Leak-Related Findings to navigate to the Identity Findings page filtered by Dark Web Intelligence findings.

Identity Risk Posture Score Page๐
The Identity Risk Posture Score page enables you to view how your Posture Score is changing over time. To access the page, select the Identity Risk Posture Score from the overview page. By default, it shows how the score has trended over the previous 14 days. Adjust the time range by using the date picker at the top of the page to choose a quick link period or to set a custom range.
Tip
There are no limits on the time range, so you can view the score for as long as there is data.

Take the following actions to explore the data:
- Select a plot within the graph to view a list of findings that were created, re-opened, dismissed, or resolved on the selected date.
- Select a finding from the table to open the finding details panel.
Note
Findings that continue to persist after they are initially opened will have their last_seen time updated. As a result, it is expected that you might not see a lot of days with new findings.
Export Identity Risk Posture Score Graph๐
To export the Identity Risk Posture Score line graph as a .PNG file, select the vertical ellipsis menu and select Download as PNG.
