Rezonate
  • 🏠Home
  • 🚩Platform Tour
    • đŸ‡ģđŸ‡ŗPlatform Dashboard
    • 🆔Identity Analytics
      • đŸĒĒIdentity Centric
      • 🔡Identity By Platform
    • âš ī¸Risks & Threats
      • Highlighted ITDR Capabilities
  • â„šī¸How-to Guides
    • ➕Adding Integrations
    • đŸ¤ĻManage Users
    • 🧑‍đŸ’ŧCustomize Exposures
    • đŸ‘ī¸â€đŸ—¨ī¸Querying & Filtering Data
  • 📐Core Integrations
    • Azure Integration
      • Required Privilegees
      • Update Certificate for Existing Installation
    • Okta Integration
      • Okta Integration -Remediation Supported
    • Google Workspace
      • 1-Click Integration
      • Legacy Integration
    • Google Cloud Integration
    • Zoom Integration
    • DocuSign Integration
    • GitHub Integration
      • GitHub Enterprise Expansion
    • AWS Integration
      • AWS - Required Privileges
      • Log Streaming Integration
    • Salesforce Integration
      • Salesforce - Collected Data & Query Volume
    • JAMF Pro Integration
    • CircleCI Integration
    • Auth0 Integration
    • Cloudflare Integration
    • CrowdStrike Integration
      • Integrating Permissions
    • Slack Integration
    • Workday Integration
    • BambooHR Integration
    • Snowflake Integration
    • LastPass Integration
    • SentinelOne integration
    • SAP Cloud Platform Integration
    • GitLab Integration
    • Oracle NetSuite Integration
    • Atlassian Cloud Integration
    • Zendesk Integration
    • HiBob Integration
    • Microsoft Defender Integration
    • Docusign Integration
    • Mongo Atlas Integration
    • Ping Identity One Integration
    • Generic HRIS Integration
  • 📍Notifications & Alerts
    • Slack Integration
    • HTTP Webhook Integration
      • Webhook Alert Example - Saved Search
      • Webhook Alert Example- ITDR
    • Microsoft Teams Integration
    • Torq Integration
    • Email Integration
    • Splunk Integration
    • Datadog Integration
    • PagerDuty Integration
    • Jira Integration
  • 🆘Troubleshooting & Support
    • Collectors IP Ranges
    • Data Processing
      • AWS
      • Azure Active Directory
      • Azure Cloud
      • Google Workspace
    • SSO Integrations
      • SSO Login - Okta
      • SSO Login - AzureAd
  • 📓Legal & Terms
Powered by GitBook
On this page
  • Human Identities
  • Non-Human Identities (NHI's)
  1. Platform Tour
  2. Identity Analytics

Identity Centric

The Identity centric is a 2-page section that presents aggregated, cross-platform information about the identities and the access that they have to the environment.

PreviousIdentity AnalyticsNextIdentity By Platform

Last updated 10 months ago

For this mode to be unlocked, at least 2 integrations must be connected to Rezonate.

Human Identities

a unified view of all of the Human identities, that exist across the different platforms. Rezonate, through its Authorization graph (Identity Storyline), aggregates the different sub-identities associated with each Identity, into 1 unified entity that has attributes, access path, and Risk.

From this view, it's possible to query and ask questions such as:

  • Show me all of the users who have access to specific applications

  • Show me all of the identities who have high privileges in at least one platform

  • Show me all of the identities who have no HR-related record, or are marked as offboarded.

Selecting an identity we will open a drawer with 3 tabs:

Properties - A summarized information about the identity, including associated emails, names, and other useful information collected across the board. for example -when selecting Michael Scott's identity we will see that he's known by a few names such as Michael Scott, ScottTrexony, and others. We can also see the creation date of the identity and note that he last signed in 3 days ago.

By Clicking the Devices, we can also see all of the Registered Mobile or endpoint devices that he ever used to operate in the environment. clicking on them will show additional information, such as device-state, and serial numbers.

Identity Storyline - A Visual Representation that describes the access that the identity has to the environment, taking into consideration federated access, and tenant configurations. for example, below we can see that Michael has access to a Google Workspace account through Okta and that he has federated access to 5 AWS Accounts, managed through EntraID SSO. we can also that Michael has access to additional products such as GitHub, Snowflake, and others.

By Selecting an item on the graph, we can View his storyline and deep-dive into his access path, or alternatively, we can View entity details to see expanded properties, privileges, and activity information

Security Risks - an aggregated risks & threats view for Michael Scott entities, including their risk-level, status, and ability to drill down for more information.


Non-Human Identities (NHI's)

A unified view of all of the Non-human identities, that exist across the different platforms. Rezonate Aggregate those identities by general type according to the following categories:

  • Access Keys

  • Service Accounts

  • Access Tokens

  • IAM Roles

By selecting a category we will see the different entities associated with it, including their risk level, number of identities, and associated accounts. by clicking a row we can pivot to the relevant entity page for more information.

Michael Scott Entity Properties
Michael Scott Devices View
NHI Section
🚩
🆔
đŸĒĒ
Identity Analytics Section
Michael Storyline view