Complimentary Identity Security Risk Review

Find the identity risks attackers see first.

Get a clear, expert view of risk across Microsoft Entra ID, Active Directory and Okta. Find the weak points before stolen logins, too much access or hidden attack paths lead to a breach.

Free review · Findings session with our experts · Report for your executives
Identity is the new perimeter

How strong is your identity security posture?

Today’s attackers often log in rather than break in. They use valid accounts, inherited rights and identity mistakes to move between users, devices, cloud services and key data.

A Vectra Identity Security Risk Review, delivered with CrowdStrike technology, shows your team where you are exposed across on-premises and cloud systems. We find the weak spots that give attackers a way in. Then we turn what we find into clear priorities.

The review looks for the conditions that most often lead to account takeover, privilege escalation and lateral movement.

  • Compromised credentials

    Accounts with signs that credentials are exposed or at higher risk.

  • Excess privilege

    Users or services with more access than their role needs.

  • Stale accounts

    Dormant or unmanaged identities that widen the attack surface.

  • Weak configurations

    Settings and trust links that create exposure you can avoid.

  • Hybrid attack paths

    Links that let attackers move from on-premises systems to the cloud.

  • Lateral movement

    Identity conditions that let access spread across systems.

  • Service account risk

    Non-human identities with broad, lasting or poorly governed access.

  • Conditional access gaps

    Places where risk-based access rules could be stronger.

Figures from CrowdStrike’s Identity Security Risk Review page. Sources cited there: the 2022 CrowdStrike Global Threat Report, EMA Research and the 2024 CrowdStrike Global Threat Report.

80%
of breaches use compromised identities.
50%
of organisations had an Active Directory attack over a two-year period.
75%
rise year on year in cloud intrusions that used valid credentials.
What you will uncover

Turn a complex identity estate into clear security actions.

See where the risk sits, how it could be used against you and which fixes matter most.

Complete visibility

Get a clearer view of your identities across on-premises and cloud systems.

  • Active Directory identities
  • Microsoft Entra ID entities
  • Okta identity exposure

Actionable risk findings

Find the gaps that make identity attacks more likely or more damaging.

  • Compromised credentials
  • Excessive privileges
  • Configuration weaknesses

Prioritised roadmap

See the likely attack paths and get expert advice on how to close them.

  • Risk-ranked remediation
  • Executive-level reporting
  • Practical next steps
How it works

A focused review. Clear findings. No guesswork.

Vectra and CrowdStrike specialists guide you through a simple three-stage assessment.

Discover and profile

A light Falcon sensor maps your Active Directory accounts. Secure connectors let us see into supported cloud identity systems.

Analyse identity risk

We map accounts, rights, settings and the links between them against a risk framework. This shows up weak points and likely attack paths.

Review and prioritise

Our experts walk you through the findings and show the protection options that apply. You get an executive-ready report with ranked actions.

What you receive

Move forward with a defensible plan.

The review helps you plan the technical fixes and gives your leaders what they need to decide.

  • Executive summary - a short overview of the main identity risks and what they mean for the business.

  • Prioritised findings - issues ranked by risk, across account hygiene, privilege and attack paths.

  • Expert advice - practical steps to harden Active Directory, Entra ID and other supported identity controls.

  • A live demo - see how CrowdStrike Falcon Identity Protection can detect and stop identity attacks in the cloud and on-premises.

What to know before your review.

Is the review really free?

Yes. Eligible organisations can request the review at no cost. We will confirm the scope, technical needs and timing with your team.

Which systems can you assess?

The review covers Microsoft Active Directory and Entra ID. It can also cover relevant Okta environments, depending on the agreed scope.

Will the review disrupt our users or systems?

The review uses a lightweight CrowdStrike Falcon sensor and secure connectors. We agree deployment and access needs before we start, to keep the impact on operations low.

What happens after the assessment?

Vectra and CrowdStrike specialists go through the findings with you, hand over an executive report and discuss practical fixes and protection options. You are under no obligation to buy a product.

Who should attend the findings session?

We suggest people from cyber security, identity and access, and infrastructure or cloud operations, plus the executive or risk owner who is accountable for security.

Know where identity risk exists - before an attacker does.

Request your free Identity Security Risk Review. See where you are exposed now, the likely attack paths and the actions that matter most.