Accounts | Insights
What is the Accounts page?
The Accounts page provides a view into the registered accounts associated with any registered connectors. View Accounts by source, linked identities, amount of privileged access, and more.
Accounts are displayed in order of privileged access and associated key entitlements. Privilege is sorted by Highest, High, Moderate, Low, None, and Undetermined, and is based on each account's administration and access capabilities.
How is it useful?
Use the Accounts page to discover which accounts possess high-level or administrative privileges, track membership in security groups or role access, and view areas of potential risk and remediation in the Detections and Recommendations columns.
Search and filter results
On the Accounts page, search results display automatically as you add search terms and select options.
Use a Saved filter
Insights has preset saved filters to allow you to quickly visualize what accounts need your attention. Select a Saved filter from the drop-down list.
Saved filters
-
Dormant privilege account with recommendations Inactive high and highest privilege accounts with open recommendations.
-
Privilege accounts under attackHigh and highest privilege accounts under attack whose security posture can be improved.
-
Unmanaged privileged accounts High and highest risk accounts not managed by Password Safe.
Create your own filter
- Click Add Filter.
The Filter Detections dialog box displays. - Select And or Or to determine how you want the saved filter to refine the first data set you're entering.
- Optionally, click Add Filter to add a new set of filtering criteria, and select your criteria from the drop-down menus.
- Optionally, click Add Group to add a group of additional filters to further refine your filtered criteria.
- Click Apply Filter.
Use the columns
Column title | What it means |
---|---|
Account name | The primary email address associated with the account. |
Provider | Where the account was discovered. |
Type | Service or user. |
True Privilege | The level of True Privilege the account has. See True Privilege. |
Labels | Any labels that the account has. See below for what each label indicates. |
State | Activated or deactivated. |
Dormant | The number of days the account has been dormant. An account becomes dormant after 30 days of inactivity. |
Key | Count of key entitlements held by the account. Entitlements are what grant privileges. |
Detections | Count of detections associated with the account. |
Recommendations | Count of recommendations associated with the account. |
Customize your recommendations display
Select which columns to view in your results list via the Columns icon and reorder your results by column:
- Click the column header to activate it.
- Click the arrow icon in the activated column to sort alphabetically or numerically.
View the Account Details page
Click an account name to open the Account Details page.
The Account Details page summarizes the account status, source, and assigned privilege, as well as a description of the detection. It also includes additional attributes, depending on the account source.
- Entitlements tab: At-a-glance access to the account's entitlements, enabling you to quickly identify areas of potential risk or elevated privilege.
- Detections tab: A ranking of any areas of risk, according to possible severity. Click any individual detection to view detailed results to understand both the risk and its importance or severity.
- Recommendations tab: A list of security posture recommendations that are available to mediate risk.
True Privilege graph
If an account is linked to an identity, the True Privilege graph appears under Account Details. True Privilege represents the level of access, either direct or indirect, to key entitlements or other high privileged accounts. Access can be gained from misconfigurations or permission inheritance.
Click View True Privilege graph or the icon under the Actions column on the Identities grid to open the graph.
Switch between graph views by selecting Toggle orientation and Return to original graph. Toggle orientation shows the graph vertically, while the default or "original" view is vertical.
The graph is composed of nodes. Click any node to open a side panel with detailed information.
- Identities: The starting point for the graph, represented by a thumbprint.
- Accounts: The accounts the identity is linked to, represented by a profile.
- Entitlements: The high and highest entitlements the linked accounts hold.
- Escalations: Linked from entitlements via an orange line. Includes users, groups, containers, organizations, computers, policies, and more.
Updated about 8 hours ago