LogoLogo
SupportDeveloper Docs
  • Welcome
  • Getting Started
    • Introduction to BalkanID
      • BalkanID Onboarding
      • BalkanID Summary Dashboard
    • Setting Up BalkanID
      • User Role Management
      • Users Entitlements Discovery
      • Employee Data Extraction
      • Application Integration & Entitlement Data Extraction
      • Business Owners for Application Integrations
    • Entitlement Discovery
      • Entitlements Discovery
      • Applications Entitlements Discovery
      • Connection Entitlement Discovery
      • Resource Entitlement Discovery
      • Identities Entitlements Discovery
      • Working with Filters
      • Impact Analysis
    • Access Review Management
      • Access Review Campaigns
      • Performing Access Reviews
      • Campaign dashboard and management
      • Campaign Audit Reporting
      • Access Review Campaign Notifications and Reminders
      • Configuring Integration Specific Multi-Level Review Settings
      • Configuring Multi-Level Review Settings in Campaigns
      • Reviewer Insight Escalation for Campaigns
      • Recurring Campaigns
      • Campaign Escalation
      • Nominate Delegate In Account Preferences
      • Access Review Graphs
      • Access Review Recommendations
    • Access Request Management
      • Creating and Managing Access Requests
        • New User Access Request
        • New Service Account Access Request
        • New Identity Access Request
        • New Connection Access Request
        • New Resource Access Request
        • New SCIM Access Request
    • System Notifications & Automatic Ticket Creation
      • Notification Preferences
      • In-app Notifications
      • Supported Ticketing Systems
    • BalkanID CLI
      • BalkanID Extractor CLI
      • BalkanID API CLI
  • Configurations and Integrations
    • Integrations Overview
    • HRIS Integrations
      • Integrate via Merge
    • Direct Application Integrations
      • Asana Integration Setup
      • Atlassian Confluence Integration Setup
      • Atlassian Jira Application Integration Setup
      • AWS Application Integration Setup
      • AWS Identity Center Integration Setup
      • Bitbucket Integration Setup
      • Box Integration Setup
      • Code Climate Integration SetupPage
      • Datadog Integration Setup
      • Dropbox Integration Setup
      • GitHub Application Integration Setup
      • Gitlab Integration Setup
      • Google Cloud Platform Integration Setup
      • Google Drive Integration Setup Guide
      • Google Workspace Integration Setup
      • Jenkins Integration Setup
      • JumpCloud Integration Setup
      • MariaDB Integration Setup
      • Microsoft Azure and Active Directory (AD) Integration Setup
      • On-Prem Active Directory (AD) Integration Setup
      • Microsoft Office365 Integration Setup
      • MongoDB Integration Setup
      • MySQL Integration Setup
      • Netsuite Application Integration Setup
      • New Relic Integration Setup
      • Okta Application Integration Setup
      • Onelogin Integration Setup
      • OpenVPN Integration Setup
      • Pagerduty Integration Setup
      • Ping Identity Integration SetupPage
      • PostgreSQL Integration Setup
      • Ramp Integration Setup
      • Salesforce Application Integration Setup
      • SAP Integration Setup
      • Sendgrid Integration Setup
      • Sentry Integration Setup
      • Slack Application Integration Setup
      • Smartsheet Integration Setup
      • Snowflake Integration setup
      • Splunk Integration Setup
      • Sumologic Integration Setup
      • Twingate Integration Setup
      • Zoom Integration Setup
    • Manual Uploads
      • Application Entitlement Data
      • Employee Data
      • Mapping Identities to Employees
    • SSO Integrations
      • Ping Identity
      • Okta
      • OneLogin
      • Microsoft
    • Fulfillment Options
    • BalkanID API
  • Playbooks and Webhooks
    • Playbooks Overview
    • Configuring Global Playbooks
    • Configuring Integration Specifc Playbooks
    • Configuring Global Webhooks
    • Configuring Integration Specific Webhooks
    • Automated Employee Data Upload Playbook with AWS Lambda & S3
    • Automated Entitlement Data Upload Playbook with AWS Lambda & S3
  • IAM RISK ANALYZER
    • Findings
    • Current State RBAC
    • IAM Risk & RBAC Analysis Report
  • Insights and Rules
    • Entitlement Rules & Labels
      • Setup Rules and Labels
      • Terminated Employee Label
      • Privileged identity Label
      • Setup privileged identities
    • Entity Insights and Finding Rules
      • Creating entity filters
      • Setup insights using entity filters
      • Setup finding rules using entity filters
  • BalkanID Slackbot
    • Setting up BalkanID Slackbot
    • Access Requests and Access Review Notifications with BalkanID Slackbot
    • Findings (Daily Alert) with BalkanID Slackbot
  • JITPBAC
    • Overview of JITPBAC
    • Purposes
      • Create Purpose
      • Edit Purpose
      • Delete Purpose
      • Filtering Purposes
      • Create User-Purpose Access Request
        • Creating a Request Through the Web App
        • Creating a Request Through the Slackbot
      • Starting & Stopping Assigned Purposes
  • BalkanID Copilot
    • BalkanID Copilot
  • Updates
    • Release Notes
      • Introducing Findings: Prioritize, Act, and Automate Identity Risk Management
      • Action Center as a command hub for identity risk findings
      • Introducing Impact Analysis: Visualize, Understand, and Manage Access
      • In-app Notifications & Notification Preferences
      • Upgrades to RBAC Analyzer
      • Slackbot for Access Requests and Review Notifications
      • Playbooks and Webhooks for enhanced workflow automation
      • Introducing support assistant for BalkanID application for in-app support
      • Scheduling campaigns & multi-level approvals, nomination & delegation of reviews and graph views for
      • Campaign dashboard actions, access reviews by identity, enhanced access requests and entities connec
      • Access Provisioning & Deprovisioning, Email Notifications, Access Reviews & Campaigns Updates and Ne
      • Quickly find what you’re looking for with the new People, Applications, and Identities pages
      • Integrate your HRIS or Identity Provider without exposing sensitive personnel data or powerful admin
      • Quickly find unusual entitlements with Outliers (Early Access)
      • Announcing “Days Since Termination” filter
      • Announcing JumpCloud direct integration
      • Published Access Review Campaigns can now be deleted
      • Easily switch between tenants using the new tenant picker
      • Skip Access Review Campaigns by downloading a PDF report of your Entitlements
      • User account information now available on the Account page
      • Announcing Bulk API (Early Access)
      • Announcing HRIS integration capability with 23 new HRIS integrations
      • Privileged Identity insights help to quickly identify privileged identities
      • Terminated insights help to quickly identify and remediate entitlements held by terminated employees
      • Announcing Azure and Azure Active Directory direct integration
      • Access Review Campaign drafts can now be permanently deleted
  • Terms & Conditions
    • Privacy Policy
    • Terms of Service
    • AI Policy FAQ
    • Trust Center
Powered by GitBook

© 2025 · BalkanID, Inc. | Nothing on the BalkanID website, platform, or services, nor any portion thereof constitutes actual legal or regulatory advice, opinion, or recommendation by BalkanID, Inc.

On this page
  • Purpose
  • Goals
  • Key Concepts
  • 1. Insights
  • 2. Findings
  • 3. Key Relationships
  • Creating an Insight
  • Creating a Finding Rule
  • Viewing Insights and Findings

Was this helpful?

Export as PDF
  1. IAM RISK ANALYZER

Findings

Set up & manage Insights & Findings within BalkanID, enabling users to define rules, prioritize findings, and automate actions to mitigate risks effectively.

Purpose

The IAM Risk Analyzer allows organizations to prioritize risks and findings by defining custom rules based on system-generated or user-defined insights. This feature ensures that the platform highlights actionable findings tailored to the organization’s unique requirements.

Goals

1. Define Insights: Enable users to identify and label entities with specific risks or attributes.

2. Generate Findings: Combine multiple insights into actionable findings that trigger alerts or playbooks.

3. Automate Actions: Empower users to take swift action on findings using playbooks and user actions.

4. Enable Contextual Understanding: Provide detailed information about insights and findings, including risk severity, mitigation options, and reference links.

Key Concepts

1. Insights

An Insight is a system or user-defined label that identifies a potential risk or characteristic associated with an entity.

  • System-Generated Insights Examples:

    • Weak MFA

    • Over Entitled

    • Duplicate Connection

  • User-Generated Insights Examples:

    • SoD Violation

    • Privileged

Details of an Insight:

  • Insight Name: Descriptive name (e.g., Okta Weak MFA)

  • Description: Context of the insight (e.g., “Identities with weak Okta MFA factors.”)

  • Details: Additional information about the risk (e.g., “Weak MFA methods: SMS or call.”)

  • Inherent Risk Rating: Pre-assigned risk level for the insight (Low, Medium, High).

  • Proposed Mitigations: Steps to mitigate the risk (e.g., Enforce TOTP, biometric login).

  • References: Links to external guidelines or frameworks (e.g., PCI DSS, MITRE).

2. Findings

A Finding aggregates multiple insights into an actionable risk alert. Findings provide a broader risk context and are used to trigger automated workflows.

  • Example Finding:

    • Name: Weak MFA Okta User with SoD Violation

    • Description: “User has weak MFA on Okta and violates SoD policies by accessing finance applications.”

    • Risk Rating: High

    • Components:

      • Weak MFA Insight

      • SoD Violation Insight

3. Key Relationships

  • Insights → Findings: Findings are built from one or more insights.

  • Entities → Insights: Insights are associated with entities (e.g., users, connections).

  • Finding Rules: Logical expressions that define how findings are generated from insights.

Creating an Insight

Step 1: Define Insight

  • Navigate to the Configure > Rules & Playbooks > Insights section.

  • Click Create Insight and enter:

    • Name: A descriptive title (e.g., Okta Weak MFA).

    • Description: Explanation of the insight.

    • Details: Add specifics like weak MFA methods or resource details.

    • Risk Rating: Assign an inherent risk level.

    • Proposed Mitigations: Suggest actions to resolve the issue.

    • References: Add relevant links or frameworks for context.

Step 2: Select Entities

  • Define the entities this insight applies to (e.g., users, connections).

  • Apply entity filters to narrow the scope (e.g., MFA methods = SMS or call).

Step 3: Review and Save

  • Verify the details of the insight and save it.

Creating a Finding Rule

Step 1: Select Insights and Entities

  • Navigate to Configure > Rules & Playbooks > Finding Rules section.

  • Click Create Finding Rule and enter:

    • Name: Descriptive title (e.g., Weak MFA with SoD Violation).

    • Description: Explanation of the risk.

    • Select Insights: Choose insights to include in the rule.

    • Entity Filters: Add filters to refine the scope of the findings.

Step 2: Assign Risk Rating

  • Assign a Finding Risk Rating to represent the combined risk level.

Step 3: Review and Save

  • Confirm selections in a review modal and save the finding rule.

Viewing Insights and Findings

  • Navigate to the IAM Risk Analyzer dashboard > Findings section.

  • Click on a finding to:

    • View the contributing insights and details.

    • Take user actions (e.g., Review Access, Notify, Execute a Playbook, Execute a Webhook).

  • Use filters to view:

    • Insights: A list of all active insights with details.

    • Findings: Aggregated alerts with risk ratings.

PreviousAutomated Entitlement Data Upload Playbook with AWS Lambda & S3NextCurrent State RBAC

Last updated 6 months ago

Was this helpful?