Most organisations have a good understanding of how their identities are configured.
They know which accounts exist, what permissions they have and which systems they are supposed to access.
But there is a different question that is much harder to answer:
What are those identities actually doing?
That gap between configuration and real-world activity is becoming increasingly important for IT and security teams.
Configuration doesn’t tell the whole story
Active Directory and Entra ID contain a wealth of information about users, groups, service accounts and permissions. Security teams also have access to audit logs and monitoring tools.
Yet it can still be difficult to answer some very basic questions:
- Which accounts are actually being used?
- Which dormant accounts still have access to critical systems?
- Which service accounts are still required?
- Which access paths are actually being used?
- What could be affected by changes to authentication or identity infrastructure?
Knowing that an account has access is not the same as knowing that it uses that access.
This is where identity visibility becomes important.
The challenge of dormant identities
Large IT environments often contain accounts that have accumulated over many years.
Employees leave. Applications are replaced. Projects end. Service accounts remain. Permissions change and access is often inherited across multiple systems.
Over time, it becomes increasingly difficult to maintain a complete picture of which identities are still relevant.
A dormant account with access to a critical application may never cause a problem. But if that account is compromised, its existing permissions suddenly become highly relevant.
The same applies to service accounts. An account created for a specific application several years ago may still have access to systems that are no longer required.
Entra ID makes visibility even more important
As organisations move from on-premises Active Directory to Entra ID, understanding actual identity activity becomes increasingly valuable.
Migration is not simply a matter of moving accounts and permissions. IT teams need to understand which applications and systems depend on existing identities and authentication methods.
Before making changes, it helps to know:
- which identities are actually active;
- which applications still depend on legacy authentication;
- which service accounts are being used;
- which systems are connected through existing access paths.
This provides a much clearer basis for reducing unnecessary access and planning identity changes.
A growing challenge: non-human and AI identities
The number of non-human identities is also increasing.
Applications, automation platforms, APIs and AI-based tools all require identities to operate. These identities can have significant access without being associated with a person.
That creates a new governance challenge:
Do you know what these identities can access — and what they are actually using?
For security teams, understanding non-human identity activity is becoming just as important as understanding human users.
From identity data to identity intelligence
This is where Quest Identity Insights comes in.
Rather than looking only at how identities are configured, Quest Identity Insights combines identity information with observed activity to provide a clearer picture of how identities are actually being used.
It can help organisations identify:
- dormant identities that still have privileges;
- active service accounts and their access;
- relationships between identities and systems;
- potentially unnecessary access paths;
- and activity that may require further investigation.
The objective is simple: give IT and security teams a clearer view of what is actually happening across their identity environment.
Why this matters
Better identity visibility can support several areas of IT and security:
Security
Identify accounts and access paths that may otherwise remain unnoticed.
Compliance
Gain a clearer picture of identity activity when access needs to be reviewed or investigated.
Entra ID migration
Understand dependencies before making changes to authentication and identity infrastructure.
Service account management
Determine which accounts are still being used and where.
AI and non-human identity governance
Improve visibility into identities used by applications, automation and AI-based services.
See what is happening in your own environment
The best way to understand identity visibility is to see what it reveals in a real environment.
Adfontes Software can arrange an early-access assessment of your Active Directory and/or Entra ID environment using Quest Identity Insights.
The assessment is read-only and focuses on the identities, access paths and activity that are relevant to your organisation.
Want to see what your identity environment actually looks like?
>> Contact Adfontes Software to arrange an early-access assessment.