Skip to main content
Threatstealth
Login
// IDENTITY.MONITOR

Identity is the new perimeter

Login anomalies, MFA enforcement gaps, RBAC drift, and dormant privileged accounts — surfaced in real time across every tenant.

Reviewed by Threatstealth Security Architects·Aligned to SOC 2 · ISO 27001 · NIST CSF · PCI DSS V 4.0.1
// DEFINITION

What is identity and access monitoring?

Identity and access monitoring is the continuous observation of who can access what, how they prove who they are, and whether their behavior matches their baseline. Threatstealth enforces multi-factor authentication, monitors RBAC drift, and detects login anomalies across every tenant in the platform.

// THE.PROBLEM

Why identity is the #1 breach vector

  • Compromised credentials cause >60% of all breaches (Verizon DBIR)
  • MFA enrollment lapses go unnoticed until exploited
  • RBAC drift accumulates silently — yesterday's admin is today's risk
  • Dormant privileged accounts are the cheapest attacker foothold
// HOW.IT.WORKS

A four-step operational model

1

Enforce MFA universally

TOTP-based MFA is enforced at the platform level for every operator and organization user — no opt-out.

  • TOTP enrollment required
  • Backup codes managed
  • MFA reset audit trail
2

Monitor RBAC continuously

Every role change is logged with actor and justification. Privilege creep is flagged automatically.

  • Role-change audit log
  • Privilege creep alerts
  • Periodic access reviews
3

Detect login anomalies

New geo, new device, impossible-travel, and brute-force patterns trigger alerts before account takeover.

  • Impossible-travel detection
  • New-device challenges
  • Brute-force lockout
4

Lock down dormancy

Accounts unused for N days are auto-disabled. Dormant privileged accounts get extra scrutiny.

  • Auto-disable thresholds
  • Privileged dormancy alerts
  • One-click rehydration
100%
MFA enforcement
RBAC
Per-module roles
Real-time
Anomaly detection
Full
Audit trail
// WHY.IT.MATTERS

Outcomes for security teams

Cut credential-attack surface

Universal MFA + dormancy controls remove the cheapest attacker entry points before they're exploited.

Audit-ready access reviews

RBAC drift and access-review cadence map directly to SOC 2 CC6 and ISO 27001 A.9 controls.

See the chain

Identity events correlate with EDR, WAF, and SAST in the same console — credential theft → endpoint compromise → lateral movement is one investigation, not three.

// FAQ

Direct answers

Does Threatstealth replace my IdP (Okta, Azure AD)?+

No — Threatstealth complements your IdP. It monitors authentication events, enforces MFA at the application layer, and watches for RBAC drift. Your IdP remains the source of truth for identity.

Is MFA mandatory?+

Yes. TOTP-based MFA is required for every operator and organization user. There is no opt-out — this is a security platform.

How is RBAC scoped?+

Every module has its own role set (viewer, editor, admin), and roles are scoped per organization for multi-tenant isolation.

What about SSO?+

SAML/OIDC SSO is supported for enterprise customers; MFA is still enforced at the application layer as a second factor independent of the IdP.

Closed · Expert Access

Ready to see it in your environment?

Request a private security demo from the Threatstealth team.