> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/identity-posture-score.md).

# Identity Posture Scores

### Overview

The Identity Posture Score is a single score calculated for your organization to help you quickly and easily determine areas of focus that will improve your organization's overall identity security hygiene. Scores range from 0 to 100, and from very weak to very good - the higher the score, the better your organization's security posture.

Additionally, recommendations on how to improve your organization's identity posture are provided in order of impact to the score, so you can easily determine which identity security hygiene gaps to prioritize.

The Identity Posture Score is determined based on a number of criteria including integrations connected, number of users impacted by a check, check severity, user context and other factors.\
See [Calculation of Identity Posture Score](#calculation-of-identity-posture-score) for detailed information on how the score is determined and the thresholds associated with each score category.

You can see more information about your organization's current Identity Posture Score, as well as the score's trends over time, on your [Dashboard](/dashboard/posture/identities-dashboard.md#identity-posture-score)*.*

{% hint style="info" %}
There are no settings related to the Identity Posture Score and it cannot be customized directly. To learn more about tuning checks, which can impact the number of users failing a check and thus, indirectly the Identity Posture Score, please refer to our documentation on [customizing checks](/understanding-check-failures/customizing-checks.md).
{% endhint %}

### Why should I fix my organization's identity posture?

#### Identity attacks are really similar to home burglaries

Think of your organization as a house. You make sure all the doors are closed and locked before you go out to run an errand. While you're away, someone decides to break into your house. They will try to get in through the doors first because that's easiest. When they realize all your doors are locked, they don't give up - they try the windows next. But wait... you didn't check the windows!\
\
**I**f you can't get the basics of closing and locking all your doors and windows down, it wouldn't make sense to install fancy video cameras or alarm systems to monitor your house while you're away because the burglar will still get in! Although these tools can be helpful to identify the burglar later on, or shorten the amount of time they have to take your valuables, it doesn't stop them from getting into your house in the first place and causing damage.

This house example, though simplified, depicts why it is so critical to address postural issues within your organization.

Just like a burglar, a bad actor will try to use the easiest path first, like guessing the password of accounts with no MFA configured. If that doesn't work, they'll try cleverer approaches, like MFA phishing or session theft, to try and gain access to your system. One thing is for certain - while the attack technique might change, **the attacks themselves will not stop.**

With good identity security posture, when a threat comes in (because we know they *will* come in), you have some peace of mind knowing that the basic protections are in place to ensure your organization is less likely to get "broken into". You've made sure all the doors AND windows are locked, by requiring basic MFA methods and cleaning up inactive accounts. As your organization's identity security posture matures, you then take more advanced steps to protect it, like enforcing stronger MFA methods and reducing session lengths.

Improving your organization's identity posture won't stop the attacks from coming, nor will it stop a very determined bad actor who is willing to try everything possible to gain access. But it ***does*** ensure that the attacks that come in are generally less risky because the right precautions and measures were put into place.\
\
With Cisco Identity Intelligence, you get both sides - Posture Score and posture checks act as the voice in the back of your head reminding you to lock your doors and windows. While User Trust Levels and threat checks act as the fancy security system to monitor and alert on potentially malicious behavior or threats that should be investigated, and help clean up as soon as possible if someone does slip through the cracks.

### Dashboard widgets

Two widgets related to Identity Posture score can be found on the Dashboard. To read more about the widgets, please see our [Dashboard](/dashboard.md) documentation for detailed information about each visualization.

## Identity Posture Scores

### Overview - Three Scores

The Identity Posture Score provides organizations with comprehensive metrics to assess identity security hygiene. Instead of a single score, Posture Score v2 breaks down security posture into three distinct scores that measure different aspects of your identity ecosystem:

* **Users Score** — measures the security posture of human users (employees, contractors, etc.)
* **MFA Score** — measures multi-factor authentication adoption and strength
* **NHI Score** — measures the security of non-human identities (service accounts, applications, etc.)

Each score ranges from 0 to 100 and is classified into one of five categories:

| Score Range | Classification |
| ----------- | -------------- |
| 0–39        | Very Weak      |
| 40–59       | Weak           |
| 60–79       | Neutral        |
| 80–89       | Good           |
| 90–100      | Very Good      |

### Understanding the Three Scores

#### Users Score

The Users Score evaluates the security of your human user population across factors including:

* **Account activity** — detects inactive and never-logged-in users
* **Admin account hygiene** — identifies dormant admin accounts and admins sharing authenticators
* **Guest account management** — identifies stale guest accounts
* **HRIS integration** — validates user data against your HR system for missing or discrepant records
* **Active Directory health** — identifies accounts with weak passwords or kerberoastable configurations

A higher Users Score indicates a well-maintained user population with strong account governance practices.

#### MFA Score

The MFA Score measures the strength and adoption of multi-factor authentication:

* **MFA adoption** — percentage of users with MFA configured
* **MFA strength** — identifies users with weak MFA methods (SMS, email, security questions) instead of phishing-resistant methods (FIDO2, hardware keys)
* **MFA bypass risks** — detects users with recovery methods that are frequently used, which may indicate bypass activity
* **Priority user coverage** — admins and other high-risk users receive additional weight in the calculation

A higher MFA Score indicates strong MFA adoption and the use of phishing-resistant authentication methods across your organization.

#### NHI Score

The NHI (Non-Human Identity) Score measures the security of service accounts, applications, and other machine identities:

* **Authentication strength** — detects non-human identities without MFA or phishing-resistant authentication
* **Privilege management** — identifies non-human identities with unnecessary admin privileges
* **Access hygiene** — detects dormant non-human identities and those with browser access
* **Ownership and lifecycle** — identifies non-human identities with no owners or deprovisioned owners
* **Credential rotation** — detects non-human identities with failed password rotation

A higher NHI Score indicates well-managed, secure non-human identities with proper controls and lifecycle management.

### Score Calculation

Each score is calculated based on weighted indicators. The weighting reflects both the severity of the security issue and the scope of affected users or identities:

* **Severity weight** — critical issues receive higher weight than low-severity issues
* **Scope multiplier** — issues affecting more users or identities have greater impact on the overall score
* **User context** — administrators and other privileged users often receive higher weighting for security-sensitive checks (e.g., MFA requirements)

The calculation is continuous and updates as posture data changes throughout the day.

### Requirements and Limitations

#### Prerequisites for Maximum Scores

To achieve the highest possible scores (90–100 range), one condition must be met:

**All posture checks must remain enabled** — organizations cannot exclude checks to artificially inflate scores.

#### Optional Integration: HRIS Data

If you connect an HRIS system (Workday or manual upload), two additional checks become active:

* **Users not in HRIS** — identifies user accounts with no matching HRIS record
* **HRIS discrepancies** — identifies user accounts with mismatched data (name, email, status) compared to HRIS

If HRIS integration is not configured, these checks remain inactive and do not impact your Users Score. Your Users Score will be calculated from the other identity checks instead. Adding HRIS integration may initially lower your Users Score as discrepancies are discovered, but it enables better long-term user lifecycle management.

#### New Integration Grace Period

When you first enable a new integration (such as connecting your HRIS or identity provider), your scores may temporarily increase. This grace period lasts for seven days while the system collects baseline data. After seven days, scores normalize based on actual security posture.

### Using Your Scores

#### Interpreting Your Posture

Review each score alongside the detailed recommendations in your dashboard:

* **Users Score:** Review inactive accounts, admin account hygiene, and HRIS alignment
* **MFA Score:** Review MFA adoption rates and the distribution of authentication methods
* **NHI Score:** Review privilege assignments, dormant identities, and ownership records

#### Taking Action

For each score, the dashboard prioritizes recommendations by impact. Organizations should determine the appropriate remediation approach for each issue:

* **User remediation** — enable MFA, rotate credentials, update account settings
* **Account deletion** — remove inactive, unneeded, or deprovisioned accounts
* **Check exclusions** — exclude specific users or identities when they have legitimate exceptions, e.g. a user can be [excluded](https://app.gitbook.com/o/5tZLGpRcYwxbRurPmO8K/sites/site_VTshA/s/qPSBzsjxd7KYg9DNVZ4l/~/diff/~/changes/1109/~/revisions/current/understanding-your-users/remediation-actions#exclude-user-from-check) from a particular check so that they are no longer failing the check for a specified window of time
* **Custom detection settings** — adjust detection thresholds for your environment (e.g., inactivity periods) to better align with your organization's processes and policies (Ex: the default setting for the Inactive Users check is 30 days, when your organization's process is 90 days)
  * To configure a check's settings, navigate to the check you'd like to modify. If [**Check Settings**](https://app.gitbook.com/o/5tZLGpRcYwxbRurPmO8K/sites/site_VTshA/s/qPSBzsjxd7KYg9DNVZ4l/~/diff/~/changes/1109/~/revisions/current/understanding-check-failures/customizing-checks) are available for that particular check, it will be located in the top right corner of the Check page, and select **Custom Detection Settings**. Note that not all checks have settings that can be modified
* **Sensitive applications list** — mark applications that should receive additional security scrutiny. You can modify the list by [Adding Sensitive Applications](https://docs.oort.io/applications#customizing-the-applications-page)&#x20;

#### Improving Your Scores Over Time

Identity posture improvements compound gradually as remediation work progresses:

1. Address high-impact recommendations first (those affecting the most users or the highest-risk identities)
2. Focus on the score with the greatest gap to improve overall security posture
3. Monitor trend data to see the impact of remediation efforts
4. Prioritize phishing-resistant MFA adoption for users, especially admins

### Related Resources

* [Posture Dashboard](/dashboard/posture/identities-dashboard.md#posture-scores) — view your current scores and drill into detailed recommendations
* Journeys — see your organization's identity security improvement roadmap
* Users — manage user accounts and view individual security posture
* Non-Human Identities — manage service accounts and application identities
