📖Cisco Identity Checks
Cisco Identity Intelligence provides two categories of insights: identity threat detection and identity posture management. More information about the different types of checks can be found here.
Navigate to the relevant section or search for a specific area of interest using either the left hand navigation menu or the list below. Click on any detection to read more information about what criteria is used to fail a user for a specific check, which data sources are compatible with each check, as well as recommendations to remediate and customizable settings.

Access from Denied Territories
Application Login Bypasses SSO
Applications with Expired Secret
Identity Intelligence Client Secret Expiring Soon
Missing Value in Mandatory Field
Non-Human Identity Password Expiration Failure
Non-Human Identities with No MFA Configured
Okta Session Length Policy Compliance
Role Assigned to Azure Cloud Only Account
Shared Mailbox Sign In Enabled
User Has Directly Assigned Application
User Password Expiration Failure

A Bypass Code Was Used To Successfully Sign In
Access From Dormant Non-Human Identity
Accounts With Unusually High Activity
Active Account under Heavy Attack
Activity From Untrustworthy ISP
Admin Role Assigned to Non-Human Identity
Authenticator Registration Anomalies
Break-Glass Account Successful Sign In
Code Exfiltration By Guest Account
Google Drive File with Excessive Sharing Permissions
Microsoft Entra ID Admin Activity Anomaly
Non-Human Identity with Interactive Browser Access
Service Account Successful Sign In
Service Principal Risk Detected
Shared Mailbox Successful Sign In
Sign-in from Recently Created IdP
Successful Access from a Previously Only Failing IP
Suspicious Activity Reported by End User
Users With Defined Email Forward Rules
Last updated