Skip to main content

Identity Explorer

The Explorer tab gives you four ways to investigate the identity data behind the summary. Switch between remediation priorities, people, privileged access, and the full at-risk identity inventory without leaving Identity X-Ray.

Identity Explorer on the Privileged view with access, state, reach, source, and severity

Before you start

  • Complete the prerequisites in the Identity X-Ray overview.
  • Set the Data Source and Focus controls before comparing identities.
  • Use All Sources when you want Retrievy to unify the same person across sources.

Choose an Explorer view

ViewUse it to
DriversStart with the finding groups that clear the most exposure.
PeopleReview the same human across multiple Data Sources.
PrivilegedCompare identities that hold or can reach the selected crown jewels.
IdentitiesBrowse the complete at-risk identity inventory in the current scope.

Prioritize Drivers

Top Exposure Drivers ranks finding groups by remediation impact. Items that open a path to a crown jewel lead the list.

Each card shows the severity, affected count, Data Source, exposure pillar, and a Tier 0 label when the finding opens a detected path. Select Full findings list to continue remediation from the ISPM dashboard.

Review People

People at Risk groups identities that share the same email address or user principal name. Expand a person to see the account and finding breakdown for each Data Source.

Retrievy does not automatically merge possible matches that lack a shared email identifier. It lists them under Possible same person for review. This prevents similar display names from being treated as one person without supporting evidence.

Review Privileged Access

Privileged Access includes identities that hold or can reach the selected crown jewels. Its columns show:

  • Access: By design or Shadow Admin, plus Standing or PIM-eligible when assignment evidence is available.
  • State: Enabled, Disabled, Guest, or Not collected.
  • Reach: Direct, a hop count, or a dash when no route applies.
  • Source and Severity for investigation context.

PIM-eligible means the assignment must be activated before it becomes effective. It remains relevant because it can still create a route to a crown jewel.

Browse Identities

Identity Explorer lists up to the first 50 identities in the current scope, ordered by exposure. The table shows Identity, Type, Source, Findings, Severity, and whether Tier 0 is Reachable.

If more identities match, the footer reports how many remain. Select Full findings list when you need the complete finding workflow.

Use the identity detail drawer

Select an identity from Privileged, Identities, the map, or an expanded attack-path group. The drawer can show:

  • Path to Tier 0 and All Detected Paths.
  • Risk Markers collected for the identity.
  • Finding count and either Blast Radius or Top Severity.
  • The finding title and rationale for each detected check.

Press Escape, select the close button, or select outside the drawer to return to the list.

How this affects your Retrievy Index

Changing an Explorer view or opening an identity does not change your Retrievy Index. Drivers helps you find the active finding groups most likely to improve the ISPM module score after remediation and verification.

The Index continues to use the severity and state rules in the scoring rules catalog.

Troubleshooting

Symptom: The same person appears as two entries in People.
Fix: The source identities do not share a verified email address or user principal name. Check Possible same person, then correct the identity attributes in the source systems if they should match.

Symptom: State reads Not collected.
Fix: The current evidence does not include a positive enabled, disabled, or guest signal for that identity. Do not treat Not collected as Enabled.

Symptom: An identity appears under Identities but not Privileged.
Fix: It has identity findings but does not hold or reach a crown jewel in the current source and focus.