Findings allow you to view and investigate notable events in your organization's Active Directory and Entra ID, including:
- Active Directory Tier Zero and Entra ID Privileged object activity, including the identification of unprotected Tier Zero objects.
- Hygiene indicators detected by Assessments.
- Detected TTP and Detected Anomaly Indicators collected by Audit.
|
|
NOTE:
- Hygiene indicators identified by Assessments show that certain objects may be vulnerable to adversary attacks.
- Detected indicators suggest that an action occurred which could potentially be an adversary attack. Detected TTPs (tactics, techniques, and procedures) are indicators found through search-based detection, while Detected Anomalies are indicators identified through statistical analysis.
|
To view Findings:
The Findings View displays the following information for each finding:
- Finding name
- Severity level
|

|
NOTE: Identity Defense calculates severity levels by a range of values (for example, the lower the value, the higher severity). If you sort by this column, you can see the Findings in order of most to least severe. |
 |
Critical |
Generally reserved for Hygiene and Detected Indicators that are changes to Tier Zero and Privileged object security, have significant potential impact to the Active Directory or Entra ID environment, and are not part of the default Active Directory or Entra ID configuration. |
 |
High |
Generally reserved for:
-
Hygiene and Detected Indicators that are of high concern but impact single objects.
-
the discovery of new Tier Zero domain objects and Privileged tenant objects.
-
changes to Tier Zero and Privileged objects that occur more often through normal business operations or are part of the default Active Directory or Entra ID configuration. |
 |
Medium |
Generally reserved for the discovery of:
-
Tier Zero user, computer, group, and Group Policy objects.
-
Privileged user, role, group, and service principal objects. |
- Type (Tier Zero, Hygiene, Detected TTP, or Detected Anomaly)
- Workload (Active Directory or Entra ID)
- Last Detected date and time. (This field displays the signed-in user's local date and time.)
- Status (Active or Inactive)
|
|
NOTE: If you click the Filter button, you can filter displayed results by one or more of the following criteria:
- Finding
- Severity
- Type
- Status(Active Findings display by default. You can choose to display either Active or Inactive Findings in the list, but not both.)
|
From the here you can dismiss one or more Findings and view Finding history.
The Object View provides a consolidated view of principals and their associated findings. Use this view to identify principals with detected issues, review hygiene status, and analyze findings across Active Directory and Entra ID environments.
The view displays the following information:
| Column |
Description |
| Principal Name |
Name of the principal associated with findings. |
| Type |
Type of object, such as User or Group. |
| Directory Name |
Directory where the object resides. |
| Workload |
Identity platform associated with the object, such as Active Directory or Entra ID. |
| Certification Status |
Indicates whether the object is classified as a Tier Zero asset. |
| Total Detected |
Total number of detected issues for the object. |
| Total Hygiene |
Total number of hygiene-related findings for the object. |
| Total Findings |
Combined count of findings associated with the object. |
| Last Detected |
Date and time when a finding was most recently detected for the object. |
Filter and sort data
Use the Filter menu to narrow the list of displayed objects and quickly locate specific principals.
The following columns support filtering and sorting:
- Principal Name
- Type
- Directory Name
- Workload
- Certification Status
The following columns support sorting only:
- Total Detected
- Total Hygiene
- Total Findings
- Last Detected
To sort data, select a column header. Select the column header again to reverse the sort order.
To apply filters:
- Select Filter.
- Choose one or more filterable columns.
- Specify the filter values.
- Select the logical operator and apply the filter to update the results.
AND – Returns only objects that match all selected filter criteria.
OR – Returns objects that match any selected filter criteria.
Filterable columns
| Column |
Value |
| Principal Name |
Principal names |
| Type |
Types |
| Directory Name |
Directory names |
| Workload |
Active Directory, Entra ID |
| Certification Status |
Certified, Not Certified, Not Tier Zero |
Filter by principal name
You can filter the Object View by one or more principal names. Multiple principal name filters can be combined using:
- AND to return objects matching all specified criteria.
- OR to return objects matching any specified criteria.
Predefined principal name filters can also be passed through external links, allowing you to open the Object View with filters already applied.
To refresh data
- To display the most recent findings data, select the Refresh icon in the upper-right corner of the Object View.
From the Findings list, select a Finding to investigate in more detail:
- Tier Zero and Privileged objects that have been identified by the provider (Identity Defense or BloodHound Enterprise) or added manually by a user.
- Hygiene and Detected Indicators that have been found through Identity Defense Assessments and Audit Critical Activity.
From the Investigate Finding page, you can:
-
View a summary of the Finding key elements
-
Access Identity Defense Intelligence to answer your questions and provide a high-level overview of your environment, including identified Findings and recommended actions to resolve issues.
|
|
NOTE:
- Before you can access the Identity Defense Intelligence assistance, you need to read and accept the AI Terms of Use.
- To refresh the Identity Defense Intelligence content in the flyout, click the AI icon next to a different user object.
|
|
|
NOTE: Navigate between questions either by clicking a the name or using the Next and Back buttons. |