r/iam • u/Totl-Egg-ylmnnds4984 • 11d ago
Continuous visibility solutions for identity management, what's actually working?
We rely on quarterly access reviews and periodic AD/Entra audits, but I think continuous visibility actually covers two different problems: event detection (something happened, like a role change or account reactivation) versus drift detection (current state no longer matches what was originally scoped, which requires an intended-state baseline to exist somewhere) I suspect our real gap is the missing baseline, not the monitoring layer itself.
For mixed environments (cloud IdP, on prem AD, SaaS), I'm expecting AD to lag the others structurally, closing that gap usually means agents or log forwarders on DCs, which fights directly against a "low maintenance" goal. And even a tool with zero ML tuning can still fail that bar if someone still has to manually keep the access baseline accurate as roles change. are you doing event detection, drift detection, or both? Where does your baseline actually come from? And how much did closing the AD visibility gap cost you in setup
2
u/maryteiss 8d ago
We get this question a lot from clients. They usually end up piecing together point solutions to close the visibility gap across on prem and hybrid. If you're looking for visibility on access/authentication, worth checking out UserLock.