Back to all guides

    Identity & Access Management

    Set up user authentication, SSO, and access controls.

    Overview

    Identity & Access Management (IAM) helps you monitor user authentication, enforce MFA, and manage privileged access across your organisation.

    Step 1: Review Identity Overview

    1. Navigate to Security Apps → Identity & Access
    2. Review MFA adoption rates across your organisation
    3. Check for accounts without MFA enabled
    4. Identify stale or inactive accounts

    Step 2: Configure MFA Policies

    1. Set MFA requirements (all users, admins only, etc.)
    2. Configure allowed MFA methods
    3. Set grace period for MFA enforcement
    4. Enable alerts for MFA bypass or removal

    Step 3: Monitor Privileged Access

    1. Review all users with admin roles
    2. Enable alerts for new admin assignments
    3. Set up periodic access reviews
    4. Configure just-in-time admin access if available

    Step 4: Account Lifecycle Management

    1. Configure stale account detection (e.g., 90 days inactive)
    2. Set up alerts for disabled accounts with active sessions
    3. Monitor for accounts shared between multiple people
    4. Review guest and external user access

    Step 5: Password Security

    • Monitor for leaked credentials
    • Enforce password complexity requirements
    • Track password age and rotation
    • Identify users with commonly-used passwords

    Best Practices

    • Enforce MFA for 100% of users
    • Use phishing-resistant MFA (hardware keys, passkeys)
    • Implement least privilege access
    • Conduct quarterly access reviews

    Need more help?

    Our support team is here to assist you with any questions.

    Contact Support