Join our Newsletter — 33% off our NHI Course
Home› Guides› Identity Security Posture Management (ISPM) Guide
Guide Identity Visibility, Posture & Threat Detection

Identity Security Posture Management (ISPM) Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 4 min read
On this page

Most identity breaches exploit weaknesses that already existed: an admin without MFA, a dormant account that still works, a service account with owner rights, an app registration with a forgotten secret, a policy with an exception nobody remembers. Identity security posture management (ISPM) is the practice, and increasingly the product category, of continuously finding and fixing those weaknesses across identity providers, directories, cloud, SaaS and non-human identities before attackers use them. This guide explains what ISPM covers, the most important posture checks, how to prioritise findings and how to run ISPM as an ongoing programme.

Key takeaways

  • ISPM is to identity what cloud security posture management is to cloud: continuous assessment of configuration and hygiene, with prioritised remediation.
  • Cover identity infrastructure configuration (IdPs, directories, federation), account hygiene (MFA, dormancy, privilege) and non-human identities (credentials, permissions, ownership).
  • Prioritise by exploitability and blast radius: privileged identities and attack paths to tier zero first.
  • Posture only improves if findings reach owners with deadlines and are verified as fixed.

What ISPM assesses

AreaExample checks
AuthenticationMFA coverage; phishing-resistant MFA for admins; legacy authentication enabled; weak recovery options
PrivilegeNumber of standing admins; privileged accounts without just-in-time; privileged accounts used for daily work; nested group privilege
Account hygieneDormant accounts; leavers still active; shared accounts; accounts with non-expiring passwords
IdP and directory configurationRisky tenant settings; conditional access gaps and exclusions; federation trusts; delegation and certificate template weaknesses
Applications and OAuthUser consent settings; high-privilege app permissions; apps with long-lived secrets; unowned app registrations
Non-human identitiesService accounts with admin rights; stale access keys; unused permissions; secrets outside vaults; missing owners
Attack pathsChains of permissions that lead from ordinary accounts to tier-zero control
SaaS configurationAdmin counts, MFA enforcement and sharing settings in key SaaS platforms

Prioritising findings

ISPM tools can produce thousands of findings. Prioritise with:

  • Privilege: findings on privileged or tier-zero identities first.
  • Exposure: internet-reachable, externally federated or third-party-connected identities.
  • Exploitability: known active attack techniques, such as MFA gaps, Kerberoastable accounts and consent phishing exposure.
  • Attack paths: weaknesses that form part of a route to high-value assets.
  • Data sensitivity of the systems the identity can reach.

Common high-value fixes

  • Enforce phishing-resistant MFA for all administrators. See the Passwordless and Passkeys Guide.
  • Block legacy authentication protocols.
  • Reduce standing Global Administrators and Domain Admins; enable just-in-time elevation. See the JIT Access Guide.
  • Disable dormant and leaver accounts.
  • Remove service accounts from privileged groups and rotate old credentials. See the Service Account Security Guide.
  • Restrict user consent to OAuth apps and remove high-risk unused apps. See the SaaS and OAuth App Governance Guide.
  • Close conditional access exclusions that are no longer needed.

Running ISPM as a programme

  1. Baseline: assess all identity systems and publish a posture score or set of key metrics.
  2. Assign: route findings to the owners of each system and identity, with severity-based deadlines.
  3. Remediate: fix high-severity items first; use automation for safe, repeatable fixes.
  4. Prevent drift: detect new misconfigurations as they occur; add guardrails in policy and infrastructure-as-code.
  5. Report: track posture trends for leadership. See the Identity Security Metrics Guide.

ISPM, IVIP and ITDR

  • ISPM finds weaknesses before they are exploited.
  • ITDR detects exploitation in progress. See the ITDR Guide.
  • IVIP provides the unified identity data both rely on. See What Is IVIP?

Many products combine two or three of these. What matters is that posture findings, detections and identity context feed each other.

Practitioner checklist

  • Define the identity systems in scope, including SaaS and NHI sources.
  • Run a baseline posture assessment and agree key metrics.
  • Prioritise by privilege, exposure, exploitability and attack paths.
  • Route findings to owners with deadlines and verify fixes.
  • Monitor continuously for configuration drift.
  • Connect posture findings with ITDR and governance processes.

Standards and references

Related NHI Mgmt Group resources: IVIP and ISPM Buyer's Guide · Active Directory and Entra ID Hardening Guide · IdP and SSO Security Guide · Top 10 NHI Issues

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org