Terminology Index

Glossary

1801 terms

Open concept maps

Showing 865-896 of 1801 terms

I
32

Identity Telemetry

The activity data generated by identity systems, sign-ins, authentication results, privilege changes, access grants, and federation events, that feeds detection, hunting, and investigation of identity-based threats.

Identity telemetry is the stream of events from authentication and access systems: successful and failed logins, MFA prompts, token issuance, role and entitlement changes, and federation activity. Because identity is a primary attack surface, this telemetry is a high-value source for detecting anomalies, hunting credential-based intrusions, and investigating incidents. Ensuring it is collected with good coverage is a foundational logging decision for identity security.

Introduced in: Logging, Monitoring, and Telemetry

Examples

  • Logging sign-in events and results for detection and investigation.
  • Capturing privilege and entitlement changes as identity telemetry.
  • Feeding federation events into anomaly detection.

No related terms linked yet.