Get Started with ETM Identity

ETM Identity helps organizations identify identity-related risks, monitor their security, and take steps to prevent threats. It is an integral part of a zero-trust security approach, which considers identities the main defense line.

Prerequisites

  • ETM License
  • ETM Identity License 
  • VM, PA application subscription
  • Active Directory–specific policies and controls need to be configured in the Policy Audit application (optional).

ETM Identity Setup Journey

The following section provides an overview of the ETM Identity setup journey.

Your setup path depends on the identity platform you connect. Start by determining which identity platform you want to connect: Active Directory (AD), Microsoft Entra ID, Okta, or a combination of these platforms.

ETM Identity supports two connection methods:

  • Agent: Use for Active Directory only. This is the recommended method. However, it cannot be used if organizational policies prevent software installation on domain controllers.
  • Connector: Use for Microsoft Entra ID and Okta. You can also use a connector for Active Directory if agent installation is not permitted.

Step 1: Connect your identity platform

Find your path in the table below. Each row covers everything you need for that platform:

Platform Connection method Setup steps Special notes What you'll see after setup
Active Directory (AD) Agent (recommended)

Connector (alternative): Use if your enterprise policy blocks agent installation
Agent:

1. Install the ETM Identity Agent (Windows Agent 6.4.0) on the Domain Controller. To know more details on how to install the agent, refer to Cloud Agent Online Help.

2. Activate ETM Identity in the Cloud Agent UI.

Connector:
Follow the steps in Active Directory Connector Setup.
Agent: Install only on primary domain controllers, not every controller. If you are unsure which are primary, check with your AD administrator.

Connector: No special notes.
Agent: Your first scan starts as soon as you activate the agent. The UI can take a few hours to fully update; refresh periodically.


Connector: Allow 15–20 minutes for the connector to move from processing to a processed state.
Microsoft Entra ID Connector Connect your Entra ID tenant to ETM Identity using a connector.

Follow the steps in Microsoft Entra ID Connector Setup.

Allow approximately 15 to 20 minutes for initial data processing.

Okta Connector Connect your Okta tenant to ETM Identity using a connector.

Follow the steps in Okta Connector Setup.

Allow approximately 15 to 20 minutes for initial data processing.

Step 2: Activate ETM Identity 

Complete the activation steps that apply to your setup:

  • Agent (AD): Open the Cloud Agent UI and activate ETM Identity for the domain controller.  Refer to the Cloud Agent Online Help. 
  • Connector (AD, Entra ID, or Okta): ETM Identity is activated automatically after connector processing is complete.
  • For non-UAI customers (any platform): Complete the Export/Import Configuration step before you continue. This step is mandatory. If it is not completed, Asset Criticality Scores and TruRisk™ scores will not be available.
    Navigate to the Export/Import Configuration tab and complete this step as part of onboarding, before you move to the next steps.

Step 3: Access ETM Identity in ETM as Cyber Risk Posture Management

  1. Log in to the ETM application.
  2. Navigate to the Cyber Risk Posture Management section where the ETM Identity is available.
  3. Once activated, the default ETM Identity dashboard is visible.

Step 4: View Asset Inventory

The inventory section shows server assets where Active Directory services are installed. For Microsoft Entra ID or Okta deployments, inventory data is limited to identity assets collected through the configured connector. The inventory data may differ from Active Directory-based inventory views.

Non-Windows servers do not appear in the inventory.

Step 5: Monitor Risks Automatically

After installing an Agent, the user interface may take several hours to update. Refresh your browser periodically to ensure you see the most up-to-date details. The first scan starts as soon as the ETM Identity module is activated on the agent. 

  • ETM Identity scans every 4 hours by default (customizable).
  • Vulnerabilities are detected from both AD and server assets. Vulnerabilities identified by the agent during scans provide an accurate view of the target environment.
  • Misconfigurations are identified from AD only. Misconfigurations are based on policies and controls configured in the Policy Audit application.

Step 6: View Attack Path Analysis

  • Use the Attack Path Analysis feature to visualize potential attack routes.
  • Follow remediation instructions to mitigate risks.