ETM Identity Release 1.4.0 

August 04, 2026

AI-Powered Attack Path Overview

We have introduced AI-Powered Attack Path Overview to provide contextual and actionable insights for attack paths identified within ETM Identity.

This feature uses Amazon Bedrock to summarize attack paths automatically. Security teams can quickly understand risks and investigate suspicious activity.

Key benefits are:

  • Faster understanding of complex attack paths
  • Simplified investigation of suspicious identities and relationships
  • Reduced analyst effort through automated AI-generated explanations
  • Contextual visibility into attack progression from source identity to privileged target assets

How It Works

When viewing an attack path, users can select AI Overview to generate an attack path summary.

The AI Overview provides:

  • A concise summary of the selected attack path
  • Detailed information about suspicious hops and relationships
  • Descriptions of attack path transitions and privilege escalation opportunities
  • A direct link to the attack path for additional investigation

Attack Path Context

The AI summary is generated specifically for the selected source-to-destination attack path.

The analysis includes:

  • Source identity context
  • Intermediate suspicious users, groups, and permissions
  • Target privileged asset or account
  • Attack path progression and risk explanation

Dynamic AI-Based Analysis

The attack path summary is generated in real time whenever the AI Overview is requested. This ensures the latest attack path information is always reflected in the generated analysis.

Domain Trust Findings

We have introduced Domain Trust Findings to help identify misconfigurations in the Domain Trust Map (DTM).

Previously, suspicious nodes and edges identified within DTM were visible only within the domain trust map visualization. With this enhancement, suspicious relationships now appear as findings, making them easier to investigate and track.

View DTM feature.

Key benefits are:

  • Centralized visibility of DTM-related risks
  • Consistent findings experience across ETM Identity
  • Easier prioritization of domain trust misconfigurations
  • Improved tracking of suspicious trust relationships

Finding Generation

Domain Trust Findings are generated for:

  • Suspicious domain trust relationships
  • Suspicious nodes identified during DTM analysis
  • Suspicious edges associated with DTM attack paths
  • Rule-based detections associated with domain trust configurations

Automated Evaluation

Domain Trust Findings are automatically generated through:

  • Scheduled rule evaluation
  • End-of-scan processing
  • Domain trust map updates

Rule-Based Detection Framework

This enhancement uses the existing DTM rule framework and adds support for findings generation without changing the current workflow.

Risk Factor Insights for Identity Weaknesses

We have extended support for Risk Factor Insights to help organizations measure and prioritize identity risks with ETM risk scoring. 

Risk Factors allow security teams to identify the impact of multiple identity weaknesses and misconfigurations on TruRisk™ scores. This provides a more accurate view of the business risks.

To view this widget, navigate to Dashboard > TruRisk of Identities.

TruRisk of Identities widget with Top Risk Factors (UAI-Enabled Accounts):

For UAI-enabled accounts, the widget shows the top risk factors that affect the TruRisk score. It also links directly to related findings.

TruRisk of Identities widget for accounts where UAI is not enabled:

Risk Factor Insights are not displayed for accounts without UAI enabled.

Key benefits of Risk Factor Insights are:

  • View identity risk across your Active Directory assets through a single TruRisk™ score
  • See how misconfigurations, authentication gaps, and account hygiene issues affect risk
  • Quickly identify the highest risk factors and prioritize remediation
  • Apply risk scoring to specific assets, asset groups, or business entities

 

Key capabilities of Risk Factor Insights include:

  • Define risk factors for specific assets or asset groups
  • Include identity misconfigurations, authentication gaps, and account management risks in risk calculations
  • Incorporate existing findings into TruRisk™ scoring
  • Customize risk views using business entities and organizational requirements
  • Configure risk using point, percentage, or severity-based scoring

Introduced Tag-Based Scoping in Role-Based Access Control (RBAC)

We enhanced ETM Identity Role-Based Access Control (RBAC) with tag-based scoping. You can control access to identity assets and findings based on assigned tags. This allows users to view only the data that falls within their authorized scope.

How Tag-Based Scoping Works

Example: If a user is assigned the tag Department = Finance, they can view only assets associated with the Finance tag.

  • Users can access assets that match their assigned tags
  • Assets outside the assigned scope are not visible
  • Supports both static and dynamic tagging approaches
  • Helps organizations implement business-unit-specific access controls

 

Key benefits of tag-based scoping are: 

  • Limit visibility to authorized identity assets and findings
  • Segregate access across teams, departments, and business units
  • Apply more granular access controls within ETM Identity

  • Simplify access management in large and distributed environments

With tag-based scoping, administrators can define access boundaries using tags. This ensures that users can access only the assets and data associated with their assigned scope.

Tenant Attributes

Tenant-related attributes can be used as part of RBAC implementations and tag-based scoping workflows.

Supported tenant attributes include:

  • Tenant ID
  • Tenant Name

Integration Behavior

Integration Behavior
Active Directory (AD) Each Active Directory domain belongs to a single tenant and can contain multiple users and groups. Tenant information can be used in dynamic tagging workflows. 

 

Microsoft Entra ID Tenant Name and Tenant Domain may contain different values.
AD Agent Tenant Name and Tenant Domain are generally identical.
Okta Tenant-level support is currently unavailable.

Issues Addressed

There are no notable customer issues in this release.