Skip to main content

Introduction to Identity Resiliency: Behavioral Insights and Guided Recovery

Use this article to get started with Identity Resiliency for Okta, Microsoft Entra ID, and Microsoft Active Directory backed up data.

Overview

Identity Resiliency in Druva provides Behavioural Insights and guided recovery tools to investigate compromised identities, determine the blast radius of an attack, and restore identities to a known-good state. The feature is purpose-built for environments where attackers gain access through legitimate credentials, phishing, token theft, MFA fatigue, or password spraying rather than exploiting vulnerabilities.

Identity Resiliency includes two capabilities:

  • Identity Behavioral Insights: Analyze a specific suspicious identity activity over a time window. Druva maps activity events to MITRE Tactics, Techniques, and Procedures (TTPs), shows what objects changed, created and deleted, and visualizes how the compromise propagated across users, groups, roles, applications, and policies. For more information, see Create an identity activity analysis for the required identity provider and Review the identity activity analysis results to take appropriate corrective actions.

  • Guided Recovery Plan: From the identity activity analysis results, generate a guided recovery plan and restore selected identities and their configurations to a clean pre-compromise state. For more information, see Build a guided recovery plan.

    You can track and download recovery results from the Cyber Resiliency > Identity Resiliency > Recovery Jobs page. For more information, see Monitor recovery jobs.

Access Path for Identity Resiliency: Behavioral Insights and Guided Recovery

To access this feature, from the Druva Cloud Platform Console, go to the Global Navigation menu > Cyber Resiliency > Identity Resiliency. You will be redirected to the Identity Behavioral Insights page.

Here's a quick product tour that helps you get started with the Identity Resiliency: Behavioral Insights and Guided Recovery feature.

Supported Identity Providers

  • Microsoft Entra ID

  • Microsoft Active Directory

  • Okta

The Identity Provider selector on the New Analysis page shows only the providers your tenant has connected. If a provider is missing, confirm the workload integration is active in Druva.

Licensing Requirements for Identity Resiliency

To access Identity Resiliency feature, customers must possess an Identity workload license. We have introduced a new Identity ARR SKU, to be purchased separately as a standalone offering or as a bundle. Contact your Account Manager or raise a case via Dru Assist to enable this feature.

Required Roles

Role

Access

Cloud Admin

Full access. Create analyses, generate and execute recovery plans, view and download recovery jobs.

Cloud Admin (Read-only)

Investigative access. view analyses, activity results, and recovery jobs; cannot create or execute recovery plans

How to use this feature?

Pre-requisites

  • Data protection must be enabled for the supported and configured identity providers

  • Backup must be successfully completed and snapshots available for Identity Behavioral Insights

  • To access Identity Resiliency feature, customers must possess an Identity workload license. We have introduced a new Identity ARR SKU, to be purchased separately as a standalone offering or as a bundle. Contact your Account Manager or raise a case via Dru Assist to enable this feature.

Once you have verified the above pre-requisites are met, start using this feature.

It is a simple three step workflow:

Step 1: Define the Scope

Before you can respond to a threat, you need to pinpoint exactly what you are dealing with.

  • Identify the target: Select the specific user account or service principal account/NHI that is exhibiting suspicious behavior.

  • Set a time window: Narrow the investigation to a specific date/time range so you can focus purely on the suspicious events.

For more information, see Create an identity activity analysis for the required identity provider.

Step 2: Investigate

With your scope narrowed down, you can dig into the details to understand how serious the issue is and how it happened.

  • Review what happened: Look at the recent actions taken by that account.

  • Check the impact: Review all impacted identity objects (permissions, or configurations) that the identity interacted with during the defined timeframe.

  • Understand the attack pattern: Map suspicious behavior to known attacker techniques using the industry-standard MITRE Tactics, Techniques, and Procedures (TTPs) to understand the attacker’s likely objectives and actions.

Step 3: Resolve

The last step is about fixing the problem and getting things back to normal safely.

  • Build a guided recovery plan: Based on everything you found during the investigation, get a clear, ready-to-follow plan.

  • Restore and recover: Restore the selected impacted objects by compromised identity, eliminating the attackers persistence and the compromised identity itself back to a known, trusted state, ensuring business continuity.

For more information, see Build a guided recovery plan and Monitor recovery jobs.


💡Tip: You can view the existing or historical created Identity Activity Analyses from Cyber Resiliency > Identity Resiliency > Identity Behavioural Insights > Recent Analyses section.


Next Step

Did this answer your question?