Overview
Identity Resiliency in Druva provides Behavioural Insights and guided recovery tools to investigate compromised identities, determine the blast radius of an attack, and restore identities to a known-good state. The feature is purpose-built for environments where attackers gain access through legitimate credentials, phishing, token theft, MFA fatigue, or password spraying rather than exploiting vulnerabilities.
Identity Resiliency includes two capabilities:
Identity Behavioral Insights: Analyze a specific suspicious identity activity over a time window. Druva maps activity events to MITRE Tactics, Techniques, and Procedures (TTPs), shows what objects changed, created and deleted, and visualizes how the compromise propagated across users, groups, roles, applications, and policies. For more information, see Create an identity activity analysis for the required identity provider and Review the identity activity analysis results to take appropriate corrective actions.
Guided Recovery Plan: From the identity activity analysis results, generate a guided recovery plan and restore selected identities and their configurations to a clean pre-compromise state. For more information, see Build a guided recovery plan.
You can track and download recovery results from the Cyber Resiliency > Identity Resiliency > Recovery Jobs page. For more information, see Monitor recovery jobs.
Access Path for Identity Resiliency: Behavioral Insights and Guided Recovery
To access this feature, from the Druva Cloud Platform Console, go to the Global Navigation menu > Cyber Resiliency > Identity Resiliency. You will be redirected to the Identity Behavioral Insights page.
Here's a quick product tour that helps you get started with the Identity Resiliency: Behavioral Insights and Guided Recovery feature.
Supported Identity Providers
Microsoft Entra ID
Microsoft Active Directory
Okta
The Identity Provider selector on the New Analysis page shows only the providers your tenant has connected. If a provider is missing, confirm the workload integration is active in Druva.
Licensing Requirements for Identity Resiliency
To access Identity Resiliency feature, customers must possess an Identity workload license. We have introduced a new Identity ARR SKU, to be purchased separately as a standalone offering or as a bundle. Contact your Account Manager or raise a case via Dru Assist to enable this feature.
Required Roles
Role | Access |
Cloud Admin | Full access. Create analyses, generate and execute recovery plans, view and download recovery jobs. |
Cloud Admin (Read-only) | Investigative access. view analyses, activity results, and recovery jobs; cannot create or execute recovery plans |
How to use this feature?
Pre-requisites
Data protection must be enabled for the supported and configured identity providers
Backup must be successfully completed and snapshots available for Identity Behavioral Insights
To access Identity Resiliency feature, customers must possess an Identity workload license. We have introduced a new Identity ARR SKU, to be purchased separately as a standalone offering or as a bundle. Contact your Account Manager or raise a case via Dru Assist to enable this feature.
Once you have verified the above pre-requisites are met, start using this feature.
It is a simple three step workflow:
Step 1: Define the Scope
Before you can respond to a threat, you need to pinpoint exactly what you are dealing with.
Identify the target: Select the specific user account or service principal account/NHI that is exhibiting suspicious behavior.
Set a time window: Narrow the investigation to a specific date/time range so you can focus purely on the suspicious events.
For more information, see Create an identity activity analysis for the required identity provider.
Step 2: Investigate
With your scope narrowed down, you can dig into the details to understand how serious the issue is and how it happened.
Review what happened: Look at the recent actions taken by that account.
Check the impact: Review all impacted identity objects (permissions, or configurations) that the identity interacted with during the defined timeframe.
Understand the attack pattern: Map suspicious behavior to known attacker techniques using the industry-standard MITRE Tactics, Techniques, and Procedures (TTPs) to understand the attacker’s likely objectives and actions.
For more information, see Review the identity activity analysis results.
Step 3: Resolve
The last step is about fixing the problem and getting things back to normal safely.
Build a guided recovery plan: Based on everything you found during the investigation, get a clear, ready-to-follow plan.
Restore and recover: Restore the selected impacted objects by compromised identity, eliminating the attackers persistence and the compromised identity itself back to a known, trusted state, ensuring business continuity.
For more information, see Build a guided recovery plan and Monitor recovery jobs.
💡Tip: You can view the existing or historical created Identity Activity Analyses from Cyber Resiliency > Identity Resiliency > Identity Behavioural Insights > Recent Analyses section.
Next Step
Create an identity activity analysis for the required identity provider
Monitor recovery jobs for the identity providers
Track and monitor all the Identity Resiliency activities from Audit Trails and Alerts.
