Identity Intelligence
AI-driven analytics that expose identity risk and attacks across your providers.
Cisco Identity Intelligence applies AI-driven analytics across your identity providers to expose risky, unused, and misconfigured accounts and to detect identity-based attacks that slip past point tools. It builds a unified graph of users, devices, and access, then surfaces the identity risk and anomalous behaviour that lead to breaches. Faltrox operates it as the identity-analytics layer of your detection and zero-trust programme.
Overview
What Identity Intelligence is
Identity is the new perimeter, and attackers increasingly log in rather than break in — using valid but compromised or over-privileged accounts. Cisco Identity Intelligence sits across your identity providers (Entra ID, Okta, Active Directory, and more) and applies AI-driven analytics to expose the identity risk and attacks that individual tools miss.
It builds a unified graph of identities, devices, and access relationships, then continuously analyses it to surface risky posture — dormant accounts, excessive privilege, missing MFA, misconfiguration — and to detect anomalous, identity-based attack behaviour in real time. It integrates with Duo, ISE, and the Cisco security stack to feed access decisions and detection, turning identity into a source of both hardening and threat detection. Faltrox operates it, tunes the analytics to your environment, and acts on the findings.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Identity Providers
Analyses identities across Entra ID, Okta, Active Directory, and other providers.
Risky & Dormant Accounts
Surfaces over-privileged, unused, and orphaned accounts that widen the attack surface.
Identity Attacks
Detects anomalous, identity-based attack behaviour that point tools miss.
Access Relationships
Maps who can access what across a unified identity-and-access graph.
Misconfiguration
Flags missing MFA, weak policy, and misconfiguration that create identity risk.
Cisco Security Stack
Feeds Duo, ISE, and detection so identity risk informs access and response.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Connect
Identity Intelligence connects to your identity providers and the Cisco security stack via APIs.
- 02
Graph
It builds a unified graph of identities, devices, and access relationships across the environment.
- 03
Analyse
AI-driven analytics continuously assess the graph for risky posture and anomalous, identity-based behaviour.
- 04
Surface
It surfaces risky accounts, misconfiguration, and identity attacks with the context needed to act.
- 05
Act
Findings feed Duo, ISE, and detection, and Faltrox acts on them to harden identity and drive response.
Capabilities
Key capabilities
Multi-Provider Analytics
Analyses identities across Entra ID, Okta, Active Directory, and other identity providers.
Unified Identity Graph
Builds a single graph of users, devices, and access relationships across the environment.
Identity Risk Posture
Surfaces dormant, over-privileged, and orphaned accounts and missing MFA that widen exposure.
Attack Detection
Detects anomalous, identity-based attack behaviour that individual tools miss.
Misconfiguration Detection
Flags weak policy and misconfiguration in identity providers before they are exploited.
AI-Driven Analytics
Machine learning continuously assesses the identity graph for risk and anomaly.
Cisco Stack Integration
Feeds Duo, ISE, and detection so identity risk informs access decisions and response.
Actionable Context
Presents findings with the context needed to remediate posture and investigate attacks.
Works with
Part of the platform
Cisco products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Cisco Identity Intelligence for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What problem does Identity Intelligence solve?
Attackers increasingly log in with valid but compromised or over-privileged accounts rather than exploiting software. Identity Intelligence exposes that identity risk — dormant accounts, excessive privilege, missing MFA, misconfiguration — and detects identity-based attacks that point tools miss, across all your identity providers at once.
02Which identity providers does it cover?
It analyses identities across multiple providers — Entra ID, Okta, Active Directory, and others — building one unified graph, so you see identity risk across the whole environment rather than provider by provider.
03Is it hardening or threat detection?
Both. It surfaces risky identity posture to harden proactively (over-privilege, dormant accounts, missing MFA), and it detects anomalous, identity-based attack behaviour in real time — turning identity into a source of both prevention and detection.
04How does it work with Duo and ISE?
It integrates with Duo, ISE, and the wider Cisco security stack, feeding identity risk into access decisions and detection — so a risky identity can drive stronger authentication, restricted network access, or an investigation. Faltrox wires these together.
05How does Faltrox operate it?
We connect it to your identity providers and security stack, tune the analytics to your environment, triage the findings, and act on them — hardening identity posture and feeding identity-based detections into the SOC services we run.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us