Most organisations do not know, because they have never tested it. A configuration review confirms your identity platform is set up the way the vendor intended. It does not tell you whether an attacker who already holds a valid credential can escalate privilege, move laterally, and stay in your environment undetected.
Would your identity controls stop a real attack?
What is identity assurance?
Identity assurance is the practice of testing whether identity and access controls hold up under realistic attack conditions, rather than confirming they are configured correctly. It covers authentication, privileged access, detection, and identity infrastructure, and it produces evidence of exploitable paths rather than a settings report.
Is this the same as identity assurance levels?
No. The term is also used in identity proofing to describe confidence that a person is who they claim to be, expressed as assurance levels in standards such as the NIST digital identity guidelines. That usage concerns verifying an identity at the point of enrolment or authentication. The meaning on this page concerns testing whether the controls protecting those identities can be defeated.
How identity attacks actually unfold
Privilege escalation
Lateral movement
Undetected persistence
Without tested detection, access is held for weeks or months before anyone notices.
Why configuration reviews miss identity risk
Stolen credentials remain a major factor in identity-related attacks, but the real issue is not whether credentials can be compromised. It is what an attacker can do next once valid access has been obtained. A configuration review answers a settings question: is this control switched on and configured correctly? It cannot answer the operational question, which is whether the control holds when a real attacker works around it.
The gap shows up in three ways:
- A control can be correctly configured and still be by-passable in practice
- Fragmented IAM and PAM estates create escalation paths no single review covers
- Detection is assumed to work because it has never been tested against a live attempt
What identity assurance testing involves
Identity assurance testing applies real-world offensive techniques to your identity controls under adversarial conditions, then works collaboratively with your team to confirm what was detected and what was missed. The objective is evidence of what is exploitable, rather than a list of what is misconfigured. Intragen delivers this with Dionach, combining offensive testing with identity remediation expertise.
testing covers four domains:
- Authentication controls
- Privilege and access governance
- Detection and response
- Identity infrastructure
What each domain covers, and how the packaged tiers differ, is set out on the assessment page. Explore the Identity Assurance assessment.
How does this differ from a penetration test?
A conventional penetration test looks for a way in. Identity assurance testing assumes the attacker is already in, holding a valid credential, and tests what happens next. The distinction determines what each approach can find.
| Criterion | Configuration review | Penetration test | Identity assurance testing |
|---|---|---|---|
| Core question | Is it set up correctly? | Can someone get in? | What happens once they are in? |
| Starting position | Documentation and settings | Outside the perimeter | Holding a valid credential |
| Identity focus | Settings only | Incidental | Primary |
| Detection tested | No | Sometimes | Yes, with whoever handles your detection |
| Typical finding | Misconfiguration | Vulnerability | Exploitable identity path |
Is a vendor health check enough?
A vendor health check can confirm whether one platform is configured against recommended settings. Identity assurance testing looks across the wider identity estate and tests whether controls can withstand realistic attack techniques, including chained weaknesses across platforms, privileges, users, and detection processes.
Intragen's Identity Assurance service applies this approach in packaged engagements. See what an assessment covers →
Do you need identity assurance testing?
The test is simple. If your identity controls have never been challenged by someone trying to defeat them, you have documentation rather than evidence. Five statements to check against your own environment:
- Your identity platform has been reviewed for configuration but never attacked
- You cannot say with evidence whether MFA can be bypassed in your environment
- You do not know whether a credential-based attack in progress would be detected, or by whom
- Privileged access spans more than one platform, with no single owner of the escalation risk
- An auditor or regulator has asked how control effectiveness is verified, and the answer referenced configuration
Recognising three or more is common, including in organisations with mature identity programmes.
Trusted by organisations across Europe
Ready to see what an assessment covers?
Intragen’s Identity Assurance assessment tests your identity controls under realistic attack conditions and provides evidence-based findings, remediation priorities, and board-ready reporting.
Frequently asked questions
The entry-level package takes approximately two weeks. Packaged tiers mean there is no lengthy scoping exercise before testing begins.
Scope, timing, and techniques are agreed with your team before testing begins, and the engagement is run collaboratively rather than as a covert exercise. Techniques that could affect availability are agreed in advance or excluded.
No. A dedicated security operations centre is not required. Detection testing works with whatever arrangement you have, whether that is an in-house team, an outsourced provider, or alerting reviewed by your IT function.
No lengthy scoping exercise is needed before an initial conversation. Identity Assurance is delivered through packaged tiers, with light scoping used to agree rules of engagement, tailor testing to your environment and confirm access before testing begins.
Intragen delivers the service with Dionach, combining offensive testing expertise with identity remediation experience. The engagement is scoped, managed, and reported by Intragen.