test your identity defences before attackers do

Would your identity controls survive a real attack?

Most organisations assume their identity controls work. Identity Assurance tests them under real-world attack conditions, showing what is genuinely exploitable across authentication, privilege, access governance, detection and identity infrastructure.

950x650 - Identity Assurance banner image
Why it matters

Why testing identity controls matters

Most identity controls are configured once and never validated again. They are set up during a project, then left in place for years while the environment changes around them: new joiners, new applications, new integrations, and quiet configuration drift.

Attackers, meanwhile, target identity directly, because valid access is easier to abuse than a firewall is to breach. A control that looks correct in the console can still be exploitable in practice, whether through an over-privileged account, a weak recovery path, or a gap between your IAM and PAM tooling. Until the controls are tested under real attack conditions, those gaps stay invisible, and the first time a failed control shows itself should not be during an incident.

Read: Your Identity Controls Have Never Been Tested, and Here’s Why It Matters →

Start your Identity Assurance journey

Fill out the form below and our team of specialists will be in touch.

Delivered by Intragen with Dionach

What is Identity Assurance?

Identity Assurance is a focused assessment that tests whether your identity controls hold up under real-world attack conditions, from authentication and privileged access through to detection, response and identity infrastructure. It goes beyond a configuration review or a compliance checklist. Rather than asking whether a control exists, it asks whether that control would actually stop an attacker.

Delivered by Intragen and Dionach, the assessment simulates real threat-actor techniques through a collaborative purple team approach, working alongside your teams and SOC. The result is a clear line between a theoretical gap and a real, exploitable path into your environment.

Assessment scope

What we test

Authentication controls

MFA bypass, token theft, SSO weaknesses, conditional access gaps.

Privilege and access governance

Escalation paths, excessive entitlements, JML weaknesses, just-in-time controls.

Detection and response

SOC alerting, anomaly detection, session monitoring and incident response.

Identity infrastructure

Directory security, federation trust, service accounts and non-human identities.

Attack progression

Credential compromise, privilege escalation, lateral movement, persistence and exfiltration depending on scope.

Deliverables

What you get

The assessment gives you clarity on your real identity risk: not assumptions, not checkbox compliance, but evidence. You will get:

A prioritised view of where your identity controls are genuinely exploitable, ranked by real risk rather than theoretical severity.

The specific attack paths that work today, demonstrated against your environment rather than assumed.

Validation of whether your SOC detection actually triggers when those paths are used.

Clear, practical remediation guidance, with defined effort and indicative cost for each fix.

Board-ready evidence you can take to auditors and risk committees.

Specialist focus

Why Intragen

Intragen is an identity security specialist, not a generalist consultancy with identity added to a long list of services.

Our focus is backed by recognised partner status, independent accreditation, and practical experience across IAM, PAM, IGA, and access management. With Identity Assurance, we combine that expertise with offensive testing to give you evidence of what is exploitable, what needs fixing, and how to prioritise remediation.

Okta Apex Partner.

One Identity Platinum Premier+ Partner, a status held by only two other partners.

Palo Alto Networks identity security partner.

Certified to ISO 27001, holder of Cyber Essentials, and an approved G-Cloud supplier.

Trusted by regulated organisations across the UK and Europe, including The Australian Football League and Laurea University.

Your Identity Assurance questions answered

Identity Assurance is a focused, collaborative assessment, delivered by Intragen with Dionach, that tests whether your identity controls hold up under real-world attack conditions and identifies what is genuinely exploitable. Rather than checking whether a control exists, it uses real offensive techniques to establish whether that control would actually stop an attacker, across authentication, privileged access, access governance, detection and response, and identity infrastructure.

A penetration test looks broadly across your environment; Identity Assurance focuses specifically on your identity and access controls and whether they would withstand a real attack. A conditional access policy can be correctly configured and still be bypassed through token theft; MFA can be in place and still be defeated by session hijacking; role assignments can follow documented procedure and still create privilege escalation paths. Identity Assurance finds those exploitable paths and ties each one to clear remediation.

A vendor health check confirms what is set; Identity Assurance shows what is exploitable. Configuration reviews and vendor health checks tell you whether a product is configured to best practice, but not whether an attacker could still get through. Identity Assurance tests your controls with real-world offensive techniques, across your whole identity estate rather than a single tool, so you get evidence instead of assumption.
The Identity Assurance assessment covers identity controls across authentication, privileged access, access governance, detection and response, and identity infrastructure. Depending on scope, this may include MFA, SSO, conditional access, privilege escalation paths, JML processes, service accounts, federation trust, non-human identities and SOC detection.
No - a security operations centre is not a prerequisite. If you have SOC or detection capability, the assessment also validates whether it actually triggers when identity attack paths are used; if you don't, the testing of your identity and access controls still applies in full. The scope adjusts to the controls you have in place.

You receive a prioritised, evidence-based view of where your identity controls are genuinely exploitable (ranked by real risk), the specific attack paths that work against your environment, validation of whether your SOC detection triggers, practical remediation guidance with defined effort and indicative cost per fix, and board-ready evidence you can take to auditors and risk committees.

Identity Assurance is a tailored, packaged engagement, so the timeline depends on the size of your estate and the scenarios in scope. We agree scope and duration up front (starting with a short briefing) so there are no open-ended commitments and you know what to expect before work begins.

Identity Assurance is best suited to regulated and critical-infrastructure organisations that need assurance their identity controls actually work, not just that they exist. This is typically across financial services, healthcare, energy, technology and the public sector. It is usually commissioned by CISOs, IT security directors and compliance leads at mid-to-large European enterprises, particularly those with obligations under frameworks such as DORA and NIS2.

Get started

Find out what is genuinely exploitable in your identity controls.

Start the conversation without a lengthy scoping call.