Monitoring and enforcing identity policy
Policy on paper is not a control. How to detect credential attacks, audit access continuously, and enforce configuration automatically so drift and abuse surface fast.
What to implement
Centralize identity and authentication logs into a SIEM, build detections for credential attacks (password spray, impossible travel, MFA fatigue, legacy-auth use, new admin grants), enforce configuration with policy-as-code and conditional access so violations are blocked rather than merely logged, and run continuous access reviews. Detection plus automated enforcement is what turns written policy into an actual control.
A password policy, an MFA mandate, and an access model only matter if you can see when they're violated and stop it. Monitoring and enforcement close the loop: they catch the attacks your preventive controls miss and the drift that quietly reopens closed doors.
What to detect
- **Password spray and brute force** — many accounts hit with a few common passwords, or one account hit repeatedly; alert on failed-login spikes and lockouts.
- **Impossible travel / anomalous sign-in** — logins from two distant locations in a short window, or from unusual geographies/ASNs.
- **MFA fatigue / repeated push denials** — bursts of MFA prompts, especially followed by an approval.
- **Legacy-auth and MFA-bypass attempts** — any sign-in via a protocol that skips MFA.
- **Privilege changes** — new admin-role grants, group membership changes, service-principal credential additions, and consent grants to new apps.
- **Impossible or dormant-account activity** — sign-ins on accounts that should be disabled, or sudden use of a long-dormant account.
- **Session/token anomalies** — token replay from a new device, or session use inconsistent with the original sign-in.
Enforce, don't just observe
Detection tells you after the fact; enforcement stops it. Wherever possible, convert a policy into an automated gate.
- **Conditional access** — block or step up authentication based on risk (device compliance, location, sign-in risk score), so risky sign-ins are challenged or denied in real time.
- **Policy-as-code / configuration guardrails** — codify identity and cloud config (MFA required, no public admin, legacy auth off) and enforce/auto-remediate drift.
- **Automated response** — high-risk detections can auto-revoke sessions, force password reset, or disable an account pending review.
- **Rate-limiting and adaptive lockout** at the authentication layer.
Alert on the sign-in that succeeded, not just the ones that failed
Failed-login noise is easy; the dangerous event is the anomalous success — the login after a spray, the approval after a fatigue burst, the new-device token use. Tune detections toward successful-but-anomalous authentication, because that's the account takeover in progress.
Continuous audit
- Run **periodic access recertification** and treat un-reaffirmed access as revocable.
- Report on **standing privilege, MFA coverage, dormant accounts, and stale service principals** on a cadence.
- **Retain authentication and admin logs** long enough for investigations, and protect them from tampering.
- Feed findings back into policy — repeated exceptions usually mean the policy or the role design needs fixing.
Monitoring maturity evidence
Track: coverage of identity log sources into the SIEM, list of active detections mapped to attack techniques (e.g. MITRE ATT&CK), mean time to detect/respond for credential incidents, conditional-access enforcement coverage, config-drift auto-remediation rate, and access-recertification completion.