Capability

Identity exposure management

Directory posture read only, and correlated with the network rather than reported beside it.

Who this is for

MSPs managing customer directories

You run identity for many organizations and have no consistent read of how exposed each one is.

Internal IT after an audit finding

You have been asked about delegation, stale privilege and certificate templates and have no current answer.

The problem it addresses

Identity findings are usually produced by a separate tool and read on their own. An over-privileged service account is a moderate finding in isolation; the same account running an internet-reachable service is the first hop of a route. Nothing joins the two when identity lives in its own report.

How Exploit Hound handles it

  • 1
    Read-only, and gated behind written authorization

    Assessment is read-only LDAP, read-only Microsoft Graph and the read-only Google Admin SDK. Assets must be marked authorized before anything is assessed.

  • 2
    Access is made as an administrator you nominate

    For Google Workspace, every read is made through domain-wide delegation you add and revoke in your own Admin console, and appears in your audit log under that name.

  • 3
    Unassessed is reported as unassessed

    Where a scope needed to read an area is not granted, the area is reported as unassessed rather than as clean.

  • 4
    Identity joins the same graph

    Accounts, groups and privilege become nodes and edges alongside assets and services, so an identity weakness is visible as part of a route rather than as a separate list.

What the result rests on

  • 21 read-only Active Directory posture checks, from delegation to certificate templates
  • Microsoft Graph reads for Entra ID and Microsoft 365 exposure
  • Google Admin SDK reads for Workspace, with third-party application grants optional and reported as unassessed when not granted
  • Group membership and privilege relationships as edges in the exposure graph

The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.

What is generally available, and what is Beta

Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.

CapabilityStatusNotes
Exposure graphGenerally Available
Attack paths and choke pointsGenerally Available
Active Directory exposureBetaBeta — no live directory assessed
Entra ID / Microsoft 365 exposureBetaBeta — Graph payload mapping unproven
Google Workspace exposureBetaBeta — built 18 August 2026
Single sign-on (OpenID Connect)BetaOpenID Connect authorization code flow with PKCE. SAML and SCIM provisioning are not implemented. An email address is unique across a deployment, so one address cannot hold accounts in two tenants.

In the console

sniff.exploithound.com/admin/integrations/entraDemonstration data · v2.58.16
Identity exposure in the Exploit Hound console: directory posture findings correlated with the assets and services they affect

The interface is the running application. The data in it is invented — every hostname, finding and customer name shown is fabricated for demonstration, and none of it describes a real estate. The full product tour walks every screen.

See it against your own estate

A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.

Request a guided evaluation Pricing Trust Center Integration status Product tour

v2.58.16 Exploit Hound 2.58.16 · Continuous Threat Exposure Management