Back to Field Notes
Identity & Access/Field Note

Alexa Research — Mapping the Identity Attack Surface

An honest map of your identity attack surface is usually surprising. Here is how to build one — and what we found.

Author

Yusuf Ahmed

Principal Engineer, Platform Security

Published

March 21, 2026

Read

10 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01Most enterprises have a partial view of their identity attack surface. Human identities are well-understood; workload identities less so; AI agent identities barely understood at all. Alexa Research developed a methodology for a unified view.
  • 02Methodology: enumerate every identity provider (workforce, customer, B2B, machine), every authoritative source (HR, vendor master, CMDB, cloud IAMs), every authentication path (federation, brokering, trust, peering), every elevation path (JIT, role assumption, service-account chaining), every recovery path (password reset, MFA reset, IdP recovery).
  • 03What we consistently find: 3-5 identity providers in active use, multiple authoritative sources that disagree on basic facts, federation paths no one remembers configuring, recovery paths weaker than primary authentication. Each is a gap a competent attacker exploits before touching anything technical.
  • 04Closing the map: decide on the authoritative source per identity class, eliminate redundant providers, consolidate authentication paths to a small number of well-monitored brokers, strengthen recovery to match primary auth. Typically takes 6-12 months and reduces identity risk more than any single tool purchase.

Most enterprises have a partial view of their identity attack surface. The human identities are well-understood; workload identities are less so; AI agent identities are barely understood at all. Alexa Research developed a methodology for producing a unified view across all three.

The methodology

  • 01Enumerate every identity provider — workforce, customer, B2B, machine
  • 02Enumerate every authoritative source — HR, vendor master, CMDB, cloud IAMs
  • 03Enumerate every authentication path — federation, brokering, trust, peering
  • 04Enumerate every elevation path — JIT, role assumption, service-account chaining
  • 05Enumerate every recovery path — password reset, MFA reset, IdP recovery

What we consistently find

Three to five identity providers in active use. Multiple authoritative sources that disagree on basic facts. Federation paths that no one remembers configuring. Recovery paths that are weaker than the primary authentication. Each of these is a gap a competent attacker exploits before they touch anything technical.

Closing the map

Decide on the authoritative source for each identity class. Eliminate redundant providers. Consolidate authentication paths to a small number of well-monitored brokers. Strengthen recovery to match primary auth. The exercise typically takes 6-12 months and reduces identity-related risk more than any single tool purchase.

#Alexa Research#Identity#Attack Surface

/WRITTEN_BY

Yusuf Ahmed

Principal Engineer, Platform Security · Alexa Cybersecurity