Every identity is a door. We show you which ones are unlocked — and close them.
Your directory already contains the paths an attacker would walk. MIR finds them, ranks them by what closing them does to your score, and closes them.
90 secondsNo signup to startRead-only, no agents
The problem
Identity is where breaches start, and where visibility ends.
Most organisations can tell you how many accounts they have. Very few can name the three chains that lead from a standard user to Domain Admin.
// the account nobody remembers
A service account created six years ago for a project that ended
Still enabled. Still privileged. No sign-in for 412 days, on no one’s review list, and holding a delegation set by someone who has since left. It generates no alerts because it does nothing — until it does.
// three hops, zero alerts
Escalation built entirely from legitimate permissions
A nested group membership, a delegation, then Domain Admin. Every step is authorised, so nothing looks abnormal to your SIEM. The path was always there; someone finally walked it.
// the hybrid seam
Two directories, one trust, no single view
Sync between on-prem AD and Entra ID creates privilege relationships that neither directory’s native tooling maps end to end. Post-acquisition estates multiply the problem.
The programme
What MIR actually does
One continuous loop across both directories — not four dashboards.
Map the full identity attack surface
Read-only discovery across on-premises Active Directory and Entra ID, mapped to MITRE ATT&CK.
- Stale and dormant enabled accounts
- Shadow admins via nested group membership
- Kerberoastable service accounts and SPN exposure
- Constrained and unconstrained delegation
- Weak Kerberos and legacy authentication configuration
- Leaked and reused credential matches
- Conditional access and MFA coverage gaps
- Human and non-human identity inventory
Rank by attack path, not by CVSS
Findings are assembled into paths and ranked by what closing them does to your exposure score.
- Full privilege-escalation path mapping
- Ranked top-three fixes per cycle
- Modelled exposure reduction per fix
- Board-readable risk language alongside technical detail
Close it, reversibly
Guided or fully managed closure, change-controlled and backed up before any change is applied.
- Guided or managed remediation options
- Backup and rollback before every change
- Verified on rescan, not on assertion
- Change-control aligned to your process
Re-score and report
The same measurement runs monthly so improvement is evidence rather than assertion.
- Monthly exposure re-score
- Attributable score delta per closure
- Quarterly board and audit pack
- Evidence set for cyber insurance and ISO 27001 / Essential Eight
At a glance
What’s included
The commercial and technical shape of the programme, before you talk to anyone.
| Directory coverage | Hybrid AD + Entra ID, multi-forest and post-acquisition estates |
| Deployment | Read-only. No agents on domain controllers, no schema changes |
| Baseline | Breach Likelihood Assessment — attack paths mapped within days |
| Cadence | Continuous discovery, monthly re-score, quarterly executive report |
| Remediation | Guided or fully managed, with backup and rollback |
| Frameworks | Mapped to NIST CSF, ISO 27001 Annex A and ACSC Essential Eight |
| Guarantee | 90% reduction in measured identity exposure score in 90 days — see terms |
This is a good fit if…
- 1,500–10,000 users, hybrid Microsoft estate
- Security team of 1–10 carrying identity alongside everything else
- Recent audit, insurance renewal or board question about identity risk
- Post-acquisition estate with inherited directories nobody fully owns
If none of these describe you, MIR probably is not your priority — and we would rather tell you that than sell it. Run the free assessment on a different surface and see where your score is actually worst.
The fair questions
No. Collection is read-only and API-based. Nothing is installed on domain controllers and no schema changes are made. This is deliberate — it is what makes a first assessment a low-friction decision rather than a change-board item.
Defender for Identity detects known attack behaviours in real time and does that well. MIR measures the conditions that make those attacks possible — stale privilege, delegation, sprawl — and closes them. Detection tells you about the fire; exposure management removes the fuel. Most of our clients run both.
Probably the same top findings, plus everything created in the three months since. A pen test is a point-in-time sample; your directory changes weekly. The difference is continuity and closure, not detection skill.
Find out where you stand on identity — in 90 seconds.
Eight questions, a score, and your top three exposure factors. If you want the real number, the full assessment reads your actual environment: read-only, no agents, 48 hours to a report.
90 secondsNo signup to startNo agents, read-onlyNo obligation