Start with Identity
← Glossary
Concept

Identity Resilience

The ability to keep authenticating and authorising legitimate users, and to recover the identity system itself, when the identity provider or directory is degraded, compromised, or unavailable.

Identity resilience is a distinct discipline from identity security. Security asks how an attacker gets in; resilience asks what happens once the identity system is the casualty. If Active Directory is encrypted in a ransomware event, or a cloud identity provider has a multi-hour outage, every downstream application that depends on it fails at once. Identity has become the single point of failure that most disaster recovery plans still treat as infrastructure someone else looks after.

Three capabilities carry most of the weight. Forest and tenant recovery means being able to rebuild a directory to a known-good state, tested rather than assumed, which is the specialism of vendors such as Semperis. Break-glass access means credentials that work when the identity provider does not, stored and governed outside it, and exercised in drills rather than discovered during an incident. Authentication fallback means a documented path for critical applications when primary authentication is down, agreed in advance rather than improvised.

The practical test is simple and uncomfortable: if your directory were unavailable right now, how long until a named person could restore it, and has anyone actually done it?

See also: ITDR, zero standing privileges, ITDR tools compared

Related terms
Last reviewed By SWI Community TeamSuggest a correctionHow we research