Showing results for 
Show  only  | Search instead for 
Did you mean: 

Risk scoring and nested groups

Risk scoring and nested groups


  1. Identity jdoe belongs to an AD group named "ACME Admins".
  2. "ACME Admins" is a member of the AD group named "Domain Admins".
  3. If I have a risk score configured for "Domain Admins", it does NOT affect the overall score for jdoe.
  4. If I have a risk score configured for "ACME Admins", it DOES affect the overall score for jdoe.



This is working as currently designed (as of identityIQ 5.2). The risk score algorithm does not take into account nested groups. It expects scores to be set at the individual group level.

Labels (1)
Version history
Revision #:
4 of 4
Last update:
‎May 29, 2023 07:51 PM
Updated by: