Comprehensive Identity Protection for Today's Enterprise, published by SANS Institute in April 2026, documents a guided demo of Rubrik Identity Resilience, a unified platform combining proactive identity protection with rapid recovery across Active Directory, Microsoft Entra ID, and Okta. The report examines how the platform addresses identity as the primary attack pathway into modern enterprises, covering recovery orchestration, tamper-resistant monitoring, non-human identity risk, and compliance for regulated environments.
Key findings:
- 80% of cyber intrusions now leverage compromised credentials
- 90% of attacks on critical infrastructure begin with identity compromise
- Traditional Active Directory forest recovery requires 20-plus manual steps per domain; Rubrik reduces this to a five-step wizard-driven workflow
- Only 15% of organisations are confident in their ability to prevent attacks leveraging non-human identities, while 69% report significant concerns
- Service accounts, OAuth tokens, and API keys now outnumber human identities in many enterprise environments, yet remain largely invisible to traditional identity monitoring
- Rubrik's tamper-resistant monitoring operates independently of Windows Event Logs, so event data remains intact even when attackers achieve Domain Admin privileges and attempt to clear logs
- Surgical rollback allows administrators to revert specific attacker-made changes (GPO edits, unauthorized group membership additions) while preserving legitimate business changes made during the same period
- Okta support was added to the platform in September 2025, extending coverage to the third major identity provider alongside Active Directory and Entra ID
- Policy-driven risk detection scans identity configurations against MITRE ATT&CK, D3FEND, OWASP, ANSSI, ISO 27001, CIS Controls, NIST SCF, GDPR, HIPAA, PCI DSS, SOC 2, and CMMC
- Rubrik Security Cloud – Government Edition (RSC-G) supports FedRAMP, CJIS, and StateRAMP compliance, but currently covers only Identity Recovery capabilities — proactive features like risk detection and surgical rollback remain limited to standard Rubrik Security Cloud editions
- DSPM integration maps identity access to sensitive data categories (PCI, PHI, financial information), enabling risk scoring that factors in data sensitivity alongside identity privilege
The findings point to a structural gap in how organisations have historically approached identity security: backup vendors focus on recovery after compromise, while identity governance tools focus on prevention, but few platforms unify both. This report finds that unified visibility across human and non-human identities, combined with monitoring that survives log-clearing techniques, addresses a specific blind spot that neither backup-only nor governance-only tools have closed. The distinction SANS draws between RSC-G's recovery-only coverage and standard edition's full resilience feature set is a practical consideration for public sector buyers evaluating compliance-bound deployments.
This report is based on a SANS-guided demo observation of Rubrik Identity Resilience rather than a practitioner survey, drawing on direct evaluation of platform capabilities across Active Directory, Microsoft Entra ID, and Okta environments, supplemented by industry data on credential-based attacks and non-human identity risk.