> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/dashboard.md).

# Dashboard

Dashboard provides a general and holistic view of the identity security posture across scanned environments based on different perspectives.

## Scan Context

The band at the top of the page names the scan the figures belong to and describes its scope as a row of chips: the policy that produced the scan, and the forests and domains it covered. When a scan covers more scopes than fit on one line, the remainder is collapsed into a **+N More** chip.

Two selectors sit on the right of the band:

**Provider:** Chooses which provider the dashboard reports on. The list shows only the providers present in the selected scan, under an `In this scan` heading, each with the number of issues found for it, and can be filtered by typing. The cards below the band change with the selection, so an Active Directory dashboard shows users, computers, groups and GPOs while an AWS dashboard shows users, policies, roles, access keys and groups.

**Compare:** Chooses another scan to compare the current one against.

The chips follow the selected provider, so they describe the scope in that provider's own terms: an Active Directory selection shows the forests and domains covered, while an AWS selection shows the accounts, for example `Accounts - 834922934926 (Commercial)`.

## Risk by Scope

Risk by scope breaks the scan down by the scopes it covered, so a scan spanning more than one forest or domain shows where the risk actually sits. The heading carries the number of scopes.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-f80ad2ca0877a49eddc0f2d11847298a946b0188%2Fdashboard-readme-risk-by-scope.png?alt=media" alt=""><figcaption><p>Risk by scope</p></figcaption></figure>

**Scope:** The forest or domain the row is about, linking to its entity page.

**Risk:** The risk score calculated from that scope's own findings, drawn as a gauge.

**Exposure:** The exposure points accumulated within that scope.

**Affected objects:** How many objects in the scope have at least one issue, out of the number of objects scanned for it.

**Issue Counts:** The issues found in the scope, as one badge per severity.

{% hint style="info" %}
Each scope is scored on its own findings, so the scope risks do not add up to the scan score, and a finding that reaches two scopes is counted in both.
{% endhint %}

The same figures for a single domain are shown on that domain's [Domain scope](/fsprotect/unified-identities/ad-identities/domains.md) card.

## Over-privilege Audit Logging

Over-privilege audit logging reports how much of the environment the [Over-Privilege Analysis (Beta)](/fsprotect/scans/policies/policies.md) module was actually able to judge. A permission can only be marked **Actively in use** if the object's SACL audits it, so an object with no auditing produces no evidence either way, and an unused permission cannot be told apart from an unobserved one.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-39fcc47b77291c5095332269835582e52f03325d%2Fdashboard-readme-over-privilege-audit-logging.png?alt=media" alt=""><figcaption><p>Over-privilege audit logging</p></figcaption></figure>

The heading carries the number of objects checked. The bar splits them three ways:

**No logging:** Objects whose SACL audits nothing. Permissions on these objects can never be confirmed as in use.

**Partial logging:** Objects whose SACL audits some, but not all, of the access the analysis needs.

**Full logging:** Objects whose SACL audits everything the analysis needs.

Auditing needs both halves: the SACL on the object, and the audit policy on the domain controller. When controllers are missing their audit policies, a warning below the bar says how many, and links to the list of them in [Search & Reports](/fsprotect/search-and-reports.md).

{% hint style="info" %}
The card is shown for scans whose policy enables the Over-Privilege Analysis (Beta) module. The usage evidence it describes is what produces the `Actively in use` value on an issue's affected-entity table, which requires a [Splunk](/fsprotect/configuration-center/splunk.md) integration.
{% endhint %}

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-2830cc62579adb9641fae4f4dde34bea4dde5553%2FDashboard1.png?alt=media" alt=""><figcaption></figcaption></figure>

### Risk Score, Exposure Score, Dangerous Path Count, Shadow Admins,and Severities

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-d281d893889d47996e8c7458342e6098e0a5b1ad%2Fdashboard-readme-image-1.png?alt=media" alt=""><figcaption><p>Risk Score, Exposure Score, Dangerous Path Count, Shadow Admins,and Severities</p></figcaption></figure>

**Risk Score:**\
Risk score is the primary indicator of the current identity security posture of scanned environments. It is calculated based on the number and severity of detected issues. A risk score of 100 indicates the presence of at least one issue that may lead to a full identity compromise.

**Exposure Score:**\
A metric that represents the overall level of exposure based on discovered misconfigurations, excessive permissions, and risky identity relationships.

**Dangerous Path Count:**\
Dangerous Path Count indicates the number of potential attack paths that could lead to the compromise of privileged identities through misconfigurations or indirect permission relationships.

**Shadow Admins:**\
The number of identities that effectively hold administrative privileges through indirect, inherited, or hard-to-detect permission assignments, posing a significant security risk.

**Critical**: The number of Issues with Critical severity.

**High**: The number of Issues with High severity.

**Medium**: The number of Issues with Medium severity.

**Low**: The number of Issues with Low severity.

**Info**: The number of Issues with Info severity.

### Risk Breakdown by MITRE ATT\&CK Tactics

Risk scores based on MITRE ATT\&CK Tactics mapping.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-5e092388c2e72d8287ea67917954058255cde1d2%2Fdashboard-readme-image-2.png?alt=media" alt=""><figcaption><p>Risk Breakdown by MITRE ATT&#x26;CK Tactics</p></figcaption></figure>

### Tier Analysis Statistics

The Tier Analysis statistics highlight identities and objects that play an important role in attack paths leading toward Tier 0.

| Statistic                          | Description                                                                                                                                                                                  |
| ---------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Top Exposed Tier 0 Identities**  | Shows up to five Tier 0 identities with the highest exposure to incoming attack paths. These objects act as important convergence points for paths that can reach Tier 0.                    |
| **Top Exposed Tier 2 Identities**  | Shows up to five Tier 2 identities with the highest exposure to incoming attack paths. These objects represent significant bottlenecks along paths leading toward Tier 0.                    |
| **Top Blasting Tier 2 Identities** | Shows up to five Tier 2 identities with the strongest combined incoming and outgoing attack-path connectivity. These objects can both receive access and propagate it further toward Tier 0. |

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-277257bb0604acae761f2a7aff3c54424118e417%2Fdashboard-readme-image-3.png?alt=media" alt=""><figcaption><p>Tier Analysis Statistics</p></figcaption></figure>

### Top Choke Points

Top Choke Points highlights representative attack paths that contain important bottlenecks on the way to **Tier 0**.

Each path shows the relationships used to progress toward Tier 0 and highlights the points where multiple attack paths converge. **Chokes** indicates the number of identified choke points on the displayed path, while **Reaches Tier0** confirms that the path reaches a Tier 0 object.

The **Choke recommendations** section lists relationships that can be reviewed to help break the attack path. When multiple critical paths are available, **Prev** and **Next** can be used to navigate between them.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-f7d13d267bd20b88873f01dce3f7deb55cc50134%2Fdashboard-readme-image-4.png?alt=media" alt=""><figcaption><p>Top Choke Points</p></figcaption></figure>

{% content-ref url="/pages/g5En4Jdt1S56NE9nxFNk" %}
[Active Directory Dashboard](/fsprotect/dashboard/0x1-dashboard.md)
{% endcontent-ref %}

{% content-ref url="/pages/VSw3Ka6oNdezQSPeySdP" %}
[Azure / Entra ID Dashboard](/fsprotect/dashboard/azure-entra-id-dashboard.md)
{% endcontent-ref %}

{% content-ref url="/pages/IbDdRIKT1f1TFHTgPaJa" %}
[AWS Dashboard](/fsprotect/dashboard/aws-dashboard.md)
{% endcontent-ref %}

{% content-ref url="/pages/JjM8GRUeU3JlDWgDHMd3" %}
[GCP Dashboard](/fsprotect/dashboard/gcp-dashboard.md)
{% endcontent-ref %}
