Demo Center Home  >  Holistic Identity Demo

PLATFORM

HOLISTIC IDENTITY

See how one exposed asset expands into a person’s full risk picture, and how SpyCloud remediates the entire exposure automatically. Walk through how one exposed credential expands into a full holistic identity with IDLink, then gets remediated automatically across Active Directory, Entra ID, and Okta.

HOLISTIC IDENTITY Protection by SpyCloud

     
       
  

What you'll see

From one password to the whole identity

This demo follows a single identity end to end, from one recaptured credential to the full set of exposed assets connected to that person, and finally to automated remediation. You will see how SpyCloud surfaces an exposure, expands it into a holistic identity view with IDLink, and closes the access without an analyst chasing it down.

The walkthrough moves from detection to full remediation. SpyCloud confirms an exposed identity, IDLink maps everything tied to that person, and Identity Guardians reset the exposed password and revoke active sessions according to your policy, whether the environment runs on Active Directory, Microsoft Entra ID, Okta Workforce Identity, or a combination of them.

Explore
the recaptured identity catalog, over 1 trillion assets collected from phishing kits, malware, breaches, and combolists
Inspect
one phishing record tied to a real employee, flagged HIGH severity on a confirmed email and plaintext password
Investigate
a single email with an IDLink search in SpyCloud Investigations
Connect
63 exposed identity assets, 61 surfaced only by IDLink, mapped into one holistic identity
Remediate
the exposed password automatically with Active Directory Guardian, and across Entra ID and Okta
Confirm
the result: caught, reset, and forced to change at next login, with no analyst required

Same holistic identity, same automatic response across Active Directory, Entra ID, and Okta, whether your workforce identities are on-prem, hybrid, or fully cloud.

HOW IT WORKS

One record becomes the whole identity

STEP 1

Start from exposure

A recaptured phishing record, matched to a real exposed employee and flagged HIGH severity on a confirmed email and plaintext password.

STEP 2

Expand with IDLink

IDLink pivots across the full dataset, turning one email into 63 connected identity assets, 61 of which exact matching would never surface.

STEP 3

See the whole identity

The graph maps every reused email, username, and password back to one employee, so you act on the whole identity instead of a single login.​

STEP 4

Remediate

Identity Guardians reset the exposed password and revoke active sessions across Active Directory, Entra ID, and Okta, no analyst required.

Outcomes of holistic identity
threat protection

8x

more identity records vs exact matching

14x

More exposed plaintext passwords vs exact matching

5 min.

from detection to remediation of malware-exposed credentials

WHAT IDLINK FOUND

One email, 63 connected assets

The demo starts with a single email address. IDLink expands it into 63 exposed identity assets tied to the same person,
and 61 of them surface only because of IDLink.

Data breach infographic showing passwords, emails, IPs, and identifiers.

Check Your Exposure

See your organization’s real exposure,
matched against SpyCloud’s recaptured identity records.

Holistic Identity Demo FAQs

It shows how SpyCloud turns a single exposed credential into the full holistic identity behind it, then remediates that exposure automatically. The walkthrough moves from one recaptured phishing record tied to an employee, through an IDLink search in SpyCloud Investigations that surfaces 63 connected identity assets, to an automated password reset through Active Directory Guardian.

 

A holistic identity is the complete set of data tied to one person across their online life: work and personal emails, usernames, current and historical passwords, PII, financial data, and location. Attackers assemble these fragments to bypass single-account defenses, so remediating one credential in isolation leaves the rest of the identity exposed. SpyCloud maps the whole identity so a team can act on all of it.

 

IDLink is SpyCloud’s identity analytics capability for pivoting across recaptured data. It correlates the many fragments that make up a person’s identity, such as emails, usernames, and passwords reused across accounts, to connect exposures an exact credential match would never link. In the demo, exact matching would have found a handful of assets, while IDLink surfaces 61 additional ones, and across a workforce it finds up to 14x more exposed plaintext passwords per user.

 

The data is recaptured from the criminal underground, including third-party breaches, infostealer malware records, and successfully phished data. Because SpyCloud recaptures it close to the source rather than scraping public sites, exposures often appear before criminals have used them, which gives defenders time to remediate.

SpyCloud’s Identity Guardians act on confirmed exposures without analyst effort. Active Directory Guardian scans AD accounts against recaptured data and can reset an exposed password within five minutes of discovery, forcing a change at next login. Equivalent solutions extend the same automated detection and remediation to Entra ID and Okta, so the exposure is closed wherever your workforce authenticates.