---
title: >-
  BeyondTrust Identity Security Insights identity configuration or security
  posture change detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  identity configuration or security posture change detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights identity configuration or security posture change detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect changes to identity configurations or security posture that may affect authentication, authorization, or overall security controls within the environment.

## Strategy{% #strategy %}

Monitor identity platforms and related services for configuration changes. This detection helps surface modifications that could weaken security posture by introducing unauthorized access.

## Triage and Response{% #triage-and-response %}

1. Identify the account `{{@entityName}}` associated with the detected configuration change.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the change aligns with approved administrative actions, change management processes, and organizational security policies.
1. If the change is unauthorized, revert the configuration immediately and take appropriate remediation steps in accordance with established incident response.
