Clearer identity findings and recommendations for breach exposure
We've renamed and updated the Identity findings and recommendations that deal with credential breaches so they're easier to understand and act on. The names now describe exactly what each finding or recommendation covers, and for each one we've refreshed the supporting content - descriptions, risk explanations, details, immediate actions, and proactive actions — so the guidance is clearer and more actionable.
Here's what's changed:
"User has old password" is now "Account exposed in breach after last password change"
The new name makes the finding's purpose clear: it flags accounts whose credentials were exposed in a known breach and haven't been changed since.
"Remind your users to change their password" is now "Reset passwords exposed in breaches"
The new name reflects the specific action that reduces risk — resetting passwords that have been exposed in breaches.
"Remediate identity breach of multiple users" is now "Review identities with breaches"
The recommendation now includes clear guidance for addressing Identity breach findings. Since these findings belong to a unique category that can't be resolved through standard means, they call for a different approach.