Roll MFA, SSO, PAM, least privilege, automation, review cadence and stale accounts into one IAM programme health score.
The weights reflect how much each control reduces the chance of account takeover or a material access finding, which is why MFA and least privilege carry the most and SSO coverage — valuable but largely an enabler — carries less. Breached platform quotas are subtracted rather than weighted because they block change regardless of how good the rest looks. A single programme number is what a steering committee can act on, and the focus-area output keeps that conversation on the control with the most headroom rather than the one with the loudest advocate.
IAM Health Score
score = 20% MFA + 18% least privilege + 15% PAM + 13% review cadence + 12% SSO + 12% automation + 10% stale-account cleanliness, less 2 points per breached platform limit.
Residual risk
residual risk posture is banded from 100 − health score, so a 57-point programme carries medium-to-high residual risk.
score = 20% MFA + 18% least privilege + 15% PAM + 13% review cadence + 12% SSO + 12% automation + 10% stale-account cleanliness, less 2 points per breached platform limit. The weights reflect how much each control reduces the chance of account takeover or a material access finding, which is why MFA and least privilege carry the most and SSO coverage — valuable but largely an enabler — carries less. Breached platform quotas are subtracted rather than weighted because they block change regardless of how good the rest looks.
A single programme number is what a steering committee can act on, and the focus-area output keeps that conversation on the control with the most headroom rather than the one with the loudest advocate.
This calculator takes 8 inputs: MFA coverage, SSO coverage of the application estate, Privileged accounts under PAM, Least privilege score, Provisioning automated, Access review campaigns per year, Stale account rate, Policy or quota limits currently breached. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because it breaks the most common attack path outright. Credential theft through phishing and stuffing accounts for the bulk of identity incidents, and phishing-resistant MFA stops that path even when the password is already public — no other single control in this list has that property.
It means the programme depends on controls it does not have, not that a breach is imminent. Read it alongside the focus area: a 57 driven by review cadence is a governance problem to schedule, while a 57 driven by MFA coverage is an exposure to fix this quarter.