IAM Health Score Calculator
Roll MFA, SSO, PAM, least privilege, automation, review cadence and stale accounts into one IAM programme health score.
Inputs
IAM Health Score
57/ 100
Rating
D — Weak
Residual Risk Posture
Medium
Highest-Leverage Focus Area
Access review cadence
Points to the Next Grade
3
Penalty From Breached Limits
8points
Step by step
Values used
MFA coverage = 82 %; SSO coverage of the application estate = 63 %; Privileged accounts under PAM = 55 %; Least privilege score = 61 / 100; Provisioning automated = 70 %; Access review campaigns per year = 2 campaigns; Stale account rate = 3.20 %; Policy or quota limits currently breached = 4 breaches
IAM Health Score
score = 20% MFA + 18% least privilege + 15% PAM + 13% review cadence + 12% SSO + 12% automation + 10% stale-account cleanliness, less 2 points per breached platform limit.
Residual risk
residual risk posture is banded from 100 − health score, so a 57-point programme carries medium-to-high residual risk.
IAM Health Score
= 57 / 100
Rating
= D — Weak
Residual Risk Posture
= Medium
Highest-Leverage Focus Area
= Access review cadence
Points to the Next Grade
= 3
Penalty From Breached Limits
= 8 points
How it works
The weights reflect how much each control reduces the chance of account takeover or a material access finding, which is why MFA and least privilege carry the most and SSO coverage — valuable but largely an enabler — carries less. Breached platform quotas are subtracted rather than weighted because they block change regardless of how good the rest looks. A single programme number is what a steering committee can act on, and the focus-area output keeps that conversation on the control with the most headroom rather than the one with the loudest advocate.
Formulas
IAM Health Score
score = 20% MFA + 18% least privilege + 15% PAM + 13% review cadence + 12% SSO + 12% automation + 10% stale-account cleanliness, less 2 points per breached platform limit.
- review cadence
- Campaigns per year × 25, so quarterly reviews score full marks
- stale-account cleanliness
- 100 minus 10 × the stale account rate
- breached limit
- A policy character, attachment or assignment quota already exceeded
Residual risk
residual risk posture is banded from 100 − health score, so a 57-point programme carries medium-to-high residual risk.
- residual risk
- What is left after the controls you actually have in place
Frequently Asked Questions
How is IAM Health Score calculated?
score = 20% MFA + 18% least privilege + 15% PAM + 13% review cadence + 12% SSO + 12% automation + 10% stale-account cleanliness, less 2 points per breached platform limit. The weights reflect how much each control reduces the chance of account takeover or a material access finding, which is why MFA and least privilege carry the most and SSO coverage — valuable but largely an enabler — carries less. Breached platform quotas are subtracted rather than weighted because they block change regardless of how good the rest looks.
Why does IAM Health Score matter?
A single programme number is what a steering committee can act on, and the focus-area output keeps that conversation on the control with the most headroom rather than the one with the loudest advocate.
What values do I need to enter?
This calculator takes 8 inputs: MFA coverage, SSO coverage of the application estate, Privileged accounts under PAM, Least privilege score, Provisioning automated, Access review campaigns per year, Stale account rate, Policy or quota limits currently breached. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does MFA carry the largest weight?
Because it breaks the most common attack path outright. Credential theft through phishing and stuffing accounts for the bulk of identity incidents, and phishing-resistant MFA stops that path even when the password is already public — no other single control in this list has that property.
What does a low score actually mean?
It means the programme depends on controls it does not have, not that a breach is imminent. Read it alongside the focus area: a 57 driven by review cadence is a governance problem to schedule, while a 57 driven by MFA coverage is an exposure to fix this quarter.
You might also need
- Identity Risk CalculatorCommonly used together
- Access Governance Score CalculatorCommonly used together
- Least Privilege CalculatorCommonly used together
- Single Sign-On Coverage CalculatorCommonly used together
- JWT Payload Size CalculatorAlso in Identity & Access Management
- Privilege Escalation Risk CalculatorAlso in Identity & Access Management