Skip to content
Calcrivo

IAM Health Score Calculator

Roll MFA, SSO, PAM, least privilege, automation, review cadence and stale accounts into one IAM programme health score.

Inputs

%
%
%
/ 100
%
campaigns
%
breaches

IAM Health Score

57/ 100

Rating

D — Weak

Residual Risk Posture

Medium

Highest-Leverage Focus Area

Access review cadence

Points to the Next Grade

3

Penalty From Breached Limits

8points

Step by step

  1. Values used

    MFA coverage = 82 %; SSO coverage of the application estate = 63 %; Privileged accounts under PAM = 55 %; Least privilege score = 61 / 100; Provisioning automated = 70 %; Access review campaigns per year = 2 campaigns; Stale account rate = 3.20 %; Policy or quota limits currently breached = 4 breaches

  2. IAM Health Score

    score = 20% MFA + 18% least privilege + 15% PAM + 13% review cadence + 12% SSO + 12% automation + 10% stale-account cleanliness, less 2 points per breached platform limit.

  3. Residual risk

    residual risk posture is banded from 100 − health score, so a 57-point programme carries medium-to-high residual risk.

  4. IAM Health Score

    = 57 / 100

  5. Rating

    = D — Weak

  6. Residual Risk Posture

    = Medium

  7. Highest-Leverage Focus Area

    = Access review cadence

  8. Points to the Next Grade

    = 3

  9. Penalty From Breached Limits

    = 8 points

How it works

The weights reflect how much each control reduces the chance of account takeover or a material access finding, which is why MFA and least privilege carry the most and SSO coverage — valuable but largely an enabler — carries less. Breached platform quotas are subtracted rather than weighted because they block change regardless of how good the rest looks. A single programme number is what a steering committee can act on, and the focus-area output keeps that conversation on the control with the most headroom rather than the one with the loudest advocate.

Formulas

IAM Health Score

score = 20% MFA + 18% least privilege + 15% PAM + 13% review cadence + 12% SSO + 12% automation + 10% stale-account cleanliness, less 2 points per breached platform limit.

review cadence
Campaigns per year × 25, so quarterly reviews score full marks
stale-account cleanliness
100 minus 10 × the stale account rate
breached limit
A policy character, attachment or assignment quota already exceeded

Residual risk

residual risk posture is banded from 100 − health score, so a 57-point programme carries medium-to-high residual risk.

residual risk
What is left after the controls you actually have in place

Frequently Asked Questions

How is IAM Health Score calculated?

score = 20% MFA + 18% least privilege + 15% PAM + 13% review cadence + 12% SSO + 12% automation + 10% stale-account cleanliness, less 2 points per breached platform limit. The weights reflect how much each control reduces the chance of account takeover or a material access finding, which is why MFA and least privilege carry the most and SSO coverage — valuable but largely an enabler — carries less. Breached platform quotas are subtracted rather than weighted because they block change regardless of how good the rest looks.

Why does IAM Health Score matter?

A single programme number is what a steering committee can act on, and the focus-area output keeps that conversation on the control with the most headroom rather than the one with the loudest advocate.

What values do I need to enter?

This calculator takes 8 inputs: MFA coverage, SSO coverage of the application estate, Privileged accounts under PAM, Least privilege score, Provisioning automated, Access review campaigns per year, Stale account rate, Policy or quota limits currently breached. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why does MFA carry the largest weight?

Because it breaks the most common attack path outright. Credential theft through phishing and stuffing accounts for the bulk of identity incidents, and phishing-resistant MFA stops that path even when the password is already public — no other single control in this list has that property.

What does a low score actually mean?

It means the programme depends on controls it does not have, not that a breach is imminent. Read it alongside the focus area: a 57 driven by review cadence is a governance problem to schedule, while a 57 driven by MFA coverage is an exposure to fix this quarter.

You might also need