See detected routes to Tier Zero, then fix the shared path.
Retrievy Identity X-Ray reconstructs evidence-backed Active Directory and supported Entra ID and Azure entitlement paths, shows the shortest detected route for each identity on the map, retains additional detected routes for drill-down within bounded limits, identifies shadow administrators, and ranks shared first-hop chokepoints. Every answer is scoped to the evidence the connected sources actually collected.
An admin roster cannot show who can become an admin.
Direct membership is only one route to control. Nested groups, DCSync rights, AdminSDHolder control, cloud directory roles, ownership, managed identities, and Azure RBAC can place an ordinary identity a few evidence-backed relationships away from a crown jewel. Supported delegation findings add related risk context where that evidence is collected.
A graph also needs prioritization. Treating every route as an isolated finding sends teams after individual accounts while a shared group or entitlement keeps recreating the same exposure.
Identity X-Ray makes the shortest detected paths visible on the map, preserves additional detected routes in identity drill-down, and groups their immediate shared hops into chokepoints. It does not claim that incomplete source evidence proves no path exists.
Answer the four questions that turn a graph into a remediation plan.
The analysis combines reach, path evidence, grouped first-hop chokepoints, and later verification instead of stopping at a visually impressive graph.
Who can reach Tier Zero?
Identify ordinary users, computers, and supported cloud principals that have a detected route to Domain Admins, Global Administrator, or another configured crown-jewel target.
Through which path?
Draw the shortest evidence-backed route on the map and retain additional detected routes for identity drill-down, subject to depth, path-count, and walk-budget limits.
Which shared node comes first?
Group shortest-path chains by their immediate chokepoint and rank that first shared hop by the detected accounts behind it, while acknowledging that alternate routes can remain.
How is the correction verified?
Track the underlying findings and use later directory or entitlement evidence to prove that the relationship or risky state no longer appears.
Collected relationships that can confer privilege.
The graph uses evidence-backed relationships. It does not invent an edge for a relationship the collector could not identify.
Direct and nested group paths
Ordered Active Directory membership chains from an identity through intermediate groups into a Tier Zero target.
Directory control rights
Supported DCSync, AdminSDHolder, dangerous ACL, and delegation findings where the evidence establishes privileged reach or related risk.
Shadow administrators
Non-privileged users or computers with detected reach into the selected crown-jewel set, separated from direct by-design members.
Entra directory roles and PIM
Supported standing and eligible Entra role relationships, including high-value directory-role reach where entitlement evidence is collected.
Graph permissions and ownership
Supported Graph application permissions, application or service-principal ownership, and related credential-control paths from collected Entra evidence.
Azure RBAC and managed identities
Supported Azure role assignments and managed-identity takeover relationships represented by the entitlement collector.
Custom privileged zones
User-defined crown-jewel groups or accounts alongside built-in Tier Zero targets, with the same reach and shadow-admin analysis.
Coverage state
Mapped, scanned-empty, and awaiting-source states distinguish observed absence from a source that has not supplied the necessary evidence.
Build the evidence graph, prioritize shared paths, verify the change.
-
1 Detect
Reconstruct collected relationships
Identity findings contribute principals, ordered group chains, supported control rights, and Entra/Azure entitlement relationships to the graph.
-
2 Prioritize
Rank reach and convergence
Tier rank, shadow-admin status, shortest detected routes, risk flags, and shared chokepoints focus review on the relationships with the most leverage.
-
3 Remediate
Fix the underlying edge
Remove an unintended membership, right, ownership relationship, or entitlement through the organization’s normal identity change process, and address related delegation findings in their own evidence context.
-
4 Verify
Rebuild from new evidence
A later scan reconstructs the relationships again. The correction is verified when the relevant path and supporting finding no longer appear in collected evidence.
Three identities enter the same legacy admin group
In this fictional lab, svc-deploy, alice.ops, and helpdesk-temp each enter Legacy Admin Bridge as the first hop in their shortest detected route to Domain Admins.
- Detected sources
- svc-deploy · alice.ops · helpdesk-temp
- Shared node
- Legacy Admin Bridge
- Target
- Domain Admins
- Priority signal
- Three grouped shortest paths share the same immediate chokepoint
Analysis
Reviewing the accounts one by one hides the leverage point. Grouping the detected shortest paths makes Legacy Admin Bridge the first relationship to investigate while identity drill-down preserves other detected routes that may also need remediation.
Remediation
The identity team validates the group’s remaining purpose, removes the unintended nesting, and separately reviews any alternate routes retained for the affected identities.
Verification
The next evidence collection rebuilds the graph. The grouped routes disappear when that collection no longer contains evidence of the relationship; another detected route remains visible rather than being treated as closed.
A path-management view that stays honest about evidence.
Shortest path plus drill-down
The map stays readable with one shortest detected route per identity, while drill-down retains additional evidence-backed routes within bounded enumeration limits.
First-hop prioritization
Chokepoint ranking shows which immediate node is shared by the most grouped shortest paths without promising that one change removes unknown or alternate routes.
Fail-closed classification
Unknown principal types are not automatically labeled shadow administrators, reducing false confidence from ambiguous evidence.
Coverage-aware
The interface distinguishes mapped, scanned-empty, and awaiting sources so missing collection is not reported as a clean identity surface.
Investigations the graph is designed to support.
- Which identities have detected reach into Tier Zero or a custom crown-jewel zone?
- Which route is shortest, and which additional routes were also detected?
- Which intermediate group or entitlement is shared by the most grouped paths?
- Which shadow administrators are not direct, by-design privileged members?
- Which Entra or Azure entitlement relationship creates high-value reach?
- Did the next evidence collection actually remove the path?
Continue with the relevant solution and technical guidance.
Related Retrievy solutions
Related security guidance
Identity Attack Path Management, answered.
1. Does Retrievy enumerate every possible identity attack path?
2. What does “shadow administrator” mean in Retrievy?
3. Which cloud identity paths are supported?
4. Does fixing the top chokepoint remove every route?
5. Does exploring Identity X-Ray change the security score?
Find the relationship that puts the most identities at risk.
Map detected Tier Zero reach, inspect additional paths, prioritize shared chokepoints, and verify the correction with fresh evidence.