Anomaly detection
An anomaly is an account found on a connected application that matches no known MIA user — typically an external, orphaned or undeclared account.
Why it's useful
- Spot orphaned accounts (former staff, departed contractors) that are still active.
- Detect unknown accounts (shared license, undeclared service account).
- Keep a reliable, up-to-date inventory.
How MIA detects anomalies
On each sync, MIA compares each remote account's email address to your domain name (the one set during getting started):
- if automatic creation is enabled and the email matches your domain, the account becomes a user (linked to an existing user or created automatically);
- otherwise — email outside the domain, automatic creation disabled, or account with no usable email — the account is flagged as an anomaly.
Anomalies appear in the Anomalies view, grouped by application.
Handling an anomaly
Three actions are available:
- Create a user — turns the account into a new MIA user (the anomaly disappears).
- Match — links the account to an existing user; the access enriches their profile.
- Delete — closes the remote account on the application, when it allows it.
WARNING
"Delete" acts on the service itself: the account is closed on the application side. The action is offered only for applications able to remove an access.
Good to know
- Anomaly detection is included in the free plan.
- Automatic data-breach checking on these accounts is a Pro feature.