Skip to content

Anomaly detection

An anomaly is an account found on a connected application that matches no known MIA user — typically an external, orphaned or undeclared account.

Why it's useful

  • Spot orphaned accounts (former staff, departed contractors) that are still active.
  • Detect unknown accounts (shared license, undeclared service account).
  • Keep a reliable, up-to-date inventory.

How MIA detects anomalies

On each sync, MIA compares each remote account's email address to your domain name (the one set during getting started):

  • if automatic creation is enabled and the email matches your domain, the account becomes a user (linked to an existing user or created automatically);
  • otherwise — email outside the domain, automatic creation disabled, or account with no usable email — the account is flagged as an anomaly.

Anomalies appear in the Anomalies view, grouped by application.

Handling an anomaly

Three actions are available:

  • Create a user — turns the account into a new MIA user (the anomaly disappears).
  • Match — links the account to an existing user; the access enriches their profile.
  • Deletecloses the remote account on the application, when it allows it.

WARNING

"Delete" acts on the service itself: the account is closed on the application side. The action is offered only for applications able to remove an access.

Good to know

  • Anomaly detection is included in the free plan.
  • Automatic data-breach checking on these accounts is a Pro feature.