Veza reposted this
Veza Product Update: 2025.8 At Veza, we’re advancing next-gen identity security by unifying access visibility, intelligence, governance, and automation across the enterprise’s largest attack surface: identity. Our 2025.8 release helps teams operationalize least privilege, strengthen compliance, and move from reactive governance to proactive control. Here’s some of what’s new: ✨ Natural language search in Query Builder converts questions like “Show me all AWS IAM users who can delete a particular S3 bucket” into structured queries, making authorization analysis accessible beyond IAM specialists. ✨ Query explanations with Access AI provide instant clarity on the purpose, logic, and expected results of complex saved queries directly from the query details view. ✨ Risk profile classifications organize 2,400+ out-of-the-box queries across 8 categories (MFA Health, Privileged Access, Blast Radius, Dormant Access, Orphaned Access, Access Risks, Identity Hygiene, Informational), helping teams quantify posture and prioritize remediation. ✨ Team-based sharing enables collaboration by sharing custom dashboards with specific teams or individuals via direct email links. ✨ Azure activity monitoring extends Access Monitoring capabilities to Microsoft Azure (Entra ID, Azure Roles, SharePoint Online) for visibility into active permission usage versus over-provisioning. ✨ Custom attribute transformers replace complex pipelines with reusable macros for consistent attribute processing in Lifecycle Management. ✨ Workflow priority controls for Lifecycle Management policy execution with six priority levels, ensuring critical provisioning operations execute first. ✨ Enhanced NHI overview dashboard organizes non-human identities by type and integration, with owner management, credential age tracking, and trend analysis, closing a growing blind spot in enterprise access control. ✨ Monthly export scheduling enables granular compliance reporting with query exports on specific months and days. ✨ AWS IAM Roles Anywhere discovers workloads using temporary AWS credentials via X.509 certificate authentication, including trust anchors, certificate revocation lists, and profile mappings. Read the full release here: 👉 https://lnkd.in/gDPeVt9A