Request for a feature to demonstrate a reason for false positive rule match

What is a one sentence summary of your feature request?

Add indicators to false positive rule matches in Netwrix PingCastle to show the specific reason for the match (e.g., a P-Delegated rule triggered by insufficient Read permissions on an object).

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

When Netwrix PingCastle flags a rule match, users may encounter false positives caused by environmental limitations — such as the scanner lacking Read access to an Active Directory object — rather than an actual security misconfiguration. These matches are currently presented without any explanation, making it difficult to distinguish a genuine finding from a scanning artifact.

Without visibility into why a rule was matched, analysts waste time investigating non-issues, struggle to prioritize real risks, and gradually lose confidence in the tool’s output.

The proposed solution is to add contextual reason indicators to rule matches. For example, if a P-Delegated rule fires due to insufficient Read permissions on an object, the result should display a clear marker explaining this — rather than presenting it as a plain finding.

Such solution should not require change to core scanning logic, only to how results are labeled. It gives users immediate clarity on whether a finding needs security remediation or simply a permissions adjustment, reducing investigation overhead and improving trust in the tool’s output.

How do you currently solve the challenges you have by not having this feature?

There is currently no workaround available. False positives must be reported to support and processed through tickets, increasing the time before necessary action can be taken

1 Like