Respond to identity threats.
Prove what changed.

Identity threat detection and response for Microsoft Entra ID and Azure. Find dangerous access across users and applications. Approve a targeted action. Orbitra executes it in Microsoft and verifies supported changes.

Book a response walkthroughWatch a response

Start with a demonstration tenant. Connect read-only when you choose. A named person approves every Orbitra-executed response today.

For the team that owns Microsoft security, without a dedicated identity specialist.

By operators with experience at Los Alamos, MITRE, and Morphisec.

When identity access
becomes your incident.

The person on call needs to know what is exposed, which action fits, and whether the response changed what it was meant to change.

An admin role nobody can explain.

Establish how the identity gained access. Review the direct assignment and supported privilege paths, then decide which access should be removed.

See the targeted role-removal response

An application with access it should not keep.

Investigate the workload identity and its permissions. Choose a response for its grant or credentials, with the impact on dependent applications in view.

See application-access responses

A response you need to substantiate.

Keep the approver, exact target, provider outcome, and verification together. Explain the change and what still needs review after the incident.

See what the response evidence establishes

Watch Orbitra
carry out a response.

An unauthorized admin grant becomes a targeted, approved response. Follow the handoffs all the way to the evidence.

Example incident Unexpected Global Administrator grant

Illustrative workflow

An identity signal starts the response.

An unexpected Global Administrator grant is attached to Jordan Lee. Orbitra brings the identity and event evidence into the investigation.

Privilege alone is not proof of compromise. This example starts with an unexpected grant.

Build a response, not another alert.

The reviewer establishes that the assignment is unauthorized. Orbitra prepares a targeted role removal with the evidence, exact target, and recovery details.

Access analysis and proposed fixes provide context before anyone acts.

You authorize the exact action.

Remove Jordan Lee's direct Global Administrator assignment. Alex Morgan is the named example approver. The proposal stops here until you approve it.

This button approves an illustration. It does not connect to a tenant or change a real account.

Orbitra removes the role in Microsoft.

The approved response passes policy, target, and permission checks. Orbitra then calls Microsoft Graph to remove the direct role membership.

The responder performs a real provider action in the product. This animation uses example data.

Read Microsoft again. Check what changed.

Orbitra reads the relevant role membership back from Microsoft. The expected outcome is that this direct Global Administrator membership is absent.

That verifies this removal. Other roles, group paths, sessions, and tokens still need their own checks.

Deliver the decision and the result.

Inspect the example evidence

The response record brings together the before-state, named approval, provider outcome, and verification. Your team can inspect the same evidence after the incident.

The sample is illustrative. Integrity checks do not provide independent attestation or certify compliance.

Explore the product from investigation to evidenceA named person authorizes execution. No live actions in this illustration.

A response changes
something specific.

Orbitra carries out supported Microsoft actions after named approval. Choose the response that matches the identity and the problem.

Remove the admin role.

Remove a targeted direct role membership. Read Microsoft again to check that the membership is absent.

Review the action and its scope

Disable the user account.

Change the account's enabled state and verify it in Microsoft. Review the impact and any remaining session access.

Review account disablement

Revoke user sessions.

Request user-session revocation and check Microsoft's session-valid-from timestamp. Application behavior and propagation still matter.

Review session revocation

Remove the application grant.

Delete the targeted OAuth consent grant and verify its absence. Other grants and issued tokens require their own review.

Review grant removal
Explore response actions, including workloads and Azure

Keep your Microsoft controls.
Connect the response.

Already using Defender, Entra ID Protection, or PIM? Orbitra connects identity context and its own detections to an approved action and evidence of the supported result.

Understand what deserves attention.

Review human and workload access, supported Entra privilege paths, and available identity signals in context.

Carry a decision into action.

Review the exact target and permissions. A named person approves before Orbitra invokes the supported Microsoft response.

Show what Microsoft confirmed.

Keep provider acceptance separate from verification. Retain the decision and the outcome for incident follow-up and access reviews.

See where Orbitra fits alongside Microsoft

Start with visibility.
Choose when to act.

Assessment uses a separate read-only application. Review your exposure before considering response permissions.

Read the permissions and trust details
1

Connect read-only

Admin consent to eight Microsoft Graph read permissions. Azure inventory also depends on the Azure access you configure.

See the eight read permissions
  • User.Read.All
  • Group.Read.All
  • Member.Read.Hidden
  • Application.Read.All
  • Directory.Read.All
  • RoleManagement.Read.Directory
  • AuditLog.Read.All
  • Device.Read.All
2

Review a proposed response

Inspect the exact target, scope, reversibility, and available verification. Your team can remain in Recommend mode.

3

Consent separately, approve by name

Execution uses a separate action application. Microsoft consent grants that app's configured permissions; policy, action-specific checks, and named approval govern each response.

Show who approved it.
Show what changed.

Give the next reviewer the same record: the available before-state, named approval, action result, and verification. Make the specific outcome and any remaining uncertainty clear.

Inspect an illustrative evidence record

Before and afterThe specific state the response was intended to change.

Decision and attributionA named approver, action target, and recorded outcome.

Verification with boundariesConfirmed change, pending verification, and remaining access kept distinct.

Integrity checksSHA-256 supports file checking. It does not certify compliance.

Practical answers for Microsoft identity teams.

Licensing

Privileged access without Entra ID P2

Access reviews

Find every Global Administrator

Response

What containment verification proves

Before you connect.

What does Orbitra Security do?

Orbitra provides identity threat detection and response for Microsoft Entra ID and Azure. It brings access inventory, supported privilege-path analysis, and its own detections into an investigation, then executes named-approved responses and verifies supported changes in Microsoft.

Does Orbitra act without a person approving?

Every Orbitra-executed response requires a named human approver today. In Recommend mode, your team acts. In Approve mode, Orbitra executes the approved action after policy and permission checks. Autonomous execution is not available in production.

Does the review require write permissions?

No. Assessment starts with a separate read-only application. Response requires separate consent to the action application and a named approval. Microsoft grants the permissions configured for that application; consent is not limited automatically to a single response pack.

Does Orbitra replace Microsoft security tools?

Orbitra works alongside Microsoft Defender, Entra ID Protection, and PIM. It adds its own identity detections, access analysis, prioritized remediation, and an approved response workflow. Available telemetry and Microsoft features depend on your licenses and configuration.

What does verified mean?

For a supported action, Orbitra reads the relevant state back from Microsoft after execution. A removed role assignment verifies that specific change. It does not prove every access path or issued token is gone. Evidence distinguishes provider acceptance from verification.

More questions answered

Bring one identity risk.
See the response.

Book a 30-minute walkthrough with a founder. Follow an investigation, review the proposed action, and inspect the result in a demonstration tenant. No connection to your tenant is needed.

  1. Choose a scenario. An unexpected admin grant, a risky application, or a response you need to verify.
  2. Follow the action. See the evidence, exact target, named approval, execution, and supported verification.
  3. Decide whether there is a fit. If useful, scope a read-only assessment with the permissions and Microsoft licensing explained.

Rahul or Leonard replies within one business day.
Prefer email? hello@orbitrasecurity.com

No tenant connection is needed for the walkthrough. We onboard each tenant with you. Your details go to the Orbitra founders (privacy policy).