Orbitra Security is privileged identity response for Microsoft Entra ID and Azure: see who holds privilege across human and non-human identities, govern each response through recommendation or named approval, and keep an attributable evidence receipt for every response. It is agentless, connects read-only in minutes, and works at any Microsoft license level.
What Orbitra is
Orbitra is software for the step after detection. Microsoft Entra ID Protection, Defender, or your MDR tells you that a privileged identity changed or misbehaved. Orbitra builds the privilege graph across users, groups, service principals, app registrations, OAuth grants, directory roles, and Azure RBAC, calculates identity impact before anything acts, and offers more than two dozen governed response actions from an allowlisted catalog. Every supported response is governed by tenant policy, and Orbitra independently re-reads Microsoft after supported response actions to verify the final state.
Orbitra works alongside Microsoft native controls rather than standing in for them, and it covers Microsoft Entra ID and Azure only. Every customer tenant uses Recommend or Approve today. In Approve mode, a named person signs off before Orbitra executes; Autonomous mode has never executed in a customer tenant. Read how it works for the response loop in detail, or see the glossary definition of privileged identity response.
Who it is for
Orbitra is built for lean security teams without a dedicated identity specialist: typically one to five people responsible for security at a company of 200 to 5,000 employees running Microsoft 365 Business Premium or E3. These teams already hold Global Administrator, own the tenant, and get the page when something goes wrong, but they rarely have a full-time identity engineer. Orbitra gives them a governed way to act on privileged identities and the evidence to show what was done, by whose authority, and what Microsoft showed afterwards.
Read more on what Orbitra does for lean security teams and how it works on Business Premium and E3.
The founding view
Detection is not response. Detection without verified action is just noise. Most identity security tooling stops at a finding or a score and leaves the containment to whoever is on call, working from memory in the Entra admin center in the middle of the night. The founders built Orbitra around three requirements for the response itself.
- Governed. Every response comes from an allowlisted catalog and is pre-authorized by tenant policy, not decided by a model. AI can summarize evidence and recommend from the allowlisted catalog; deterministic policy owns execution. Orbitra tells you which steps are permanent before you approve them, and rollback is provided where the provider action is truly reversible; otherwise Orbitra provides a defined recovery path.
- Verified. An accepted API call is not proof. After supported response actions Orbitra independently re-reads Microsoft and records the observed state next to the intended state. Containment is not complete until Orbitra re-reads Microsoft and the change held.
- Evidenced. Every response produces an attributable evidence receipt with a SHA-256 content fingerprint: the exact paths removed, what remains reachable, what was restored, and who or what authorized each step. Evidence exports are designed to support audit and insurer review.
Where Orbitra fits
Works alongside Microsoft native controls. Orbitra owns the governed response and evidence layer between detection and directory recovery. Microsoft detects and scores, PIM governs role activation, and your MDR escalates; Orbitra covers the part after the escalation, with a reversibility contract and an evidence receipt on each response. See how it works and the trust page.
The team
Built by people who have defended real environments.
Rahul Kumar
Co-Founder and CEO
15+ years cybersecurity go-to-market. Knows how CISOs buy, what they fear, and what makes them act.
Leonard Esere
Co-Founder and CTO
Cloud Security Solutions Architect at Los Alamos National Laboratory, and previously secured Azure infrastructure for 20,000+ users at MITRE.
Michael Gorelik
Chief Architect and Advisor
Co-founder and CTO of Morphisec. 8+ patents in threat detection. DEF CON, Black Hat and BlueHat speaker.Company facts
- Orbitra Security is a Canadian company.
- The product runs in two production regions, United States and India, with immutable data residency. You choose one at onboarding, and the data use page lists what is read.
- Onboarding is invite-only through Microsoft Entra single sign-on. There is no self-serve signup; every tenant is onboarded together with you, with consent, policy posture, approvers, and region set on a call.
- Prices are not published. Orbitra quotes after a privilege exposure review, once the scope is known. The plans page describes the model.
- Orbitra holds no compliance certification and will not imply one. The trust page lists what is offered instead, and the security page covers vulnerability disclosure.
- Found something on this site that overstates what Orbitra does? Tell us at hello@orbitrasecurity.com and we will correct it.
To reach the team, write to hello@orbitrasecurity.com or use the contact page. For the questions a Microsoft admin asks before connecting anything, see the FAQ; for practical how-tos and definitions, see the guides and the glossary; to see the product in your own tenant, read-only first, request a demo.