These are the sixteen questions we hear most often from the person who will actually grant consent: the Microsoft 365 or Entra administrator on a one to five person security team. The answers are the same ones on the homepage, in the same order, so you can send a colleague this link. The pages below carry the detail.
Where the answers go deeper
- Connecting Orbitra: the read-only start on the call, and how response permissions are consented separately per response pack.
- Trust: permissions scope by scope, the two production regions, and what we can show you about our controls today.
- How it works: the response loop: detect, plan, approve, execute, verify, evidence receipt.
- Working with Microsoft: what Defender, Entra ID Protection, and PIM already do, and where Orbitra sits.
- Plans: how the review, the read-only pilot, and response packs fit together, and how a quote is scoped.
- Data use: the categories of directory and activity data Orbitra reads.
Three things to read first
If you only have a minute, these are the points the rest of the answers rest on.
- Every customer tenant uses Recommend or Approve today, and Autonomous mode has never executed in a customer tenant.
- It starts read-only. Response permissions are consented separately, scope by scope, when you enable a response pack; removing the enterprise application ends Orbitra's access.
- Containment is not complete until Orbitra re-reads Microsoft and the change held. After supported response actions it independently re-reads Microsoft to verify the final state; where an action cannot be re-read, the evidence says so.
Where Orbitra fits
Works alongside Microsoft native controls. Orbitra owns the governed response and evidence layer between detection and directory recovery. It calculates identity impact before it acts, and every response produces an attributable evidence receipt.
If your question is not answered here, ask us directly or bring it to the privilege exposure review. Questions we hear more than once are added to this page.
Sources
- Microsoft Entra data retention: audit and sign-in logs are retained 7 days on Microsoft Entra ID Free and 30 days on P1 and P2. Checked September 2026.
Frequently asked questions
Does Orbitra replace Microsoft Defender, Entra ID Protection, or PIM?
No. Microsoft detects and scores risk, and PIM governs role activation; Orbitra sits on top as the response layer. It builds the privilege graph across your users, service principals, app registrations, and OAuth grants, calculates identity impact before it acts, executes the response your policy allows through Microsoft's own APIs, and independently re-reads Microsoft to verify the final state. You keep every Microsoft control you have today. Orbitra works with Business Premium, E3, or E5.
Will Orbitra disable accounts or revoke access on its own?
Only if you tell it to, per response pack and per risk tier. Every supported response is governed by tenant policy in one of three postures: Recommend (Orbitra proposes, you act), Approve (Orbitra prepares, a named person approves in Slack, Teams, or email, then it executes), and Autonomous (executes inside explicit bounds you set). Today every customer tenant runs in Recommend or Approve, and Autonomous mode has never executed in a customer tenant. It is enabled response pack by response pack when you decide the evidence justifies it.
What permissions does it need in our tenant?
The review and the read-only pilot use a Microsoft Entra enterprise application with read permissions granted through admin consent: User.Read.All, Group.Read.All, Member.Read.Hidden, Application.Read.All, Directory.Read.All, RoleManagement.Read.Directory, AuditLog.Read.All, and Device.Read.All. There is no agent to install. Write permissions live in a separate action application and are consented only when you enable a response pack, scope by scope. Removing the enterprise application ends Orbitra's access.
What if a response makes things worse? Can it be undone?
Each action in the catalog carries a declared reversibility contract. Where the Microsoft action is truly reversible, such as re-enabling an account or restoring a removed role or group membership, Orbitra captures the before-state and can roll back within a 24-hour window by default. Where it is not reversible, such as revoking sessions, resetting a password, or removing a credential, the contract says so before you approve and the response defines a recovery path instead. We do not claim that every action is reversible.
Could it lock out our Global Admin or break-glass accounts?
In Recommend and Approve posture nothing touches any account without a named person approving that specific action, and you can keep every privileged-role action in Approve. Orbitra does not yet have an automatic exclusion list for break-glass accounts, so bring their names to the review and we will show you exactly how they appear and how approvals protect them.
How do we know an action actually happened in Microsoft?
Orbitra never treats an accepted API call as proof. After supported response actions it independently re-reads Microsoft and records the observed state next to the intended state. If they differ, the response is marked unverified and surfaced to you. Where an action cannot be re-read, the evidence says so instead of reporting it verified.
We do not have E5. Does that matter?
No. Orbitra works at any Microsoft license level, including Business Premium and E3. Some Microsoft signals are richer on higher tiers, and the review will show you what is available on yours, but the privilege graph, the governed response catalog, verification, and evidence receipts do not depend on E5.
How long does setup take?
Connecting read-only takes minutes: an administrator grants consent and Orbitra starts reading the directory. There is nothing to install. The first full privilege map depends on tenant size. Enabling response packs takes longer because it involves your decisions about policy, approvers, and tiers, and we make those with you rather than leaving you a wizard.
Where is our data stored?
You choose one of two production regions at onboarding: United States (AWS us-west-2) or India (AWS ap-south-1). Orbitra reads the directory and activity data needed to build the privilege graph and calculate impact; the data use page lists the categories. We do not sell data, and analytics on this website run only after you accept the notice.
Are you SOC 2 or ISO 27001 certified?
Not yet, and we will not imply otherwise. What we offer today: a vulnerability disclosure program, an architecture and data-flow walkthrough with our CTO, a written description of controls, and the product's own audit trail, which produces a SHA-256 fingerprinted evidence pack for every response.
How much does it cost?
We do not publish prices. We quote after the privilege exposure review, once we both know the scope. The review costs nothing and you keep the exposure map either way.
Can we just sign up and try it?
Not self-serve, on purpose. Because Orbitra can be granted the ability to act inside your tenant, we onboard every tenant together with you: consent, policy posture, approvers, and region are set on a call, not by clicking through defaults. The fastest route is the privilege exposure review, which becomes a read-only pilot if you want it to.
We already have an MDR. Why would we add this?
Keep it. An MDR watches endpoints and identities and escalates to a human. Orbitra covers the part after the escalation: the privileged identity response itself, governed by the policy you set, executed in your tenant with a reversibility contract and an evidence receipt. Your MDR analyst can be one of the approvers in Slack or Teams.
What about service principals, app registrations, and OAuth grants?
They are first-class in the graph. Orbitra models human and non-human identities together, so a risky app grant, an over-privileged service principal, or a managed identity with standing rights shows up with the same blast radius traversal as a user with Global Administrator. Response packs for non-human identities follow the same policy tiers.
Do you support Okta, Google Workspace, or AWS IAM?
Not today. Orbitra is built for Microsoft Entra ID and Azure. We would rather do one provider with verification and reversibility than several without.
Will this help with our cyber insurance renewal?
It helps you answer the questions with evidence. Every Orbitra response produces an attributable evidence receipt showing what was done, by whose authority, and what Microsoft showed afterwards, and Microsoft Entra itself keeps audit and sign-in logs for only 30 days on P1 and P2. Orbitra is not on any carrier's approved-control list, so expect better answers on the questionnaire rather than a named premium credit.