Before you connect.
What does Orbitra Security do?
Orbitra provides identity threat detection and response for Microsoft Entra ID and Azure. It brings access inventory, supported privilege-path analysis, and its own detections into an investigation, then executes named-approved responses and verifies supported changes in Microsoft.
Does Orbitra act without a person approving?
Every Orbitra-executed response requires a named human approver today. In Recommend mode, your team acts. In Approve mode, Orbitra executes the approved action after policy and permission checks. Autonomous execution is not available in production.
Does the review require write permissions?
No. Assessment starts with a separate read-only application. Response requires separate consent to the action application and a named approval. Microsoft grants the permissions configured for that application; consent is not limited automatically to a single response pack.
Does Orbitra replace Microsoft security tools?
Orbitra works alongside Microsoft Defender, Entra ID Protection, and PIM. It adds its own identity detections, access analysis, prioritized remediation, and an approved response workflow. Available telemetry and Microsoft features depend on your licenses and configuration.
What does verified mean?
For a supported action, Orbitra reads the relevant state back from Microsoft after execution. A removed role assignment verifies that specific change. It does not prove every access path or issued token is gone. Evidence distinguishes provider acceptance from verification.
More questions answered ↗