Orbitra does not publish prices, and there is no self-serve signup. Every engagement follows the same three steps: a privilege exposure review, a read-only pilot in your own tenant, and a written quote once we both know the scope. This page explains each step, what a subscription includes, and how your Microsoft licensing affects it (it does not). For the product itself, start with how Orbitra works.
Step one: the privilege exposure review
The review is a 30-minute call with an Orbitra founder. It is read-only and it costs nothing. Orbitra connects to your Microsoft Entra ID tenant through Microsoft Graph and Azure APIs using read scopes only, with nothing installed on endpoints, and builds the privilege graph: which people hold Global Administrator and other privileged roles, which service principals and app registrations carry high-privilege permissions or broad consent grants, and what each of those identities can reach.
You keep the map. Whether or not we go further, you leave the call with the privilege graph for your tenant and a short list of what stood out. Nothing acts during the review. Response permissions are a separate consent that you may never grant.
To book one, use the review request form or contact the team. A founder replies within one business day to agree a slot.
Step two: the read-only pilot
If the review shows something worth watching, we agree a pilot on the same call: how long it runs, which region holds your data (United States or India), and who on your side would approve anything later. The pilot runs inside your tenant and stays read-only throughout.
During the pilot Orbitra keeps the privilege graph current on every sync and runs streaming detection on Entra sign-in and audit logs, with detections in minutes. For any detection or identity your team opens, Orbitra shows the response plan it would recommend from its allowlisted catalog, which steps in that plan would be permanent, and what the identity could still reach afterwards. Your team sees what a governed response looks like before consenting to any write scope.
The pilot ends with a walkthrough of what was found and, if you want to continue, a written quote.
What a subscription includes
- The privilege graph for human and non-human identities: users, groups, applications, service principals, OAuth grants, managed identities, directory roles, and Azure RBAC in one graph with blast radius traversal. You see what an identity can reach before you act, and what remains reachable after.
- Streaming detection with more than 70 deterministic detection rules. Roughly 40 percent of them target applications, service principals, consent grants, and app credentials.
- The governed response catalog: more than two dozen governed response actions across the identity provider, cloud access, OAuth, and non-human identities. Every action comes from the allowlisted catalog with a reversibility contract, and Orbitra tells you which steps are permanent before you approve them.
- Recommend, Approve, and Autonomous tiers, set per risk tier by your tenant policy. Every customer tenant uses Recommend or Approve today, and Autonomous mode has never executed in a customer tenant. If you later enable it for a response pack, Orbitra acts only within the threat classes, action allowlist, and blast-radius limits you pre-authorized.
- Independent verification: Orbitra independently re-reads Microsoft after supported response actions to verify the final state, and distinguishes submitted, propagating, verified, residual access, and recovered. See containment verification.
- Evidence packs with a SHA-256 content fingerprint on every export and four timestamps on every incident: signal observed, plan ready, action submitted, provider verified. They are designed to support audit and insurer review.
- Approvals in Slack, Microsoft Teams, and email through expiring links. A link opens the approval for review; it never executes on its own.
- Undo within a 24-hour window by default where the provider action is truly reversible, and a defined recovery path where it is not.
- Two production regions, United States and India, with immutable data residency chosen when you connect.
Where Orbitra fits
Orbitra works alongside Microsoft native controls and owns the governed response and evidence layer between detection and directory recovery. In Recommend mode, Orbitra proposes the response and your team executes it. In Approve mode, a named person signs off before Orbitra executes. It is built for lean security teams without a dedicated identity specialist.
Works at any Microsoft license level
Orbitra works at any Microsoft license level. Business Premium, E3, and E5 tenants connect the same way, with the same 8 read scopes for assessment and the same 11 fine-grained write scopes for response, consented separately, using the narrowest Microsoft scope wherever one exists. You do not need to change your Microsoft licensing to run the review or the pilot.
If you are on Business Premium or E3, see identity response on Business Premium and E3 and the guide to privileged access without Entra ID P2.
How the quote works
We quote after the review, once we both know the scope. Scope means what the graph found in your tenant, which response packs you want governed, which region holds your data, and who needs to approve. The quote is written, specific to your tenant, and comes with the pilot findings attached so the people who sign it can see what it pays for.
What we will not do is put a number on this page. A figure that is right for one tenant is wrong for another, and a single figure safe for every tenant would be padded. If you need a rough figure before the review for budgeting, ask, and we will tell you what we can once we know a little about your tenant. Common questions about scope, licensing, and permissions are also answered on the FAQ page.
Sources
- This page describes Orbitra's own engagement model and cites no Microsoft documentation. Product statements follow the same claims register as How it works and Trust. Checked September 2026.
Frequently asked questions
Why does Orbitra not publish prices?
We quote after the privilege exposure review, once we both know the scope: what the graph found in your tenant, which response packs you want governed, and which region holds your data. A number on a web page would either be wrong for your tenant or padded to be safe for every tenant, so we give you a written quote for yours instead.
Is there a free trial?
There is no self-serve signup and no trial you can start on your own. The privilege exposure review costs nothing, you keep the privilege map it produces, and the read-only pilot that follows is agreed on that call.
How long does a pilot run?
The length is agreed on the review call. It depends on what the review found and how much of your tenant you want observed before deciding. The pilot stays read-only for the whole period, so it cannot execute a response.
Can our MSP be involved?
Yes, inside your tenant. Your MSP's engineers can join the review, take part in the pilot, and be named as approvers, all within your tenant and with your visibility. Orbitra is single-tenant today: there is no partner console, fleet view, or cross-tenant approval.
What do we need to start the review?
A 30-minute slot and an administrator who can grant consent for the read scopes. Orbitra is agentless and connects through Microsoft Graph and Azure APIs, so there is nothing to install on endpoints.