The message arrives a few weeks before renewal. Your broker forwards the carrier's questionnaire, or an auditor sends a control list, and it asks how many Global Administrators you have, whether each one uses multifactor authentication, how often privileged access is reviewed, and what happens when an administrator account is compromised. A one to five person team on Microsoft 365 Business Premium or E3 can answer all four, but only with facts pulled from Microsoft Entra ID in a form an outsider can check. This page is about that evidence, not compliance: Orbitra holds no certification and is on no carrier's approved-control list. It sits alongside the Orbitra guides and glossary on privileged identity response.
The four questions insurers and auditors ask
Wording varies by carrier; substance does not. Each question maps to an artifact.
| Question | What is being checked | What answers it |
|---|---|---|
| How many Global Administrators do you have? | Whether the count is small and known. Microsoft says fewer than five Global Administrators and fewer than ten privileged role assignments. | A dated list of every holder, human and non-human, against Microsoft's guidance. See how many Global Admins you need. |
| Is MFA enforced on every administrator? | Whether a password alone can sign an administrator in. | Your Conditional Access policies, or PIM role settings on P2, exported from Entra. Not produced by Orbitra. |
| How often is privileged access reviewed? | Whether assignments are re-examined on a schedule; Microsoft lists recurring access reviews as a best practice. | A dated export at each review, and the difference from the previous one. |
| What happens when an administrator account is compromised? | Whether you have a response and can prove what you did and when. | An evidence receipt per response: target, approver, before-state, after-state (independently re-read for supported actions), fingerprint. See the compromised admin account guide. |
Thorough forms add a fifth: emergency access accounts, and when they were last tested. Microsoft says to validate them at least every 90 days and after IT staff changes; the evidence is the dated record of each test (see the break-glass account guide).
Why "pull it from the portal" runs out after 30 days
Business Premium and E3 include Microsoft Entra ID P1. On P1 and P2, Entra keeps audit logs and sign-in logs for 30 days; on Free, 7 days. Microsoft's monitoring FAQ puts it at between 7 and 30 days depending on license. A question about what changed in privileged roles over the policy year asks for data the portal no longer holds, unless you exported it or sent it through diagnostic settings to Log Analytics, a storage account, or an event hub before the window closed. Privileged Identity Management adds downloadable audit history and access reviews of role holders, but it is a P2 feature most Business Premium and E3 teams lack (see PIM without P2). Privileged access evidence therefore has to be captured on a cadence, dated, and kept outside the 30-day window, or it does not exist when the question arrives.
What a read-only connection produces in the first session
Orbitra connects to Microsoft Entra ID and Azure through Microsoft Graph and Azure APIs: agentless, nothing installed on endpoints. It starts read-only, eight read scopes for assessment, with response permissions consented separately and only if you choose to. Connecting read-only takes minutes; a complete first sync of a larger tenant takes longer. The first session produces three things.
- Privileged role holders, human and non-human. Every user and service principal holding Global Administrator, Privileged Role Administrator, or another Entra directory role Microsoft flags as privileged. Service principals with directory roles rarely appear on questionnaires and often appear in incidents.
- Blast radius for each. What each privileged identity can reach across users, groups, applications, service principals, roles, and Azure RBAC. Blast radius shows what an identity can reach before you act, and what remains reachable after. It is impact, not proof of exploitability.
- A dated export with a SHA-256 content fingerprint, so the copy filed with the renewal can be shown later to be unchanged since capture. Two dated exports, one per review, are your review record.
It does not produce Conditional Access policy state or an MFA registration inventory; neither is part of the assessment today.
The evidence receipt for any response
When a response happens (a suspected administrator compromise, a service principal holding a role it should not, an illicit consent grant to revoke), the fourth question becomes concrete: what did you do, who approved it, how do you know it worked. Every response in Orbitra produces an attributable evidence receipt recording:
- Target. The identity or object the action touched.
- Approver. Who reviewed and approved, and when. In Recommend mode, Orbitra proposes the response and your team executes it. In Approve mode, a named person signs off before Orbitra executes.
- Before-state. What Microsoft returned for the target before the action ran.
- Verified after-state. Orbitra independently re-reads Microsoft after supported response actions to verify the final state, and distinguishes submitted, propagating, verified, residual access, and recovered rather than a single "contained" (see containment verification).
- Four timestamps. Signal observed, plan ready, action submitted, provider verified.
- A SHA-256 content fingerprint on the export.
Two honest limits. The fingerprint is a content hash, not a signature: it shows the file has not changed since capture, not who produced it. And session revocation, password reset, credential removal, Azure role assignment removal and PIM changes are permanent, while Entra directory role and group membership removals can be restored within the undo window (24 hours by default); Orbitra tells you which steps are permanent before you approve them.
The honest line on MFA, and what Orbitra is not
MFA enforcement for administrators lives in Microsoft's controls. Microsoft states that MFA can be enforced on Entra roles through PIM role settings or through Conditional Access, and attributes to its own studies the figure that an account is 99.9 percent less likely to be compromised when MFA is used. Orbitra does not enforce MFA, does not write Conditional Access policy, and does not report MFA registration state today; the answer to that question is your Conditional Access policy export from Entra.
Orbitra is also on no carrier's approved-control list, holds no compliance certification, and does not replace Microsoft Defender, a SIEM, or a log archive. It works alongside Microsoft native controls; Orbitra owns the governed response and evidence layer between detection and directory recovery. If a form has a checkbox for a named control category, Orbitra is not that checkbox. It is the evidence behind several answers: who held privilege on a date, what they could reach, and what changed when you acted.
Where Orbitra fits
Orbitra is privileged identity response for Microsoft Entra ID and Azure, built for lean security teams without a dedicated identity specialist. Connect Microsoft in minutes and start read-only; that first connection cannot execute a response. Actions come from an allowlisted catalog of more than two dozen governed response actions, every supported response is governed by tenant policy, and every response produces an attributable evidence receipt with a SHA-256 content fingerprint. Every customer tenant uses Recommend or Approve today, and Autonomous mode has never executed in a customer tenant. See how it works and the trust page.
What to send when the questionnaire arrives
- The dated privileged role export. Every Global Administrator and other privileged role holder, human and non-human, counted against Microsoft's fewer-than-five guidance.
- The Conditional Access policy export from Entra showing MFA required for administrators. From Microsoft, not Orbitra.
- The previous review's export, so the reviewer sees what changed between the two dates.
- The dated emergency access account validation record, at least every 90 days per Microsoft.
- Evidence receipts for any privileged access response in the period, with your written procedure.
The fastest route to the first item is a read-only connection; the first dated export comes out of the first session. See also identity response on Business Premium and E3, lean security teams, and plans for how a pilot is scoped.
Sources
- Privileged roles and permissions in Microsoft Entra ID, checked September 2026
- Best practices for Microsoft Entra roles, checked September 2026
- Manage emergency access admin accounts in Microsoft Entra ID, checked September 2026
- What is Microsoft Entra Privileged Identity Management, checked September 2026
- Microsoft Entra ID Governance licensing fundamentals, checked September 2026
- Microsoft Entra data retention, checked September 2026
- Microsoft Entra monitoring and health FAQ, checked September 2026
Frequently asked questions
Does Orbitra satisfy my insurer's MFA requirement for administrators?
No. MFA enforcement lives in Microsoft's controls: Microsoft states that MFA can be enforced on Entra roles through PIM role settings or through Conditional Access. Orbitra does not enforce MFA, does not write Conditional Access policy, and does not report MFA registration state today. The evidence for that question is your Conditional Access policy export from Entra.
Is Orbitra on my carrier's approved-control list?
No. Orbitra is not on any carrier's approved-control list and holds no compliance certification. What it produces is evidence: a dated, SHA-256 fingerprinted record of who holds privilege in your tenant, what each identity can reach, and what changed when your team responded, designed to support audit and insurer review.
Why can't I pull the last twelve months of admin changes from the Entra portal?
Because Microsoft Entra keeps audit and sign-in logs for 30 days on P1 and P2, which is what Business Premium and E3 include, and 7 days on Free. Anything older exists only if you exported it or set up diagnostic settings to Log Analytics, a storage account, or an event hub before the window closed. Evidence for a policy year has to be captured on a cadence and kept outside Entra.
Does a read-only connection change anything in my tenant?
No. Orbitra starts read-only with eight read scopes for assessment; response permissions are consented separately and only if you choose to. It is agentless, connects through Microsoft Graph and Azure APIs with nothing installed on endpoints, and cannot execute a response while the connection is read-only.
What exactly is in an evidence receipt?
The target identity or object, who approved the action and when, the before-state read from Microsoft, the after-state Orbitra independently re-read from Microsoft for supported actions, four timestamps (signal observed, plan ready, action submitted, provider verified), and a SHA-256 content fingerprint on the export. The fingerprint proves the file has not changed since capture; it is a content hash, not a signature.