An identity inventory tells you who has access. Path analysis helps explain how that access reaches a privileged role. Orbitra connects that analysis to proposed remediation so the team can decide what to change and retain evidence of the approved result.
Start with the access relationship
A user may hold an Entra role directly or reach it through a supported group or ownership relationship. The useful question is not simply whether the identity is privileged. It is which relationship creates that privilege, whether it is required, and what other access would remain if it changed.
Orbitra inventories users and workload identities, including service principals, application registrations, grants, and managed identities. Azure RBAC inventory is also available where Azure access is configured. That broader inventory should not be confused with the narrower path engine described below.
What the path analysis currently covers
- Direct Entra role assignments.
- Nested group membership paths up to three levels.
- Application ownership paths.
- Ownership of role-assignable groups.
The current Entra engine does not enumerate Azure RBAC escalation, PIM eligibility, delegated OAuth paths, or role-to-role escalation. A path indicates supported access exposure, not confirmed exploitation. Missing a path in this analysis is not evidence that no route exists.
Use Keystone to compare proposed fixes
Keystone ranks candidate access changes by the analyzed privilege paths they remove. A what-if view helps the reviewer compare a proposed change before acting. The prioritized sequence is a practical decision aid; it is not a guarantee of the mathematically smallest fix set or complete attack-path coverage.
For example, an unnecessary direct Global Administrator assignment creates a clear review target. Removing that assignment changes one relationship. The team still needs to check other roles and memberships and establish whether the access is required for an operational purpose.
Keep exposure separate from compromise
Standing privilege is an exposure. An unexpected grant is a signal that needs context. Orbitra brings posture, audit events, and available sign-in signals into investigation so the reviewer can distinguish routine administration from suspicious activity. Available telemetry depends on Microsoft licenses and configuration.
Connect the decision to a verified change
In Recommend mode, your team acts on the proposed fix. In Approve mode, a named person approves the target and action before Orbitra executes, subject to policy and permissions. Autonomous execution is not available in production. Response requires separate consent to the action application.
For supported actions, Orbitra re-reads Microsoft state after execution. An absent role assignment verifies that removal; it does not establish the absence of all other access. Follow the six-stage example and inspect its illustrative evidence record.
Make the assessment useful to your team
Bring a question about standing admin access, application ownership, or risky group membership to a privilege exposure review. Establish which inventory and path patterns are available, compare a proposed change, and decide which evidence your access review needs.
Related guidance: find Global Administrators, privileged access without Entra ID P2, and Orbitra permissions and security.