A security team of one to five people at a company with 200 to 5,000 employees rarely includes an identity specialist. The same person who approves laptop purchases also holds Global Administrator, fills in the cyber insurance questionnaire, and gets the 2 am notification. This page describes what that team is actually holding in Microsoft Entra ID and Azure, why watching it is not enough, and how Orbitra keeps a human in charge of every response.
What a small team is actually holding
The privileged surface of a Microsoft 365 tenant is wider than the admin roster. Four things tend to sit unmanaged when nobody owns identity full time.
- Standing Global Administrators. Microsoft 365 Business Premium and E3 include Entra ID P1, not P2, and Privileged Identity Management requires Entra ID P2 or Microsoft Entra ID Governance. Without PIM, admin roles are permanent assignments, and the count grows with every migration project and every consultant. Our guide on how many Global Administrators a tenant should have covers the target and how to get there.
- App consents nobody reviewed. A user accepts an OAuth application, the grant stays in the tenant, and the application keeps whatever access it was given until the grant itself is revoked. PIM's model covers Entra roles, Azure resource roles, and groups; Microsoft's overview does not list application permissions, consent grants, or service principal credentials, so those sit outside role activation entirely. See illicit consent grant in the glossary.
- Service principal secrets. Integration accounts, scripts, and the vendor app from three years ago each hold a client secret or certificate. A new secret added outside a change window is one of the quietest ways to keep access to a tenant. The expiring client secrets guide shows how to inventory them.
- Insurer questions. The renewal questionnaire asks how many Global Administrators you have, who reviews them, and how quickly you can revoke access. Answering from memory is not evidence. The cyber insurance evidence page covers what a dated export should contain.
Why watching is not enough
Most small teams already have signals: Entra sign-in and audit logs, Defender notifications, perhaps a SIEM trial. The gap is between seeing something and knowing it is handled. Detection without verified action is just noise. A notification that a service principal gained a secret at 2 am is only useful if someone can see what that identity reaches, decide, act, and confirm the change held. In a five-person team that decision often waits until morning, and the person deciding is usually the one who also has to carry it out by hand across three portals.
Time works against the record as well. Microsoft Entra keeps audit and sign-in logs for 30 days on P1 and P2 and 7 days on Free; keeping them longer means routing them through Azure Monitor to a storage account with diagnostic settings. An insurer or auditor asking in month three what happened in month one needs a record that was written at the time, not reconstructed.
PIM, where a tenant has it, governs who holds a role and for how long. Microsoft's PIM overview describes assignment, activation, approval, extension, renewal, review, and audit history; it does not detect compromise or evaluate sign-in risk. That is the piece a lean team is missing: a governed way to respond once something is wrong. Our PIM without P2 guide covers the hardening you can do on P1 alone.
Three modes, one rule: a person stays in charge
Orbitra's response has three tiers. Your tenant policy sets the tier per response pack and per risk tier, so a low-impact cleanup and a compromised Global Administrator do not have to be handled the same way.
- Recommend. Orbitra shows the finding, the blast radius, and a recommended response from an allowlisted catalog of more than two dozen governed response actions. Nothing executes. Every tenant starts here after connecting read-only.
- Approve. Orbitra prepares the response and waits. A named person reviews the plan, sees which steps are permanent, and approves or rejects it. Only then does Orbitra execute, and it independently re-reads Microsoft after supported response actions to verify the final state.
- Autonomous. Autonomy is enabled per response pack and bounded by explicit policy. If you turn it on, Orbitra acts only within the threat classes, action allowlist, and blast-radius limits you pre-authorized, and each policy-approved step is recorded as a timeline event. Every customer tenant uses Recommend or Approve today, and Autonomous mode has never executed in a customer tenant.
Every response comes from an allowlisted catalog and is pre-authorized by tenant policy, not decided by a model. AI can summarize evidence and recommend from the allowlisted catalog; deterministic policy owns execution. For a team without an identity specialist, that means the hard decision (what to do about a compromised Global Administrator) has been made in advance, in daylight, and the on-call person is confirming rather than improvising.
Approvals from Slack, Teams, or email
A small team is not sitting in a console. Orbitra sends the approval request where the team already is: a Slack channel, a Teams channel, or email. The message carries the identity, the finding, the blast radius summary, the proposed actions, and which of them are permanent. The link is an expiring, single-purpose link that opens the review; clicking it never executes anything on its own. Destructive steps ask for a typed confirmation. The approval is recorded with who approved and when.
Two people can cover a tenant this way. One approves from a phone, and the record shows the decision was made by a person with the evidence in front of them.
What the review produces
Every response produces an attributable evidence receipt. For one incident it records:
- Four timestamps: signal observed, plan ready, action submitted, provider verified.
- The exact paths removed, what remains reachable, what was restored, and who or what authorized each step.
- The state of each action: submitted, propagating, verified, residual access, or recovered. Orbitra never shows a single "contained" state.
- Which steps were permanent and which can be undone within the undo window (24 hours by default). Session revocation, password reset, credential removal, Azure role assignment removal and PIM changes are permanent; Entra directory role and group membership removals can be restored within the window.
- A SHA-256 content fingerprint on every evidence export.
Evidence packs are designed to support audit and insurer review, and they outlive the 30-day Entra log window because they are written when the response happens. Containment time is proven per incident in your own tenant, not marketed as a number. See containment verification for what "verified" means here.
Where Orbitra fits
Built for lean security teams without a dedicated identity specialist. Orbitra works at any Microsoft license level and alongside Microsoft native controls; it owns the governed response and evidence layer between detection and directory recovery, and it does not replace Microsoft Defender, PIM, PAM, or a SOAR. It is agentless, connecting through Microsoft Graph and Azure APIs with nothing installed on endpoints, starts read-only, and response permissions are consented separately. Human and non-human identities (service principals, app registrations, OAuth grants, managed identities) sit in one graph with blast radius traversal. In Recommend mode, Orbitra proposes the response and your team executes it. In Approve mode, a named person signs off before Orbitra executes. See how it works and the trust page.
Getting started
Connect Microsoft in minutes and start read-only; that first connection cannot execute a response. Once the read-only sync has run, Orbitra lists privileged role holders, human and non-human, with the blast radius behind each, and you can export that dated list for the insurer questionnaire before consenting to any response permission. Response permissions come when you are ready to move from Recommend to Approve, not on day one. Plans are per tenant, per response pack, on an annual term; see plans or contact us for a quote.
Related reading
Sources
- Microsoft Entra ID Governance licensing fundamentals (Business Premium and E3 include Entra ID P1; PIM requires Entra ID P2 or Entra ID Governance). Checked September 2026.
- What is Microsoft Entra Privileged Identity Management (what PIM manages, what its overview does not list, no compromise detection or sign-in risk evaluation). Checked September 2026.
- Microsoft Entra data retention (audit and sign-in logs kept 30 days on P1 and P2, 7 days on Free; longer retention through diagnostic settings to a storage account). Checked September 2026.
Frequently asked questions
Do we need a dedicated identity engineer to run Orbitra?
No. Orbitra is built for lean security teams without a dedicated identity specialist. It connects read-only through Microsoft Graph and Azure APIs, shows the blast radius behind each finding in plain terms, and recommends a response from an allowlisted catalog. In Recommend mode, your team executes the response. In Approve mode, a named person signs off before Orbitra executes.
Does Orbitra work on Microsoft 365 Business Premium or E3?
Yes. Orbitra works at any Microsoft license level. Business Premium and E3 include Entra ID P1, and Orbitra does not require Entra ID P2. Where a tenant has PIM, Orbitra works alongside it: PIM governs who holds a role and for how long, Orbitra governs the response when something is wrong.
Can Orbitra act on its own?
Every customer tenant uses Recommend or Approve today, and Autonomous mode has never executed in a customer tenant. Autonomy is enabled per response pack and bounded by explicit policy; when you turn it on, Orbitra acts only within the threat classes, action allowlist, and blast-radius limits you pre-authorized, and each policy-approved step is recorded as a timeline event.
Does Orbitra replace Microsoft Defender or a SIEM?
No. Orbitra works alongside Microsoft native controls and owns the governed response and evidence layer between detection and directory recovery. It is software, not a managed detection and response service, and it does not replace Defender, PIM, PAM, a SIEM, or a SOAR.