The identity control plane for Entra ID and Azure

Map the identity estate. Then detect, respond, and prove it.

Orbitra builds a live graph of every human, group, service principal, managed identity and Azure role assignment in your tenant, and the relationships between them. Attack paths and blast radius come from traversing that graph, not from a checklist. Detection is weighted by what an identity can actually reach, containment runs only with the authority you grant, and most response actions are independently re-read against your tenant to confirm the change held.

30+ graph relationship types 5 min Entra connection 0 endpoint agents 16 response actions

Graph coverage spans 11 node types and 30+ relationship types across Microsoft Entra ID and Azure Resource Manager. Detection runs on a one-minute polling cadence. Most response actions are independently re-read against Microsoft Graph or Azure after execution to confirm the change held, and the finding reopens if it drifts back.

Coverage across the identity graph Microsoft Entra ID Azure RBAC Service Principals Human Identities Audit Evidence

Map, detect, respond, assure

Add to my security stack
orbitra_search_signals
ENTRA_ROLE_GRANTprivileged role assignment
SVC_KEY_CREATEDnew credential on app registration
SESSION_ANOMALYimpossible travel for admin account
Plan
  1. Traverse blast radius in the graph
  2. Propose containment
  3. Verify the change held
Orbitra Response Agent
Contain the admin consent spike and explain the blast radius.
01 Detected risky consent on CI-Deploy
02 Traversed blast radius across the graph
03 Revoked sessions, removed Global Administrator
Contained under approval. Change re-read and verified in tenant.
orbitra_manage_connections
Microsoft Entra ID Connected
orbitra_execute_response
REVOKE_SESSIONS200 OK
REMOVE_DIRECTORY_ROLE200 OK
VERIFY_APPLIEDVERIFIED
customer_response_session approval mode
TargetCI-Deploy app registration
Customer ruleApproval required for privileged role removal
ResponseRevoke sessions, remove Global Administrator
ProofApprover, API result, and independently verified final state

The four pillars

Identity security is noisy. Map the estate first, and the rest becomes decisive.

01 Map 02 Detect 03 Respond 04 Assure
MAPPED

Live graph across Entra ID and Azure role assignments

DETECTED

Risky admin consent on CI-Deploy, severity weighted by blast radius

VERIFIED

Sessions revoked, directory role removed, tenant re-read to confirm.

AUDIT READY

Hash-verified timeline exported for board and insurer review.

01

Map the identity estate before anything else.

Orbitra ingests every human, group, service principal, managed identity and Azure role assignment into one directed graph, then traverses it for attack paths and blast radius.

  • 11 node types and 30+ relationship types
  • Entra ID and Azure RBAC in the same graph
  • Attack paths and blast radius by traversal

Zero tickets to control

One control plane for the whole identity estate.

Orbitra maps the estate first, then connects detection to governed action. Human users, service principals, managed identities, app registrations, sessions, directory roles, and Azure role assignments all live in the same graph.

01 Live identity graph

Every identity and relationship in one directed graph.

Orbitra ingests 18 Microsoft Graph sources and Azure Resource Manager role data into a property graph, then traverses it for attack paths and blast radius before recommending anything.

Explore flow
02 Control plane

Choose observation, recommendation, or approval.

Teams keep sensitive steps gated while routine containment follows the policy already approved by security leadership. Autonomous execution is staged and not yet enabled for any tenant.

View modes
03 Tenant playbooks

Every response starts with your environment, not a generic ticket.

Orbitra keeps the target, owner, action, recorded final state, and approval trail tied to the same response session.

Inspect session
04 Response proof

Show exactly what changed, who allowed it, and that it actually held.

Evidence exports include before-state, API result, approver, the after-state with its verification status, and a SHA-256 content fingerprint.

Open proof trail

On your terms

You set your rules. Orbitra runs your response.

Observe, Recommend and Approve are available today. Autonomous execution is staged and not yet enabled for any tenant.

01

Recommend

The agent recommends, your team executes. Every response is reviewable before anything touches your tenant.

Recommendation

Revoke active sessions for CI-Deploy and remove its Global Administrator assignment.

Approve and runDismiss
02

Approve

The agent acts step by step, and a human signs off each sensitive move before execution. Orbitra tells you which steps are permanent before you approve them.

Awaiting sign-off - step 2/4
  • Disable user
  • Revoke sessions
  • Remove directory role
  • Verify change in tenant
03

Autonomous - staged

Built, hard-gated off, and not yet enabled for any tenant. When it is turned on, it will act only on the threat classes and blast-radius limits you pre-authorize. We will stage it with design partners, on their terms.

Staged - not enabled

Autonomous execution has never run for any tenant. Observe, Recommend and Approve are live today.

Talk to us about staging
Mode status MODE: RECOMMEND - AI RECOMMENDS / YOU EXECUTE

Built for proof

Response should not end at a ticket.

Orbitra is built for lean teams that need customer-owned response, not another queue. It covers human and non-human identities across Entra ID and Azure, records every action, and independently re-reads your tenant after most response actions to confirm the change actually held.

Category Deploy time Customer-owned response Human + NHI Lean-team fit
Enterprise platformsBroad identity suites Weeks-months Tickets only Yes SOC-heavy
NHI specialistsDiscovery-first tooling Fast Detect only Machines only Partial
Outsourced servicesManaged security providers Hours Vendor-owned Yes Low ownership
OrbitraThe identity control plane 5 minutes You control it Both Purpose-built

Evidence

Detection without verified action is just noise.

Cyber insurers increasingly expect proof of customer-owned response workflows. Orbitra produces the timeline, the approver trail, the after-state with its verification status, and a hash-verified evidence pack. Some containment actions can be undone; others cannot. Session revocation, password reset, credential removal and role changes are permanent. Orbitra tells you which is which before you execute.

audit_record export
10:14:02DETECTEDanomalous privileged grant
10:14:05RECOMMENDEDrevoke sessions + remove directory role
10:14:29APPROVEDj.okafor / security lead
10:14:43CONTAINEDsessions revoked / role removed
10:19:43VERIFIEDtenant re-read / change held

The operators

Built by people who have defended real environments.

Rahul Kumar

Rahul Kumar

Co-Founder and CEO

15+ years cybersecurity go-to-market. Knows how CISOs buy, what they fear, and what makes them act.
Leonard Esere

Leonard Esere

Co-Founder and CTO

12+ years designing and shipping security solutions. Cloud Security Solutions Architect at Los Alamos National Laboratory, and previously secured Azure infrastructure for 20,000+ users at MITRE.
Michael Gorelik

Michael Gorelik

Chief Architect and Advisor

Co-founder and CTO of Morphisec. 8+ patents in threat detection. DEF CON, Black Hat and BlueHat speaker.

Close the loop

The window is open. Close it.

See how Orbitra maps your identity estate, detects with graph context, contains under the authority you grant, independently re-reads your tenant to confirm most changes held, and exports hash-verified evidence.

Connected to your Entra tenant in five minutes. No endpoint agents.