Orbitra Security provides identity exposure and response for Microsoft Entra ID and Azure. It connects access inventory, supported privilege path analysis, detections, remediation priorities, and human-approved response evidence.
What Orbitra is
Orbitra helps a team understand which human and workload access matters, investigate identity events, approve a specific response, and inspect evidence of the resulting change. It combines its own analysis and detections with Microsoft telemetry available to the tenant.
It works alongside Microsoft Defender, Entra ID Protection, and PIM. Every Orbitra-executed action requires a named human approver today. Read the workflow and its coverage boundaries.
Who it is for
Orbitra is built for lean security teams without a dedicated identity specialist: typically one to five people responsible for security at a company of 200 to 5,000 employees running Microsoft 365 Business Premium or E3. These teams already hold Global Administrator, own the tenant, and get the page when something goes wrong, but they rarely have a full-time identity engineer. Orbitra gives them a governed way to act on privileged identities and the evidence to show what was done, by whose authority, and what Microsoft showed afterwards.
Read more on what Orbitra does for lean security teams and how it works on Business Premium and E3.
The founding view
A finding needs context, a decision, and follow-through. The founders built Orbitra to connect those steps, with three requirements for the response itself.
- Governed. Every response comes from an allowlisted catalog and is pre-authorized by tenant policy, not decided by a model. AI can summarize evidence and recommend from the allowlisted catalog; deterministic policy owns execution. Orbitra tells you which steps are permanent before you approve them, and rollback is provided where the provider action is truly reversible; otherwise Orbitra provides a defined recovery path.
- Verified. An accepted API call is not proof. After supported response actions Orbitra independently re-reads Microsoft and records the observed state next to the intended state. Verification establishes the specific state checked, not the absence of every remaining access path.
- Evidenced. Every response produces an attributable evidence receipt with a SHA-256 content fingerprint: the available before-state, action result, verification outcome, and named approval. Evidence exports are designed to support audit and insurer review.
Orbitra connects Microsoft identity exposure analysis to approved response and evidence. It inventories human and workload access, prioritizes supported Entra privilege paths, and re-reads Microsoft state for supported actions. A named person approves every Orbitra-executed response today. See the workflow and coverage limits, or request a read-only exposure review.
The team
Built by people who have defended real environments.
Rahul Kumar
Co-Founder and CEO
15+ years cybersecurity go-to-market. Knows how CISOs buy, what they fear, and what makes them act.
Leonard Esere
Co-Founder and CTO
Cloud Security Solutions Architect at Los Alamos National Laboratory, and previously secured Azure infrastructure for 20,000+ users at MITRE.
Michael Gorelik
Chief Architect and Advisor
Co-founder and CTO of Morphisec. 8+ patents in threat detection. DEF CON, Black Hat and BlueHat speaker.Company facts
- Orbitra Security is a Canadian company.
- Regional response and connection records use your workspace's United States or India home region. Shared ownership and authorization metadata and automatic application reports use US services. The data use page explains processing locations and reporting.
- Onboarding is invite-only through Microsoft Entra single sign-on. There is no self-serve signup; every tenant is onboarded together with you, with consent, policy posture, approvers, and region set on a call.
- Prices are not published. Orbitra quotes after a privilege exposure review, once the scope is known. The plans page describes the model.
- Orbitra holds no compliance certification and will not imply one. The trust page lists what is offered instead, and the security page covers vulnerability disclosure.
- Found something on this site that overstates what Orbitra does? Tell us at hello@orbitrasecurity.com and we will correct it.
To reach the team, write to hello@orbitrasecurity.com or use the contact page. For the questions a Microsoft admin asks before connecting anything, see the FAQ; for practical how-tos and definitions, see the guides and the glossary; to see the product in your own tenant, read-only first, request a demo.