These are the sixteen questions we hear most often from the person who will actually grant consent: the Microsoft 365 or Entra administrator on a one to five person security team. The homepage covers the essentials; this page adds operational detail. The pages below carry the detail.
Where the answers go deeper
- Connecting Orbitra: the read-only start on the call, and how response permissions are consented through the separate action application.
- Trust: permissions scope by scope, the two production regions, and what we can show you about our controls today.
- How it works: the response loop: detect, plan, approve, execute, verify, evidence receipt.
- Working with Microsoft: what Defender, Entra ID Protection, and PIM already do, and where Orbitra sits.
- Plans: how the review, the read-only pilot, and response packs fit together, and how a quote is scoped.
- Data use: the categories of directory and activity data Orbitra reads.
Three things to read first
If you only have a minute, these are the points the rest of the answers rest on.
- Every Orbitra-executed response requires a named human approver today. Autonomous execution is not available in production.
- It starts read-only. Response permissions are consented through a separate action application with its configured permission set; removing the enterprise application ends Orbitra's access.
- An accepted request and a verified state change are distinct outcomes. After supported response actions it independently re-reads Microsoft to verify the final state; where an action cannot be re-read, the evidence says so.
Orbitra connects Microsoft identity exposure analysis to approved response and evidence. It inventories human and workload access, prioritizes supported Entra privilege paths, and re-reads Microsoft state for supported actions. A named person approves every Orbitra-executed response today. See the workflow and coverage limits, or request a read-only exposure review.
If your question is not answered here, ask us directly or bring it to the privilege exposure review. Questions we hear more than once are added to this page.
Sources
- Microsoft Entra data retention: audit and sign-in logs are retained 7 days on Microsoft Entra ID Free and 30 days on P1 and P2. Checked September 2026.
Frequently asked questions
Does Orbitra replace Microsoft Defender, Entra ID Protection, or PIM?
Orbitra works alongside Microsoft Defender, Entra ID Protection, and PIM. It adds its own identity detections, access analysis, prioritized remediation, and an approved response workflow. Available telemetry and Microsoft features depend on your licenses and configuration.
Will Orbitra disable accounts or revoke access on its own?
Every Orbitra-executed response requires a named human approver today. In Recommend mode, your team acts. In Approve mode, Orbitra executes the approved action after policy and permission checks. Autonomous execution is not available in production.
What permissions does it need in our tenant?
No. Assessment starts with a separate read-only application. Response requires separate consent to the action application and a named approval. Microsoft grants the permissions configured for that application; consent is not limited automatically to a single response pack. Assessment requests User.Read.All, Group.Read.All, Member.Read.Hidden, Application.Read.All, Directory.Read.All, RoleManagement.Read.Directory, AuditLog.Read.All, and Device.Read.All.
What if a response makes things worse? Can it be undone?
Each action in the catalog carries a declared reversibility contract. Where the Microsoft action is truly reversible, such as re-enabling an account or restoring a removed role or group membership, Orbitra captures the before-state and can roll back within a 24-hour window by default. Where it is not reversible, such as revoking sessions, resetting a password, or removing a credential, the contract says so before you approve and the response defines a recovery path instead. We do not claim that every action is reversible.
Could it lock out our Global Admin or break-glass accounts?
In Recommend and Approve posture nothing touches any account without a named person approving that specific action, and you can keep every privileged-role action in Approve. Orbitra does not yet have an automatic exclusion list for break-glass accounts, so bring their names to the review and we will show you exactly how they appear and how approvals protect them.
How do we know an action actually happened in Microsoft?
Orbitra never treats an accepted API call as proof. After supported response actions it independently re-reads Microsoft and records the observed state next to the intended state. If they differ, the response is marked unverified and surfaced to you. Where an action cannot be re-read, the evidence says so instead of reporting it verified.
We do not have E5. Does that matter?
E5 is not required to start an assessment. Business Premium and E3 tenants can connect, but available sign-in data, risk signals, PIM functionality, and provider actions depend on Microsoft licensing and configuration. We confirm your coverage on the review.
How long does setup take?
Connecting read-only takes minutes: an administrator grants consent and Orbitra starts reading the directory. There is nothing to install. The first full privilege map depends on tenant size. Enabling response packs takes longer because it involves your decisions about policy, approvers, and tiers, and we make those with you rather than leaving you a wizard.
Where is our data stored?
Regional response and connection records use your workspace's United States (AWS us-west-2) or India (AWS ap-south-1) home region. Shared ownership and authorization metadata and automatic application reports use US services. The data use page lists the categories and processing locations. We do not sell data. Optional analytics on this website run only after you accept the notice; automatic application reporting operates independently of analytics choices and Do Not Track settings.
Are you SOC 2 or ISO 27001 certified?
Not yet, and we will not imply otherwise. What we offer today: a vulnerability disclosure program, an architecture and data-flow walkthrough with our CTO, a written description of controls, and the product's own audit trail, which produces a SHA-256 fingerprinted evidence pack for every response.
How much does it cost?
We do not publish prices. We quote after the privilege exposure review, once we both know the scope. The review costs nothing and you keep the exposure map either way.
Can we just sign up and try it?
Not self-serve, on purpose. Because Orbitra can be granted the ability to act inside your tenant, we onboard every tenant together with you: consent, policy posture, approvers, and region are set on a call, not by clicking through defaults. The fastest route is the privilege exposure review, which becomes a read-only pilot if you want it to.
We already have an MDR. Why would we add this?
Your MDR can remain part of the workflow. Orbitra supplies identity exposure analysis, its own detections, prioritized fixes, and governed response evidence. Agree on incident ownership and named approvers during onboarding.
What about service principals, app registrations, and OAuth grants?
Orbitra inventories service principals, app registrations, OAuth grants, and managed identities alongside users. Supported Entra paths include application ownership. Inventory coverage is broader than path analysis; Azure RBAC escalation, PIM eligibility, and delegated OAuth paths are not currently enumerated by the Entra path engine.
Do you support Okta, Google Workspace, or AWS IAM?
Not today. Orbitra is built for Microsoft Entra ID and Azure. We would rather do one provider with verification and reversibility than several without.
Will this help with our cyber insurance renewal?
It helps you answer the questions with evidence. Every Orbitra response produces an attributable evidence receipt showing what was done, by whose authority, and what Microsoft showed afterwards, and Microsoft Entra itself keeps audit and sign-in logs for only 30 days on P1 and P2. Orbitra is not on any carrier's approved-control list, so expect better answers on the questionnaire rather than a named premium credit.