Primary assessment
Entra workload & non-human identity assessment
Most tenants are governed as if only people hold access. Some of the broadest and least-visible access in a tenant belongs to identities no one logs into: service principals, app registrations, managed identities, and the automations and AI agents built on them. This assessment examines that layer directly — what these identities can reach, what credentials they hold, who is accountable for them, and whether any of that is still true by intention rather than by accident.
The report documents each material finding with the Graph query or portal evidence behind it, the practical impact in this tenant, and specific remediation guidance — including credential replacement, permission reduction, and ownership assignment.
Object examined
Question asked
Enterprise applications and app registrations
What has been integrated into the tenant, whether each integration is still used, and whether its configuration matches its stated purpose.
Service principals and managed identities
Which non-human identities exist, what they can access, and whether each has a named, accountable owner.
Graph application and delegated permissions
What each identity is permitted to do, whether application-scope permissions are justified, and where broad rights like Mail.Read or Directory access sit unreviewed.
OAuth consent grants
Which applications hold delegated access on behalf of users, at what scopes, and whether each grant remains necessary and proportionate.
Application secrets and certificates
Credential age, expiry, and validity windows — which credentials are long-lived, approaching expiry unnoticed, or past rotation with no replacement plan.
Privileged role assignments held by workload identities
Whether any service principal holds directory roles, and whether that standing privilege is deliberate, documented, and monitored.
Stale and orphaned integrations
Which connected applications have gone quiet — no sign-in activity, no owner, no remembered purpose — and what they could still reach.
Ownership and human accountability
Whether every non-human identity maps to a person responsible for its rotation, review, and eventual removal.
AI agents are assessed as what they are in the tenant: non-human identities with credentials, permissions, and trust boundaries. The same objects, the same questions.