Non-human identity assessments for Microsoft Entra ID
Service principals, app registrations, managed identities, and AI agent identities — inventoried, scored, and prioritised, with written evidence for every finding.
Fixed scope. Ten working days. Remote. Read-only.
The problem
Most Entra tenants hold far more non-human identities than human ones, and almost none are governed the way employee access is. They are created by scripts, pull requests and whoever needed one that week. Joiner-mover-leaver processes fire on employees, not on the apps they created — so when the owner leaves, the app keeps its permissions and its secret.
Nothing breaks, so nobody looks.
Try this in your own tenant
With Application.Read.All, this returns the number of app registrations holding a secret valid for more than a year:
Get-MgApplication -All | Where { $_.PasswordCredentials.EndDateTime -gt (Get-Date).AddYears(1) } | Measure-Object
What the assessment covers
44 checks across seven weighted dimensions:
| Dimension | Weight | Relative weight |
|---|---|---|
| Inventory & Ownership | 15% | |
| Credential Hygiene | 20% | |
| Permission Scope | 20% | |
| AI & Agent Exposure | 15% | |
| Lifecycle & Governance | 10% | |
| Monitoring & Traceability | 15% | |
| Regulatory Mapping | 5% |
What you receive
- A scored posture across all seven dimensions
- A critical findings table ranked by blast radius — each finding names the identity, its permissions, its owner status and its credential age
- A 30/60/90-day remediation roadmap tied to specific failed checks
- Written evidence for every check, suitable for audit files
How it works
- Read-only Microsoft Graph collection. No write permissions, ever.
- Permissions are consented by you and revoked the day the assessment ends.
- Metadata only: names, IDs, permissions, credential dates. Never content.
- A data processing agreement is available on request.
- Questions no collector can answer are covered in two structured 60-minute interviews.
Example finding
The directory reported 73% ownership coverage. All 151 owner records resolved to a single principal — an external guest account. The metric was accurate, and effective accountability was one identity outside the organisation's control.
About
Dharma Ramasamy. 26 years in enterprise IT. Eleven years at Centene, a Fortune 25 healthcare payer, owning enterprise SSO and federation across 21 external vendor partners under HIPAA — including signing-certificate rotation and metadata lifecycle where a lapse took members offline.
Earlier: Mastercard, Edward Jones, Anheuser-Busch, AT&T.