Non-human identity assessments for Microsoft Entra ID

Service principals, app registrations, managed identities, and AI agent identities — inventoried, scored, and prioritised, with written evidence for every finding.

Book a 20-minute call

Fixed scope. Ten working days. Remote. Read-only.

The problem

Most Entra tenants hold far more non-human identities than human ones, and almost none are governed the way employee access is. They are created by scripts, pull requests and whoever needed one that week. Joiner-mover-leaver processes fire on employees, not on the apps they created — so when the owner leaves, the app keeps its permissions and its secret.

Nothing breaks, so nobody looks.

Try this in your own tenant

With Application.Read.All, this returns the number of app registrations holding a secret valid for more than a year:

PowerShell
Get-MgApplication -All | Where { $_.PasswordCredentials.EndDateTime -gt (Get-Date).AddYears(1) } | Measure-Object

What the assessment covers

44 checks across seven weighted dimensions:

Assessment dimensions and their weighting
DimensionWeightRelative weight
Inventory & Ownership15%
Credential Hygiene20%
Permission Scope20%
AI & Agent Exposure15%
Lifecycle & Governance10%
Monitoring & Traceability15%
Regulatory Mapping5%

What you receive

How it works

Example finding

From a lab tenant built for calibration — synthetic data.

The directory reported 73% ownership coverage. All 151 owner records resolved to a single principal — an external guest account. The metric was accurate, and effective accountability was one identity outside the organisation's control.

About

Dharma Ramasamy. 26 years in enterprise IT. Eleven years at Centene, a Fortune 25 healthcare payer, owning enterprise SSO and federation across 21 external vendor partners under HIPAA — including signing-certificate rotation and metadata lifecycle where a lapse took members offline.

Earlier: Mastercard, Edward Jones, Anheuser-Busch, AT&T.

LinkedIn