Every identity in Entra ID, and who answers for it
Users, guests, admins, service principals, devices and agent identities, read through the Graph API into a subscription you already own. Every finding comes with what it means, who owns it, and what to do next.
Where it sits
Bsure sits on top of your Microsoft tenant. Which means you are, too
Read-only, in your own subscription. Everything below it keeps running as it is.
bsure
read-only
Every account, its owner, its next step
Microsoft Graph
read
your microsoft tenant
identities · sign-ins · apps · agents · devices · licenses
Entra ID
PIM
IGA
PAM
Your tools set and enforce the rules
Bsure covers Microsoft only, and goes deeper into it. What the category is, and who defined it →
What comes out of it
What one finding tells you
The list is ranked by the priorities you set and updated once a day, after data collection. Every finding on it opens into the same six things.
What teams use it for
How it works
From Entra ID to a named owner, in five steps
All of it runs inside your own subscription.
Bsure surfaces and routes. Every change is made by your people, in your own tools.
Newest in the product
New in Bsure
What it is
Bsure is an Azure Managed Application
It installs from Azure Marketplace into a subscription you already own, and it runs there.
where it runs
In your own subscription
Seven Azure resources in a managed resource group in your subscription.
What gets created
what it can change
Read-only, by design
Ten Graph permissions, all read, held by a managed identity. No secret to rotate or leak.
Kenneth Blix Arna, IT manager, Sandefjord kommune

