Every identity in Entra ID, and who answers for it

Users, guests, admins, service principals, devices and agent identities, read through the Graph API into a subscription you already own. Every finding comes with what it means, who owns it, and what to do next.

A field of points, one point per identity in a demo tenant. Five of them are called out by what is wrong with them: a guest with no sign-in in 14 months, an E5 license never opened, an admin role with no time limit, a secret that expired last month, and an agent identity with no owner.
A field of points, one point per identity in a demo tenant. Five of them are called out by what is wrong with them: a guest with no sign-in in 14 months, an E5 license never opened, an admin role with no time limit, a secret that expired last month, and an agent identity with no owner.
A field of points, one point per identity in a demo tenant. Five of them are called out by what is wrong with them: a guest with no sign-in in 14 months, an E5 license never opened, an admin role with no time limit, a secret that expired last month, and an agent identity with no owner.

Where it sits

Bsure sits on top of your Microsoft tenant. Which means you are, too

Read-only, in your own subscription. Everything below it keeps running as it is.

Enforcing policy and knowing what is actually there are two different jobs

What it does

What it does not tell you

Entra ID

Grants access.

Who owns each account, and which have gone quiet.

PIM

Time-bound admin roles.

The permanent roles still outside it.

IGA

Provisions and reviews access.

The accounts it was never set up for.

PAM

Vaults privileged credentials.

The privilege it never onboarded.

bsure

read-only

Every account, its owner, its next step

Microsoft Graph

read

your microsoft tenant

identities · sign-ins · apps · agents · devices · licenses

Entra ID

PIM

IGA

PAM

Your tools set and enforce the rules

Bsure covers Microsoft only, and goes deeper into it. What the category is, and who defined it →

What comes out of it

What one finding tells you

The list is ranked by the priorities you set and updated once a day, after data collection. Every finding on it opens into the same six things.

Bsure · Assessments · Your list

31 agents with no accountable owner or sponsor

1

Act now

2

·

Assign an accountable owner and sponsor or accept the risk by clicking here

3

4

Drilldown · Agents Without Owner or Sponsor

Needs attention

31

of 34 total

Risk accepted

3

Target

0

Priority

Act now

Last 90 days

-3

Agent name

Agent form

Blueprint

Application permissions

Delegated permissions

Case Enrichment Onboarding Agent

Agent identity

Runtime.All

Copilot in Power Apps · Field Service

Agent identity

D365 Knowledge Agent · External Source

Agent identity

5

Select the rows, then hand them over

1 selected

Delegate

Accept risk

×

TH

T. Haugen · IT operations

✓ Selected

Open email draft

Copy instructions to clipboard

6

Rechecked on the next collection run

Active

24

Delegated

1

Ignored

0

1

What it says

Plain words and a count. No rule syntax to decode.

2

How urgent it is

Act now or act soon, ranked by the priorities you set.

3

What to do about it

The next step, in the same line. Or accept the risk, which keeps its own tab and can be reopened.

4

What is behind it

Drilldown opens its own page: every agent, its form, its blueprint and its permissions, with filter, sort and export.

5

Who owns it

Select the rows and delegate to anyone in your Entra tenant, with the email draft ready. No Bsure account needed.

6

What happens next

The change is made in your own tools. The next run checks whether it stuck.

Real finding, real drilldown and real rows from a demo tenant.

Bsure · Assessments · Your list

31 agents with no accountable owner or sponsor

1

Act now

2

·

Assign an accountable owner and sponsor or accept the risk by clicking here

3

4

Drilldown · Agents Without Owner or Sponsor

Needs attention

31

of 34 total

Risk accepted

3

Target

0

Priority

Act now

Last 90 days

-3

Agent name

Agent form

Blueprint

Case Enrichment Onboarding Agent

Agent identity

Copilot in Power Apps · Field Service

Agent identity

D365 Knowledge Agent · External Source

Agent identity

5

Select the rows, then hand them over

1 selected

Delegate

Accept risk

×

TH

T. Haugen · IT operations

✓ Selected

Open email draft

Copy instructions to clipboard

6

Rechecked on the next collection run

Active

24

Delegated

1

Ignored

0

1

What it says

Plain words and a count. No rule syntax to decode.

2

How urgent it is

Act now or act soon, ranked by the priorities you set.

3

What to do about it

The next step, in the same line. Or accept the risk, which keeps its own tab and can be reopened.

4

What is behind it

Drilldown opens its own page: every agent, its form, its blueprint and its permissions, with filter, sort and export.

5

Who owns it

Select the rows and delegate to anyone in your Entra tenant, with the email draft ready. No Bsure account needed.

6

What happens next

The change is made in your own tools. The next run checks whether it stuck.

Real finding, real drilldown and real rows from a demo tenant.

How it works

From Entra ID to a named owner, in five steps

All of it runs inside your own subscription.

1.0

Read

Ten Microsoft Graph permissions, all of them read. Nothing is written back.

What is read


Microsoft Graph · read-only

2.0

Join

Sign-ins, roles, app permissions and licenses attach to the same account.


Azure SQL · in your subscription

3.0

Assess

Every finding has a threshold you set. Cross it and the finding goes active.

Your thresholds


Dashboards and Power BI

4.0

Route

Every finding goes to a named person in your tenant, by email, with a link back to it.


Email draft

5.0

Verify

The list updates after the next collection run, which shows whether the change stuck.

How often


System Health · every run

1.0

Read

Ten Microsoft Graph permissions, all of them read. Nothing is written back.

What is read


Microsoft Graph · read-only

2.0

Join

Sign-ins, roles, app permissions and licenses attach to the same account.


Azure SQL · in your subscription

3.0

Assess

Every finding has a threshold you set. Cross it and the finding goes active.

Your thresholds


Dashboards and Power BI

4.0

Route

Every finding goes to a named person in your tenant, by email, with a link back to it.


Email draft

5.0

Verify

The list updates after the next collection run, which shows whether the change stuck.

How often


System Health · every run

Bsure surfaces and routes. Every change is made by your people, in your own tools.

What it is

Bsure is an Azure Managed Application

It installs from Azure Marketplace into a subscription you already own, and it runs there.

where it runs

In your own subscription

Seven Azure resources in a managed resource group in your subscription.

What gets created

what it can change

Read-only, by design

Ten Graph permissions, all read, held by a managed identity. No secret to rotate or leak.

Azure Marketplace

Reviewed and published by Microsoft

“The product gives us a completely different overview than we could achieve on our own with simple means.”

“The product gives us a completely different overview than we could achieve on our own with simple means.”

Kenneth Blix Arna, IT manager, Sandefjord kommune

Ready to secure your tenant the modern way?