EntraOps Privileged EAM

Control Plane
under Control

Open-source tooling to classify, identify, and protect privileged access across Microsoft cloud services using the Enterprise Access Model.

A clearer control plane

Know where privilege lives.

EntraOps makes privileged access legible across your Microsoft cloud estate. It turns roles, scope, identity context and history into an operational model your team can inspect and act on.

  1. Classify with context

    Map Microsoft Entra ID, Azure RBAC, Intune, Defender and Identity Governance permissions to the Enterprise Access Model.

  2. Keep a history

    Store findings as code, compare changes in Git, and surface the movement of privileged identities over time.

  3. Protect the boundary

    Turn classified assets into stronger Conditional Access targeting and Restricted Management Administrative Unit coverage.

Tier Breach Analyzer

See when access crosses the tier boundary.

Compare intended object tiers with granted service tiers, filter every assignment path and move from an anomalous flow to the role, scope and PIM context behind it.

Tier Breach Analyzer

Tier breach, visible.

Inspect the live Sankey, filters and assignment detail behind each cross-tier access path.

Git-backed reporting

Make configuration changes visible.

Every committed export and Tenant Governance snapshot becomes inspectable evidence. Compare points in time, trace a change, then see how Conditional Access controls apply across the tenant.

Privilege History

Track the movement of privilege.

Trend privileged assets, role assignments and tier breaches from the Git history of your Privileged EAM export. Filter by RBAC system, tier and role, inspect any snapshot, or compare two points in time.

Configuration Analyzer

Trace the Conditional Access flow.

Analyze Tenant Governance configuration snapshots for drift, property-level changes and policy coverage gaps. Follow every active policy from assignment to its effective grant control.

Features

Core EntraOps capabilities.

Collect and classify privileged access, apply protection scope, and generate evidence for review and investigation.

[RBAC]

Classify every plane

Analyze Entra ID directory roles, Identity Governance, Intune, Defender XDR, Microsoft Graph app roles and Azure RBAC using customizable JSON classification templates.

[SCOPE]

Continuously discover scope

Use high-privilege roles, Azure Resource Graph and Microsoft Security Exposure Management assets to keep Control Plane scope current.

[PIM]

Follow real privilege paths

Resolve active, eligible, time-bounded and nested assignments, including PIM for Groups and Azure constrained delegation context.

[GIT]

Keep privilege as code

Export deterministic JSON, track changes in Git and generate Privilege History from the repository itself without a separate data store.

[GUARD]

Automate protection

Target classified assets with Conditional Access groups, Restricted Management Administrative Units and privileged Identity Governance catalog protection.

[MAP]

Explore without a backend

Generate six self-contained reporting apps for classification, EAM inventory, access paths, tier breaches, history and configuration analysis.

What changed

What changed in EntraOps 1.0.

Release 1.0, September 2026. A broader control plane, offline analysis, and tenant configuration history.

A practical EAM adoption path

Progress from classification to measurable control.

EntraOps provides the evidence and automation for each stage, so adopting the Enterprise Access Model becomes an iterative operational practice.

👑

Classify

Adapt the classification template to your critical scopes, services and tenant-specific roles.

🔬

Identify

Resolve role assignments, nested paths and privileged identities across every supported RBAC system.

🛡️

Protect

Apply Restricted Management Administrative Units and Conditional Access coverage to classified assets.

🔎

Monitor

Send tier context to your security tools and investigate exceptions, drift and breach paths.

📊

Report

Track posture, privilege history and attack-path evidence to steer the next improvement cycle.

Example outputs

Review the generated evidence.

Inspect administrative boundaries, Conditional Access groups, access paths and the classification evidence available to investigation tools.

Protection automation

Build restricted management boundaries.

Create tier-aware administrative units that give privileged assets the management boundary they need.

01 / 04

Integrations

Put privileged-access context where investigations happen.

EntraOps turns classifications into a shared security signal: query it in Microsoft Security, enrich it through Sentinel, or join it to attack paths in BloodHound.

Microsoft Security

Hunt with classified privilege.

Ingest complete Privileged EAM records through a Log Analytics custom table or Microsoft Sentinel WatchLists. The shared parser normalizes both paths, so KQL queries and workbooks work regardless of ingestion choice. Optional WatchLists enrich High Value Assets, VIP Users, identity correlation, managed-identity resources, recommendations and CSPM attack paths.

Examples of Microsoft Security integration →

BloodHound OpenGraph

Connect classification to attack paths.

Export Privileged EAM data as OpenGraph JSON and enrich AzureHound with EntraOps role assignments, scope reasoning, tier evidence, nested groups, PAW ownership and identity relationships. The Access Path Map carries the same context into an offline, interactive graph.

Explore the OpenGraph integration →

Learn

Get oriented. Then go deep.

Adopt EntraOps with practical guidance, explore its classification model, or watch the Enterprise Access Model in action.

Documentation

Set up the module, configure your tenant, and connect each capability to an operating workflow.

Read the docs →

Classification Explorer

Get familiar with the tiering model, role actions and classification decisions behind EntraOps.

Open explorer →

Sessions

Learn more about EntraOps, its use cases and core concepts through hands-on demos from community conferences.

Adoption of Enterprise Access Model with EntraOps
Classification of Intune RBAC and BloodHound-Integration

Choose your setup

Start quickly. Customize when you need to.

Use the guided defaults for a fast first run, or shape the EntraOps configuration around your tenant, scope and operating model before deployment.

Option 01 · Quickstart

Follow the guided setup.

Choose a deployment path, accept the recommended baseline and get EntraOps running with the minimum number of decisions.

Quickstart · Get Started guide

Option 02 · Expert mode

Customize your configuration.

Use the Configuration Wizard to create, import and export EntraOpsConfig.json with the settings, classifications and collection scope your environment requires.

Expert mode · Configuration Wizard

Deploy

Make your tiered administration model visible and manageable.

Start from the EntraOps repository template, run it locally or in GitHub, and keep privileged-access evidence in a workflow your team owns.

Use the repository template

Designed for PowerShell Core.
Run EntraOps locally, in a CI/CD pipeline, or in your automation environment. The included reporting apps are static and self-contained.

Contributions

Made in the open.

EntraOps is maintained as a community project. Contributions, issue reports and feature requests are welcome on GitHub.

Martin Sohn Christensen

Contributor · BloodHound integration

Martin Sohn Christensen

@martinsohn
Michael Soule

Contributor · LZ Bootstrap

Michael Soule

@soulemike
Tier Breach Analyzer showing classified privilege flows