Product description
Microsoft Entra Permissions Management is a cloud infrastructure entitlement management (CIEM) solution that helps you secure your multicloud environment by providing comprehensive visibility and control over permissions for any identity and any resource across Microsoft Azure, Amazon Web Services (AWS) and Google Cloud Platform (GCP).
With Microsoft Entra Permissions Management, you can discover, remediate, and monitor permission risks for all identities, both users and workloads, across your cloud infrastructures. You can assess the gap between permissions granted and permissions used, automate the principle of least privilege, implement consistent security policies, detect anomalous activities, and generate detailed forensic reports.
Microsoft Entra Permissions Management enables you to:
Get full visibility
Discover what resources every identity is accessing across your cloud platforms. Permissions Management provides granular and normalized metrics for key cloud platforms: AWS, Azure, and GCP. You can also view the Permission Creep Index (PCI), an aggregated metric that periodically evaluates the level of risk associated with the number of unused or excessive permissions across your identities and resources. It measures how much damage identities can cause based on the permissions they have.
Automate the principle of least privilege
Use usage analytics to ensure identities have the right permissions at the right time. Permissions Management allows you to automatically delete permissions unused for the past 90 days, grant permissions on-demand for a time-limited period or an as-needed basis, and automate just-in-time access for cloud resources.
Unify cloud access policies
Implement consistent security policies across your cloud infrastructure. Permissions Management helps you enforce least privilege policy consistently in your entire multicloud infrastructure. You can also integrate Permissions Management with Microsoft Entra ID (Azure AD) to leverage its identity governance capabilities such as access reviews, entitlement management, and privileged identity management.
Prevent data breaches
Detect anomalous activities with machine learning-powered (ML-powered) alerts and generate detailed forensic reports. Permissions Management helps you prevent data breaches caused by misuse and malicious exploitation of permissions with anomaly and outlier detection. You can also get insights into mitigating the top identity and permissions risks across multicloud environments in the 2023 State of Cloud Permissions Risks Report.
Microsoft Entra Permissions Management is a part of the Microsoft Entra product family, which offers multicloud identity and network access products to safeguard connections between people, apps, resources, and devices.
Microsoft Entra Permissions Management is available as a subscription service that charges per billable resource per month. A billable resource is defined as a cloud service that uses compute or memory. Permissions Management supports all resources across AWS, Azure, and GCP, but only requires licenses for billable resources per cloud provider.