EntraOps
Classify, govern and monitor privileged access in Microsoft Entra ID.
What is EntraOps?
EntraOps is an open-source, PowerShell-based toolset for analyzing and governing privileged access in Microsoft Entra ID. Its Privileged EAM module automatically classifies users, groups, service principals and managed identities by their effective privileges, maps them to the tiers of the Enterprise Access Model, and exposes the resulting data for reporting, monitoring and attack-path analysis.
- Classification of privileged identities and workload identities into Control / Management plane tiers.
- Enrichment and export of privileged access data to Microsoft Sentinel and Log Analytics for continuous monitoring.
- Insights to identify excessive permissions, standing access and potential privilege-escalation paths.
Relation to this playbook
EntraOps is maintained by Thomas Naunheim, a co-author of this playbook, and is referenced in several chapters of the playbook for its mitigation and detection capabilities. It operationalizes many of the defensive concepts described in the attack & defense scenarios here — in particular the classification, tiering and continuous monitoring of the privileged identities that are the prime targets of the attacks covered in this project. Use it to understand and reduce the privileged-access blast radius before, and detect abuse during, the techniques documented throughout the playbook.