Know exactly who has what permissions in Azure — and who actually uses them

Permafrost EPM discovers all identities and permissions across your Azure tenants, compares assigned access against actual usage, and generates right-sized custom roles to eliminate over-privilege.

Complete visibility into Azure entitlements

From discovery to remediation — close the permission gap

Entitlement Discovery

Automatically inventory all users, groups, service principals, managed identities, and AI agents across your Azure tenants.

Usage Gap Analysis

Compare assigned permissions against actual exercised permissions. See exactly which permissions are unused and by whom.

Risk Scoring

Unused Permission Risk Score (UPRS) quantifies your organizational attack surface per identity. Prioritize remediation by risk level — critical, high, medium, low.

Right-Sized Roles

Generate least-privilege custom Azure roles based on actual usage patterns. Export as ARM templates or Terraform.

Dormant Account Detection

Identify identities with active role assignments but no sign-in activity in 90+ days.

Toxic Combination Detection

Flag dangerous permission combinations that could enable privilege escalation attacks.

Multi-Tenant Support

Connect and monitor multiple Azure tenants from a single dashboard. Each tenant is analyzed independently.

Get started in minutes

1

Grant Reader Access

An admin from your organization grants OAuth consent for read-only access. Permafrost never modifies your Azure environment.

2

Automatic Discovery

We scan your Azure tenant to discover all identities, roles, permissions, and correlate them with actual usage from activity logs.

3

See the Gap & Act

View the permission gap for every identity. Generate right-sized custom roles and export them as ARM templates to apply.

Simple, transparent pricing

Pay based on the number of objects (users, groups, service principals, managed identities, agents) in your connected tenants.

Community

For small teams exploring Azure entitlement management.

$0
  • Up to 250 total objects
  • 1 connected tenant
  • Daily sync
  • 30-day data retention
  • Basic dashboard
  • Community support
Start Free

Professional

For organizations serious about least-privilege access.

$2/object/mo
  • Unlimited objects
  • Unlimited tenants
  • Hourly sync
  • 90-day data retention
  • Custom role export (ARM / Terraform)
  • Full reports (PDF, CSV)
  • Volume discounts available
  • Priority email support
Get Started
Volume discounts: 1–1,000 objects: $2/mo · 1,001–5,000: $1.50/mo · 5,001–25,000: $1/mo · 25,001+: $0.50/mo