Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Privileged Access
14 controls
5 services covered
Checks privileged role posture across Entra and Azure subscriptions, including global administrator count, owner assignments, custom roles, disabled-account assignments, external owners, and tenant or security-group creation permissions.
What we check
Subscription Owners5
- Subscription Should Have More Than 1 Owner Assigned
- Subscription Should Have Maximum of 3 Owners Assigned
- Blocked accounts with owner permissions on Azure resources should be removed
- Remove Guest Accounts with Owner Permissions on Azure Resources
- Ensure that no custom subscription owner roles are created
Role Assignment Hygiene4
- Ensure disabled user accounts do not have role assignments
- Blocked accounts with read and write permissions on Azure resources should be removed
- Use of the 'User Access Administrator' role should be restricted
- IAM users should not have built in contributor role
Custom Roles2
- Audit Usage of Custom RBAC Roles
- Subscriptions with custom roles should not be overly permissive
Tenant and Security Group Creation2
- Ensure Users Cannot Create Security Groups
- Ensure Users Cannot Create Tenants
Global Administrators1
- Ensure that between two and four global admins are designated
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
