RiskyRolesAnalyzer
Contoso privileged role audit
Score 0 to 10 expresses live exploitability. Protected rows are reported with the reason, never offered for removal.
All sources
Azure RBAC
Entra ID
All assignment types
Permanent
Activated (PIM)
Eligible (PIM)
All principal types
Users
Groups
Enterprise Apps
App Registrations
Managed Identities
All roles
Direct & via group
Direct only
Via group only
Built-in & custom
Custom only
Built-in only
All activity statuses
Active only
Inactive only (disabled / no creds / blocked)
Disabled
No valid credential
Blocked by Microsoft
Any severity
Critical only
High & above
Medium & above
Low & above
Protected & removable
Removable only
Protected only
Show accepted
Export CSV
0 selected
Select visible
Clear
Copy removal command
Copies the native command for each selected row. Read them before you run them. Nothing runs from this page.
Select
Severity
Source
Role
Type
Principal
Identity
Status
Scope
Via
Protected
Risky Actions
Cleanup
Accept
No matching findings
×
Command