Who has the keys to your business?
Rebasoft delivers identity security as part of the same service-mapped asset graph, not as a separate bolt-on module.
Attackers are buying credentials, not finding zero-days.
The single biggest blind spot in most growing businesses is identity. The 2024–25 wave of breaches at well-resourced organisations was overwhelmingly identity-led: a phished session token, a missed MFA, a forgotten admin account, a privileged role nobody audited.
The audit question
"How many privileged accounts do you have?" The honest answer is "we’d have to ask a few people."
The insurance question
"What proportion of users have MFA?" The answer is a guess.
The customer question
"What’s your dormant-account review cadence?" The answer is a promise.
Scattered tooling
AD speaks for AD only. Entra for Entra only. Local admin discovery is a script someone runs once a year. Intune flags devices in a tab nobody opens.
Every identity source, one continuous audit.
Cloud, on-premises and local accounts in a single view — the privileged accounts your last audit didn't reach, surfaced and attributed.
All users across single- or multi-forest AD environments — with dormant-account detection (45+ days since last logon), service-account classification and admin-group membership counted and surfaced.
Full Entra inventory with per-user MFA registration evidence. Every Microsoft-defined privileged role detected — Global Admin, Exchange Admin and 24+ others — with standing rights distinguished from PIM-eligible (just-in-time).
Every host’s local accounts, Administrators-group membership, password-expiration state and last logon. The temporary admin that was supposed to be disabled — surfaced.
Local users are classified as interactive or system accounts. Sudoers and wheel membership are called out. Root exposure is flagged where enabled with an interactive shell.
From identity data to answers.
The same collection turns into the numbers finance, auditors and insurers actually ask for — without a scheduled exercise.
M365 licence assignment and waste
Every user’s licences mapped against the tenant SKU pool. When finance asks "are we paying for licences nobody uses?", the answer is a report, not an exercise.
Last sign-in and activity evidence
Per-user sign-in and last-activity tracking across the M365 estate — Entra audit logs (Premium) with fallback to the M365 Reports API. The dormant-user question becomes a number, not a guess.
Intune compliance follow-through
Non-compliant devices tagged to the user who owns them, ranked by risk, tracked to closure.
The hardest questions, answered on screen.
Audits in seconds
"How many Global Admins? Standing vs JIT? MFA coverage? Dormant-account count? Show me every admin on this server." All on screen, with the evidence trail behind each.
Insurance evidence insurers value
Proof of MFA coverage, privileged-account discipline and dormant-account cleanup — not a tick-box attestation.
Cyber Essentials A7, scored
User Access Control becomes an automated pass/fail, and the result pre-fills the A7 answers in your CE self-assessment.
Licence waste recovered
Most M365 estates have 10–20% waste in dormant users, undeprovisioned leavers and over-provisioned tiers. Rebasoft surfaces it; finance recovers the money.
| What you have today | What it actually gives you | What Rebasoft gives you |
|---|---|---|
| Active Directory Users & Computers | A snapshot. AD only. No dormant detection. No reporting. | Continuous AD audit with dormant, service-account and admin-membership reporting — across multi-forest environments. |
| Entra admin centre | Entra-only. One screen per question. | Entra + AD + M365 + local accounts in one query. |
| PowerShell scripts run quarterly | Stale within a week. | Continuous, evidenced, audit-defensible. |
| Identity governance platforms (Saviynt, SailPoint) | Enterprise-grade, enterprise-priced, enterprise-deployment-time. | Right-sized for SME and mid-market — running in days, not quarters. |
| Microsoft Defender for Identity | Microsoft estate only, alert-focused, not posture-focused. | Posture, evidence and continuous reporting across every identity source. |
Evidence that stands up to the assessor.
A £250m international charity operating in 30+ countries used Rebasoft to evidence compliance across a distributed estate — and achieve Cyber Essentials Plus.
In their words
“I can now see all my network-attached devices — in one system — and validate them for compliance purposes.”
— CISO, £250m international charity
From the blog
Privileged Access Review Guide for Clearer Control
This privileged access review guide shows security leaders how to find, assess and evidence high-risk access while keeping essential services running.
Read article
How to Assess Cyber Resilience With Evidence
Learn how to assess cyber resilience with continuous evidence, business-service context and priorities that strengthen recovery, assurance and decisions.
Read article
Business Context Risk Scoring That Drives Action
Business context risk scoring connects technical exposure to critical services, helping leaders prioritise fixes, evidence control and reduce cyber risk.
Read articleFind out who has the keys.
A 20-minute insight session on a live console. We'll show you the identity view across AD, Entra, M365 and your local accounts — and the questions it answers on your behalf.
Do we need an agent on every server to see local admins?
What level of Entra ID licensing do we need?
Will this slow down our domain controllers?
Does this replace SailPoint or Saviynt?
What does Rebasoft not currently do on the M365 identity side?
Is this Cyber Essentials A7 (User Access Control) evidence?
More questions? See the full Rebasoft FAQ — answers by topic and by role, or how Rebasoft is priced.