We want to make everything as simple as possible for you, this page will tell you everything you need to know to get up and running in minutes
Our philosophy is to make things as simple as possible, and signing up is no different. RoleSense uses Microsoft Authentication to ensure that you can login with your existing work accounts quickly without any fuss. This also enables your IT teams to choose how they control access to the RoleSense application.
If you would like to start using RoleSense, follow the instructions below -
By default, RoleSense has no access to your Azure environment, to analyse Audit Logs, User Accounts and Service Principals, please follow the steps below.
To successfully audit your environment, RoleSense requires that the Directory Readers role is assigned to the RoleSense Service Principal in Entra ID. This role allows RoleSense to retrieve information about your tenant and users, which is required to perform an access audit.
You must explicitly grant the Reader role to the RoleSense Service Principal within each Subscription you plan to review. This ensures that RoleSense is able to audit your Activity Logs and to suggest security improvements. You can optionally assign the Reader role at a Management Group level instead to provide access to multiple Subscriptions.
RoleSense allows you to audit all direct role assignments on users and service principals in a given Subscription, identifying roles that may no longer be required and role assignments that can be reduced based on actual usage.
To generate a report, first ensure that all prerequisites have been met and then follow the instructions below -
Although RoleSense queries the Graph API directly by default to generate reports, the API has a limited retention period of 30 days. If you need a longer lookback period, you can link RoleSense to a Log Analytics Workspace which contains exported Azure Activity Logs.
By default, your account will be on a free licence which allows you to generate a single report at a time and to view up to 25 individual role assignments per report.
RoleSense offers a simple licencing model based on the number of principals you need to manage. Each user licence costs £1 per user per month and grants you the ability to view all role assignments linked to a single "principal". A principal can be either a user account or a service principal.
For example, if your environment contains 50 unique principals with role assignments:
This system allows you to tailor your licences to the number of users and service principals you need to monitor, making it both cost-effective and flexible.
Determining how many licences you need for any software can be difficult, and we want to change that, so we've made it as simple as possible.
Navigate to the Billing page, you will see a recommendation for the number of required licences. This recommendation is a total count of unique principals with direct role assignments found across all Subscriptions which RoleSense has been granted access to.
The recommended quantity is reevaluated each time you navigate to Billing and provides the simplest way to ensure you have only the number of licences that you need at any time.