PRO PACK / PREVIEWPRO PREVIEW PACK

Entra Privileged Access Audit

Correlate privileged roles, PIM, application permissions, risky users and credential-expiry signals in one local audit pack.

Read-onlyMicrosoft EntraLocal PowerShell execution
Pro is not for sale yet.

Pro is currently in preview and is not for sale yet. When pack access opens, one Opselith Access Key can hold multiple owned packs and always unlock the latest eligible version.

WHAT IT IS FOR

A repeatable admin pack, not a cloud scanner.

The Pack generates one reviewed orchestration script after eligible key validation. You download or copy that script, review it, and run it locally. Authentication, tenant-specific values and exported tenant data stay in your PowerShell session and local output folders.

Principal correlationPrivileged-group viewConsolidated risk-oriented summary without declaring compromise
PACK COVERAGE

What the generated Pack collects.

Privileged roles

Role-Assignments.csv · PIM-Assignments.csv

Application privilege

OAuth-Grants.csv · Applications.csv · Service-Principals.csv

Identity risk

Risky-Users.csv · Authentication-Registration.csv

Credential expiry

Application-Credentials.csv · Service-Principal-Credentials.csv

Privileged access summary

Privileged-Access-Audit.html · Execution-Summary.csv · Findings.csv · manifest.json

REQUIREMENTS

Review access before execution.

Use least privilege and review the generated script before authenticating. The Pack does not receive or store your Microsoft 365 credentials.

LOCAL OUTPUT

Structured files you keep.

Roles/Applications/Risk/Credentials/Summary/Privileged-Access-Audit.htmlSummary/Execution-Summary.csvSummary/Findings.csvmanifest.json

The output belongs to the administrator running the Pack. Opselith does not upload these exports back to the website.

BOUNDARIES

What this Pack does not claim to do.

TRUST / EVIDENCE

Recorded trust facts, not a certification.

Opselith separates metadata review, static QA, analyzer evidence and runtime evidence. A missing runtime result or a Pending analyzer state is shown as-is rather than converted into a pass claim.

Static QAPassed

Pack catalog, generator determinism, read-only boundary and output-contract QA.

PSScriptAnalyzerPending

The generated Pack script is included in the release PSScriptAnalyzer gate. No analyzer pass is claimed before that gate runs.

Runtime evidenceNot yet recorded

No accepted runtime result is recorded for this pack yet.

Execution boundaryRead-only

generated-script-runs-locally · no website tenant connection · tenant output stays outside Opselith.

Last reviewed28 Aug 2026

Trust metadata reviewed for the current 3.0 development contract.

Referenced scripts9

9 referenced scripts · 8 analyzer Passed · 1 Pending

Pending and Not yet recorded are evidence states, not failures. Review the generated script or runbook and validate it in your own environment before production use.

ACCESS MODEL

One Access Key, multiple owned Packs.

When Pack sales open, the same Opselith Access Key can hold multiple Pack entitlements. Buying another Pack adds it to that key rather than creating key sprawl. Ownership includes future updates to the purchased Pack, so the latest eligible version stays available to generate and download from Opselith.

No credits. An eligible Pack can be generated again when an updated version is available.

FOUNDATION TASKS

Related PowerShell coverage.