No owner, or an owner who left
Owners are checked against the employee directory: missing, terminated, on leave, or never confirmed. Entra ID owners are linked automatically.
Non-human identity cleanup · Sutura Suite
Service accounts, app registrations, bots and API identities outnumber people, and nobody leaves when they should. Sutura Hakika finds them all, checks who owns each one and what it can do, ranks the risk, and tracks every cleanup until someone else has verified it.
Self-hosted · Read-only discovery · Never stores a secret value
Builds the inventory from the systems you already run
A script needed an account in 2019. An integration got an app registration with a secret that never expires. The engineer who created them left. They still sign in, some with rights over the whole directory, and nobody can say who would notice if they were misused. Hakika gives each one an owner, a purpose and a verdict.
What it finds
Owners are checked against the employee directory: missing, terminated, on leave, or never confirmed. Entra ID owners are linked automatically.
Apps holding tenant-wide write permissions or admin roles, and identities with no sign-in for months: standing access nobody needs.
Secrets and certificates that expired, are about to, or never rotate. Hakika records their dates and identifiers, never their values.
How it works
A live, read-only Entra ID connector and CSV imports build one inventory. Duplicates across sources are matched and classified, with every rule explained.
Each identity gets owners checked against the employee directory, and the systems that depend on it, so cleanup never breaks a payroll run.
A weighted, capped risk score shows exactly which factors raised it. Findings open, close and reopen by themselves as the data changes.
Remediation with evidence, verified by someone other than the person who did it. Accepted risks need an approver and an expiry date.
Built for security teams
Hakika runs on your own server and never needs write access to your tenant: it tells people what to fix and keeps the proof.
Live demo
The live demo pulls a real Microsoft Entra ID tenant every day, alongside sample data from other sources. Ask us for a demo account to sign in.
FAQ
Service accounts, app registrations and service principals, managed identities, shared and emergency accounts, bots and RPA accounts, API, database and integration identities, and scheduled-task accounts.
Read-only application permissions: Application.Read.All and User.Read.All, plus optionally the ones for delegated permissions, admin roles and sign-in activity. Hakika never changes anything in your tenant.
No. It is not a vault or a PAM tool. It finds the problem, assigns it, and keeps the evidence that it was fixed and verified.
On your own server with Docker Compose and automatic HTTPS, or Kubernetes with the Helm chart. Upgrades apply database changes automatically.
Get in touch and we'll walk you through the options.
Start with your own Entra ID tenant in a 30-day pilot.