IAMAI

Microsoft Entra baseline planner

Turn a security baseline into a rollout plan for your tenant.

IAMAI reads your tenant, compares it with Jon Hope's Defense in Depth baseline, and writes a dated plan: what to change, in what order, and who each change could affect. It finds what could lock people out before you turn a policy on. Read-only, and it runs in your browser.

Connect your tenant Try it with sample data

The sample tenant's plan in IAMAI Planner: what is ready now, the next step, and the first section's steps with their dates. The sample tenant's plan in IAMAI Planner: what is ready now, the next step, and the first section's steps with their dates.

What it does

From your tenant to the baseline, one step at a time.

IAMAI orders the work so each policy waits until what it depends on is ready.

ReadsAfter one admin consent, a Global Reader sign-in is enough. IAMAI reads your policies, people, sign-in methods and up to 30 days of interactive sign-ins.
ComparesEach baseline policy against yours, setting by setting. The name doesn't matter; the settings do.
PlansA dated plan: emergency access first, and new policies in report-only first wherever Microsoft evaluates them.

What it catches

What can lock people out, found before you turn a policy on.

Emergency accessA policy that would reach the accounts you use to get back in. The plan excludes them through one group, and each scan checks the group still holds them.
Sign-in methodsPeople whose only method a policy won’t accept, or who haven’t used the MFA they registered in the last 30 days.
Service and shared accountsAccounts that look like scanners, service mailboxes or meeting-room devices, suggested from their names, licences and sign-ins, so you decide how each is handled before MFA reaches it.
Legacy authenticationAccounts that recent sign-ins show still using IMAP, POP, SMTP AUTH or ActiveSync, named before you block legacy authentication.
Report-only resultsAfter a policy’s report-only period, the next scan names anyone it would have stopped, and its turn-on waits for them.

What it does with your tenant

Your tenant stays under your control.

IAMAI is read-only You can review the permissions before connecting. Approving them adds one enterprise application to the tenant, which you can delete. IAMAI reads the tenant to build the plan; you decide which changes to make and carry them out yourself. Your scan is processed on your device Tenant data is read from Microsoft and processed in your browser. IAMAI has no server, so your scan is not uploaded anywhere. Downloaded plans and copied briefings can contain tenant information, so review them before sharing. The website host may also collect page-load information. You can inspect the code The source and documented limits are public. Check how IAMAI works, report a problem, or suggest an improvement. View IAMAI on GitHub

About

Built by someone who does this work.

I’m Lachlan Robinette. I work with Microsoft Entra security baselines across MSP-managed tenants. I built IAMAI to help with the checks and decisions that sit between a baseline and a successful rollout. It is still in public preview. If something is wrong or unclear, tell me at [email protected].