Know what needs attention before you change a policy.
A policy can look right and still cause problems. IAMAI checks who has the required sign-in methods, whether the available records show they use them, and which exclusions or outside accounts need a closer look. Then it helps you plan the changes.
Free public previewYou review and make the changes
What it does
See what needs doing, and what needs to happen first.
Start with the tenant you have. IAMAI compares it with your chosen baseline, shows the gaps it can assess, and puts the work in order.
CheckReview policies, accounts, groups and the sign-in evidence Microsoft makes available to this tenant.
UnderstandSee what already meets the baseline, what needs attention, and who a change could affect.
PrepareWork through the prerequisites, review the instructions, and test changes before enforcing them.
What it catches
A few things worth checking before you deploy.
Sign-in methodsSomeone has registered a strong method, but the available records do not show them using it.
Emergency accessA proposed policy may reach the accounts you rely on to recover access.
ExclusionsAccounts in an exclusion group need a review of why they are still exempt.
Outside accountsGuests may need different preparation or follow-up before a change applies to them.
Shared accountsA meeting-room or service account may need attention before new sign-in requirements take effect.
What it does with your tenant
Your tenant stays under your control.
IAMAI does not change your tenant You can review the permissions before connecting. IAMAI reads the tenant to build the plan; you decide which changes to make and carry them out yourself.Your scan is processed on your device Tenant data is read from Microsoft and processed in your browser. IAMAI does not upload your scan to its own server. Downloaded plans and copied briefings can contain tenant information, so review them before sharing. The website host may also collect page-load information.You can inspect the code The source and documented limits are public. Check how IAMAI works, report a problem, or suggest an improvement. View IAMAI on GitHub
About
Built by someone who does this work.
I’m Lachlan Robinette. I work with Microsoft Entra security baselines across MSP-managed tenants. I built IAMAI to help with the checks and decisions that sit between a baseline and a successful rollout. It is still in public preview. If something is wrong or unclear, tell me at [email protected].