Every feature, edition by edition

Start free with Community. Pro adds everything below it - and you can try any Pro edition free for 60 days.

Community38 features

Free, on GitHub:

Delegation model and PIM coverage

  • Entra ID roles, PIM for Groups, administrative units and Azure RBAC
  • Intune and Defender XDR role delegation, including Defender custom roles end to end
  • Two-tier group nesting: admins join direct groups that nest into permission groups
  • Every group gets an owner automatically; groups and AUs renamed in place
  • Invite guest consultants straight into a delegation group, staged for review
  • Local self-service delegation, and consultants enabled or disabled by their owner
  • Optional network-reach and privileged-workstation (PAW) classification

Policies and engine

  • Standard and RequireApproval policy templates per kind, with a default per kind
  • Activation policies fully managed and self-correcting against your template
  • Safety brake: large or weakening policy changes wait for an administrator
  • Never deletes silently - pruning is opt-in, and undefined objects are never touched
  • Incremental runs apply only what changed
  • Direct REST engine, no PowerShell modules; errors name the actual object

Manager portal

  • The full web portal: model, review, commit and see what changed
  • Home dashboard: failed jobs, findings, break-glass state, tiers, gaps, expiring access
  • Access map, a target-first "create access" wizard, bulk-attach, clone and AU wizards
  • One Pending-changes queue: backed up first, all-or-nothing, reversible
  • Role Lookup: what a role can do, find roles by action, who can activate, compare two roles
  • "Who can do what" reports, global search, CSV export and print on every view
  • Permission template packs, and tenant preparation from one config file

Drift, lifecycle and safety

  • Drift, live vs desired: correct, delete, keep or ignore extras
  • Admin accounts with Temporary Access Passes, auto-disable dates and the full lifecycle
  • Lifecycle calendar with escalating reminders and auto-renewal
  • Emergency break-glass override: passphrase-gated, time-boxed, audited
  • Never deletes an account, and never disables one just because it is missing from your data
  • Daily checks for delegations pointing at deleted objects and for uncommitted changes

Notifications and audit

  • Template-driven email, editable in the portal, with a kill switch, redirect and allowlist
  • Alerts to Teams or any webhook, de-duplicated
  • One audit trail with before/after values; optional copy to Log Analytics
  • The current-delegations list

Hosting, setup and security

  • Installs into your own Azure subscription with one command; self-validates and rolls back on failure
  • Entra sign-in always required; private-only deployment supported
  • Managed identity or certificate; passwordless database; read-only web console identity
  • One-command update from the public GitHub release
  • Offline licence check, no phone-home - free features never depend on it

PIM Activator browser extension (Edge and Chrome)

  • One-click bulk activation with a confirm step and a live view of active roles
  • See what a group grants before you activate it; done only when access is real
  • Deploy to managed devices with Intune, with tenant-wide defaults

Pro Single Tenant12 features

Everything in Community, plus:

Find what is missing

  • Coverage and gaps across Entra, Intune, Defender, Power BI, Azure and PIM for Groups, with ready proposals
  • Discovery inbox: new scopes, workspaces, AUs and roles found on a schedule - Create or Ignore

More workloads

  • Connectors for enterprise-app roles (any app), Azure DevOps, Dataverse, Business Central and Power Platform
  • Power BI delegation and workspace discovery
  • On-premises AD through a hybrid worker: AD admin accounts, PIM groups mirrored to AD, just-in-time AD membership (preview)

Governance

  • Revoke current delegations, including approval-gated bulk revoke with a preview
  • Access reviews per department: Keep or Remove, one or two approvers, reminders, enforced by the engine
  • Second approver (maker/checker) for sensitive changes - nobody approves their own change
  • Delegated administration: portal users limited by tier, level, service or scope

Evidence

  • Tier-impact report: everyone who can reach Tier 0 or Tier 1, including through nested groups
  • Evidence export: who may hold what, who held it, and who approved
  • Support with an agreed response time at portal.invardia.com

Pro MSP13 features

Everything in Pro Single Tenant, plus:

Define once, target many

  • Target managed tenants by tag and by rollout ring (dev, test, broad)
  • Signed definition sets, verified on arrival; each tenant chooses which provider keys it trusts
  • Pull, never push: the managing tenant never writes into a customer tenant; each customer has its own database
  • Preview what reaches each tenant and what is withheld, with the reason
  • Per-customer rules; mark a row as never leaving the managing tenant

Fleet control

  • Fleet conformance: a tenants × templates matrix and ring-wide rollout planning
  • Central admin accounts whose status and auto-disable date flow down to tenants
  • Signed central kill: disable or revoke an account across all tenants
  • Revoke a person's sessions in every managed tenant at once
  • Remove an admin in all, some or none of the managed tenants - removal stays the tenant's call
  • A Source column on every managed-tenant record (managing tenant or local)

Hosting

  • Provider-hosted, or hosted in the customer's own tenant; fully private networking on both sides
  • Daily signed publish job, a managed-tenant registry and replication overview pages

Coming next

On the roadmap, not in the current release:

  • Exchange Online delegation connector