Every feature, edition by edition
Start free with Community. Pro adds everything below it - and you can try any Pro edition free for 60 days.
Community38 features
Free, on GitHub:
Delegation model and PIM coverage
- Entra ID roles, PIM for Groups, administrative units and Azure RBAC
- Intune and Defender XDR role delegation, including Defender custom roles end to end
- Two-tier group nesting: admins join direct groups that nest into permission groups
- Every group gets an owner automatically; groups and AUs renamed in place
- Invite guest consultants straight into a delegation group, staged for review
- Local self-service delegation, and consultants enabled or disabled by their owner
- Optional network-reach and privileged-workstation (PAW) classification
Policies and engine
- Standard and RequireApproval policy templates per kind, with a default per kind
- Activation policies fully managed and self-correcting against your template
- Safety brake: large or weakening policy changes wait for an administrator
- Never deletes silently - pruning is opt-in, and undefined objects are never touched
- Incremental runs apply only what changed
- Direct REST engine, no PowerShell modules; errors name the actual object
Manager portal
- The full web portal: model, review, commit and see what changed
- Home dashboard: failed jobs, findings, break-glass state, tiers, gaps, expiring access
- Access map, a target-first "create access" wizard, bulk-attach, clone and AU wizards
- One Pending-changes queue: backed up first, all-or-nothing, reversible
- Role Lookup: what a role can do, find roles by action, who can activate, compare two roles
- "Who can do what" reports, global search, CSV export and print on every view
- Permission template packs, and tenant preparation from one config file
Drift, lifecycle and safety
- Drift, live vs desired: correct, delete, keep or ignore extras
- Admin accounts with Temporary Access Passes, auto-disable dates and the full lifecycle
- Lifecycle calendar with escalating reminders and auto-renewal
- Emergency break-glass override: passphrase-gated, time-boxed, audited
- Never deletes an account, and never disables one just because it is missing from your data
- Daily checks for delegations pointing at deleted objects and for uncommitted changes
Notifications and audit
- Template-driven email, editable in the portal, with a kill switch, redirect and allowlist
- Alerts to Teams or any webhook, de-duplicated
- One audit trail with before/after values; optional copy to Log Analytics
- The current-delegations list
Hosting, setup and security
- Installs into your own Azure subscription with one command; self-validates and rolls back on failure
- Entra sign-in always required; private-only deployment supported
- Managed identity or certificate; passwordless database; read-only web console identity
- One-command update from the public GitHub release
- Offline licence check, no phone-home - free features never depend on it
PIM Activator browser extension (Edge and Chrome)
- One-click bulk activation with a confirm step and a live view of active roles
- See what a group grants before you activate it; done only when access is real
- Deploy to managed devices with Intune, with tenant-wide defaults
Pro Single Tenant12 features
Everything in Community, plus:
Find what is missing
- Coverage and gaps across Entra, Intune, Defender, Power BI, Azure and PIM for Groups, with ready proposals
- Discovery inbox: new scopes, workspaces, AUs and roles found on a schedule - Create or Ignore
More workloads
- Connectors for enterprise-app roles (any app), Azure DevOps, Dataverse, Business Central and Power Platform
- Power BI delegation and workspace discovery
- On-premises AD through a hybrid worker: AD admin accounts, PIM groups mirrored to AD, just-in-time AD membership (preview)
Governance
- Revoke current delegations, including approval-gated bulk revoke with a preview
- Access reviews per department: Keep or Remove, one or two approvers, reminders, enforced by the engine
- Second approver (maker/checker) for sensitive changes - nobody approves their own change
- Delegated administration: portal users limited by tier, level, service or scope
Evidence
- Tier-impact report: everyone who can reach Tier 0 or Tier 1, including through nested groups
- Evidence export: who may hold what, who held it, and who approved
- Support with an agreed response time at portal.invardia.com
Pro MSP13 features
Everything in Pro Single Tenant, plus:
Define once, target many
- Target managed tenants by tag and by rollout ring (dev, test, broad)
- Signed definition sets, verified on arrival; each tenant chooses which provider keys it trusts
- Pull, never push: the managing tenant never writes into a customer tenant; each customer has its own database
- Preview what reaches each tenant and what is withheld, with the reason
- Per-customer rules; mark a row as never leaving the managing tenant
Fleet control
- Fleet conformance: a tenants × templates matrix and ring-wide rollout planning
- Central admin accounts whose status and auto-disable date flow down to tenants
- Signed central kill: disable or revoke an account across all tenants
- Revoke a person's sessions in every managed tenant at once
- Remove an admin in all, some or none of the managed tenants - removal stays the tenant's call
- A Source column on every managed-tenant record (managing tenant or local)
Hosting
- Provider-hosted, or hosted in the customer's own tenant; fully private networking on both sides
- Daily signed publish job, a managed-tenant registry and replication overview pages
Coming next
On the roadmap, not in the current release:
- Exchange Online delegation connector