Try free Sign in Contact sales
Compliance / Roadmap

Automated Microsoft Entra ID evidence collection

Auditors don't just want a policy document — they want proof: who has access, what permissions they hold, whether MFA is actually enforced, and what your configuration looked like on a given date. Pulling that out of Entra ID by hand, every audit cycle, is slow and easy to get wrong. This is on our roadmap, not shipped today — here's exactly what that means.

The problem with manual Entra evidence

  • Screenshot-driven audits: Conditional Access policies, sign-in logs, and role assignments get captured as static screenshots that are stale the moment they're taken.
  • Spreadsheet group membership: exporting who belongs to which security group, and cross-checking it against who should still have access, is a manual reconciliation exercise every quarter.
  • No point-in-time MFA proof: "MFA is enforced" is a policy statement, not evidence — auditors want to see enforcement state at a specific date, not just today.
  • Evidence rots between cycles: admin turnover, ticket sprawl, and undocumented changes mean last quarter's export often can't be reproduced or verified later.
  • It repeats every cycle: SOC2, ISO 27001, and vendor security reviews all ask overlapping questions about the same Entra tenant, so the manual work gets redone from scratch each time.

What we're building — roadmap, not live

None of the items below exist in Chasa today. This is a planned connector, and we're publishing the plan early rather than waiting to announce it as finished. Track live status on our Trust Center.

  • User access exports: pulling a full list of Entra ID users and their assigned roles into a structured, exportable record.
  • Group membership evidence: a point-in-time snapshot of security group membership, so "who had access when" is answerable months later.
  • Permission mapping: tying role assignments back to the systems and data they actually grant access to, not just the role name.
  • MFA enforcement proof: evidence that Conditional Access / MFA policies were active and applied to the relevant users at a given date — not just a policy toggle.
  • Configuration snapshots: periodic captures of tenant-level security settings, so drift between audit cycles is visible instead of assumed away.
  • Audit-ready PDF/JSON exports: evidence packaged in a format an auditor or security reviewer can consume directly, instead of a folder of screenshots.

Why Chasa, and why now

This isn't a cold start. Chasa already runs an evidence-automation model in production today, just scoped to accounts receivable: every AI-drafted invoice chase requires a human to review and hit send, and that approval step creates a timestamped, auditable record — which is exactly the pattern financial controllers use for SOX AR evidence automation right now. Microsoft Entra ID is the next connector we plan to build using that same approach — human-verified, timestamped, exportable evidence — extended from AR audits into general access and identity evidence for SaaS compliance. See the full category context on our evidence automation page, and how it lines up against SOC2 and ISO 27001 evidence needs.

Use the part of Chasa that's live today

Chasa's AI-drafted, human-approved invoice follow-ups — with QuickBooks/Xero/CSV sync, HMAC-signed webhooks, and role-based workspace access — are live right now. Entra ID evidence is what we're building next.

Try Chasa free Get notified when Entra evidence ships

Auditing on a deadline? Talk to us about your audit timeline and we'll tell you honestly whether our roadmap fits it.

Related reading

Trust Center → What's live vs. roadmap across Chasa's security posture. Compliance roadmap hub → All the frameworks and connectors we're planning for. SOC2 evidence automation → Our plan to remove the manual evidence grind from SOC2 audits. SOX AR evidence automation → The live model we're extending into Entra ID evidence.