Free Tool

Assess Your Entra ID
PIM State in Minutes

Free tool that connects to your Log Analytics Workspace and generates a comprehensive report of your PIM activation patterns, user behavior, and justification quality.

Request Free Tool

Most Organizations Have
Zero PIM Visibility

You deployed Entra ID PIM. Users activate roles daily. But do you actually know what's happening?

  • No activation audit trail: Who activated what, when, and for how long? You don't have a consolidated view.
  • Weak justifications go unnoticed: Users type "test", "daily work", or leave justifications empty - and nobody reviews them.
  • Excessive durations unchecked: Are users activating 8-hour sessions when they need 30 minutes? You wouldn't know.
  • No per-user or per-role insights: Which users are the most active? Which roles are activated most? No consolidated data.

PIM without visibility is just a checkbox.
You need data to know if it's actually working.

One script. Five minutes.
See your complete PIM picture.

What Your Report Includes

A self-contained report with interactive tables, filtering, sorting, and visual charts. No external dependencies. Opens in any browser.

Executive Summary

Total activations, unique users, unique roles, activation type breakdown (Entra Role / Azure Resource / Group) and daily averages.

User Analysis

All users with activation counts, average duration per user, and number of distinct roles used. Visual bars and sortable columns.

Role & Group Analysis

Every activated role and group with usage count, unique users, type badge, and average duration. Full breakdown.

Duration Analysis

Average, median, min, max duration in minutes. Distribution buckets: under 1h, 1-4h, 4-8h, and over 8h.

Justification Quality

Empty and short justification counts with percentages. Every unique justification listed with frequency and usage share.

Weekly Trends & Raw Data

Line chart with weekly activation trends plus a full raw data table with every activation record, filterable and sortable.

How It Works

Three simple steps from request to report

Step 1: Request the Tool

  • Fill out the request form below with your details
  • We review your request and approve access
  • You receive the tool package with a setup guide

Step 2: Set Up Prerequisites

  • Install Az.Accounts and Az.OperationalInsights modules
  • Ensure your Log Analytics Workspace receives PIM audit logs
  • Grant Log Analytics Reader role to your service principal or user account

Step 3: Run and Get Your Report

  • Execute the script with your Workspace ID
  • The tool queries your LAW, processes the data, and generates the report
  • Open the self-contained report in any browser - done

What You Need

The tool runs entirely in your environment. No data leaves your tenant. No external services contacted.

  • Azure Log Analytics Workspace with Entra ID PIM audit logs (AuditLogs table with PIM activation events).
  • Az.Accounts and Az.OperationalInsights modules installed.
  • Log Analytics Reader role on the workspace (for service principal or interactive user).
  • Authentication: Interactive Azure login.

Built With Security First

Your Data Stays in Your Environment

100% local execution - the tool runs locally, queries your LAW, and writes the report to your disk.
No external calls - no telemetry, no phone-home, no data exfiltration. Zero outbound connections beyond Azure authentication.
Self-contained output - the report has no external dependencies. No CDN, no JavaScript libraries, no tracking scripts.
Read-only access - the tool only needs Log Analytics Reader. It never modifies your environment.
Free
No cost. No strings attached.
Built by: Microsoft MVP Kaido Järvemets
15+ years in Microsoft security & identity
Creator of WatchTower PIM Coach

Production-tested. Enterprise-grade.
Request Free Tool

Got Questions? We've Got Answers

Everything you need to know about the WatchTower PIM Assessment Tool.

Is it really free?

+

Yes, completely free. No hidden costs, no trial period, no feature limitations. You get the full tool with all report capabilities. We built this to help organizations understand their PIM posture.

Does any data leave my environment?

+

No. Absolutely not. The tool runs 100% locally on your machine. It queries your Log Analytics Workspace directly and writes the report to your local disk. There are no external calls, no telemetry, and no data exfiltration of any kind.

What permissions does the tool need?

+

The tool requires Log Analytics Reader role on your workspace. This is a read-only role - the tool never writes to or modifies your environment. The tool uses interactive Azure login for authentication.

What if I don't have a Log Analytics Workspace?

+

The tool requires PIM audit logs to be sent to a Log Analytics Workspace. If you haven't configured diagnostic settings for Entra ID audit logs, you'll need to set that up first. Once configured, PIM activation data will start flowing into the AuditLogs table in your workspace.

Why do I need to request it instead of downloading directly?

+

We want to ensure you get proper onboarding and support. By reviewing requests, we can provide you with the right version, setup documentation, and follow up to make sure you successfully run the assessment. It also helps us understand how the tool is being used so we can improve it.

What is WatchTower PIM Coach?

+

WatchTower PIM Coach is our full PIM monitoring and governance platform. While this free tool gives you a one-time snapshot, PIM Coach provides continuous monitoring, AI-powered justification scoring, policy enforcement, and automated remediation. Learn more about PIM Coach.

Request Your Free Tool

Get the WatchTower PIM Assessment Tool

Fill out the form below and we'll review your request and send you the tool with setup instructions.

If you don't see the request form below, please click here to open the request form.