Automated Entra ID Access Review
Every Monday, WebRun signs in to the Microsoft Entra admin centre, lists app registrations whose client secrets or certificates expire within 30 days, guest accounts with no sign-in for 90 days, and users still without multifactor authentication, records each finding in an Airtable review base, and writes a short Notion page ranking what needs action first.
How do I run a weekly access review in Microsoft Entra ID?
WebRun signs in to the Microsoft Entra admin centre every Monday and lists client secrets expiring within 30 days, guest accounts dormant for 90 days, users without multifactor authentication, and privileged role holders. It records each finding in Airtable and publishes a ranked review page in Notion with owners and dates.
- Client secrets are flagged 30 days before an application breaks
- Dormant guest accounts surface every week instead of at audit time
- Accepted findings stop repeating, so the list stays short and real
Built for IT administrators · security teams · compliance managers · managed service providers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
entra.microsoft.comin a real browser with your saved login - no setup, no API keys. -
1
Microsoft Entra ID - review secrets, guests, and MFA
WebRun opens Microsoft Entra ID to review secrets, guests, and MFA. - Sign in to the Microsoft Entra admin centre
- Open App registrations and list every client secret or certificate expiring within the next 30 days, with the application name, owner, and expiry date
- Open Users and filter to guest accounts, capturing any with no sign-in recorded in 90 days
- Check which users are still not registered for multifactor authentication
- List accounts holding privileged directory roles so the owner can confirm each is still needed
- Read only. WebRun does not disable, delete, or change any account or credential
Done when Expiring credentials, dormant guests, MFA gaps, and privileged roles are all listed.
-
2
Airtable - record every finding
WebRun opens Airtable to record every finding. - Open your access review base and add or update one row per finding
- Record the type, the object name, the owner, the expiry or last sign-in date, and the days remaining
- Close out rows whose finding no longer applies, such as a secret that has been rotated
- Keep a status field so a finding accepted by the owner is not re-raised every week
- Roll up open findings by type so the trend across weeks is visible
Done when Every finding is recorded in Airtable with an owner and a status, and resolved ones are closed.
-
3
Notion - write the weekly review
WebRun opens Notion to write the weekly review. - Create this week's access review page in your IT space
- Lead with credentials expiring soonest, since an expired secret takes an application offline
- Follow with dormant guest accounts, MFA gaps, and privileged role holders
- Give each item a named owner and the date it should be handled by
- Note what changed since last week so progress is visible
Done when This week's access review page is published with owners and dates on every item.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it disable accounts or rotate secrets?
No. WebRun reads the Entra admin centre and reports. It never disables a user, never removes a guest, never rotates or deletes a client secret, and never edits a conditional access policy. Every change stays with your administrators.
Who sees the findings?
Only your own Airtable base and Notion workspace, both internal. WebRun does not email the account owners, so nothing about your directory leaves your team without a person choosing to share it.
Will the same finding be raised every week?
No. Each finding carries a status in Airtable. Once an owner accepts or resolves an item it stops appearing on the Notion page, and a rotated secret or a removed guest is closed out automatically at the next run.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.