Know your Azure estate is under control — and prove it.

Praefic continuously scans your Azure tenants with read-only access, turns what it finds into owned, tracked findings, and shows whether things are getting better or worse. It’s governance as a record of decisions, not a list that resets every morning.

Praefic showing a finding’s history

Know your Azure estate is under control — and prove it.

Praefic continuously scans your Azure tenants with read-only access, turns what it finds into owned, tracked findings, and shows whether things are getting better or worse. It’s governance as a record of decisions, not a list that resets every morning.

Praefic showing a finding’s history

A structured way to get in control

Scanning is the easy part. Praefic is built around what comes after it.
Praefic flow: See, Decide, Organize, Verify, Prove
  1. See. Every subscription is scanned across 19 areas, from network exposure and privileged access to cost and AI models. Every finding is stored with its history.

  2. Decide. For each finding you can:

    • acknowledge it,

    • assign it to a person or a group,

    • accept the risk with an exception that has a reason and an expiry date,

    • or mark it for fixing.

    Every decision carries over from one scan to the next.

  3. Organize. Group the work into Initiatives, named remediation projects such as “Q4 network hardening” or “Clean up before the audit”. Each one has an owner, a scope and a burndown.

  4. Verify. Fixed means fixed. When someone marks a finding as fixed, the next scan checks it. A finding that comes back is reopened, and Praefic shows who changed the resource.

  5. Prove. Maturity levels, trend lines and a management report show progress in terms leadership understands.

What Praefic does

Azure already tells you a lot. Advisor and Defender for Cloud produce hundreds of recommendations, and most teams still can’t answer the question that matters: are we in control? The recommendations have no memory. Nobody can see what was already reviewed or knowingly accepted, or what was fixed and then quietly came back. The same problem often appears twice under two names. Praefic adds the missing layer. It connects with Azure’s built-in Reader role and scans on a schedule. Every finding is stored with its full history:

What Praefic does

Azure already tells you a lot. Advisor and Defender for Cloud produce hundreds of recommendations, and most teams still can’t answer the question that matters: are we in control? The recommendations have no memory. Nobody can see what was already reviewed or knowingly accepted, or what was fixed and then quietly came back. The same problem often appears twice under two names. Praefic adds the missing layer. It connects with Azure’s built-in Reader role and scans on a schedule. Every finding is stored with its full history:
  • Fixed findings are resolved automatically on the next scan.

  • Findings that come back are reopened and flagged.

  • Your acknowledgements, assignments and exceptions carry over from one scan to the next.

Praefic never writes to your environment. Not one setting is ever modified.

Initiatives: turn a list of problems into a plan

A backlog of four hundred findings isn’t a plan. An Initiative is: a named remediation project with a clear scope, owners and a finish line.
Praefic initiatives view
  • Scope it in a click. Filter findings by area, severity, subscription or resource group, select them, and add them to an Initiative. A finding can belong to more than one.

  • Assign ownership. Assign findings to people or to groups. Everyone gets an “assigned to me” view, and @-mentions in comment threads bring the right person in.

  • Separate claims from verification. Owners move work through Planned → In progress → Fix applied, or record Risk accepted. Praefic keeps that separate from what the scanner sees. “Fix applied” is the owner’s claim; “Resolved” means the next scan confirmed it.

  • Track progress honestly. Each Initiative shows how its findings break down by status and a burndown built from the actual finding history, including anything that came back after it was fixed.

  • Hand it to people outside Praefic. Generate a hand-off document as Markdown or self-contained HTML for a supplier, a partner or a product team that doesn’t use Praefic. It groups findings by issue, with why each one matters, how to fix it, a ready-to-run az command and the CIS/MCSB reference. A CSV or JSON export is available for ticket systems.

Initiatives are how a security review becomes a project with a deadline, rather than a report that ages in someone’s inbox.

Cost, next to the risks

Governance and cost are usually two tools and two teams. In Praefic they share the same resources, and the same findings.
Praefic cost shown next to risks
  • Daily spend per resource. Praefic builds a daily cost history for every resource, explorable by subscription → resource group → resource, or by service and resource type at any level.

  • Spikes caught early. Praefic compares each resource with its own recent spend, not with the estate as a whole. A Key Vault going from a few dollars a day to thousands stands out even when it’s nowhere near your top-10 spenders.

  • Budgets that work. Praefic flags subscriptions with no budget, budgets with no alerts, expired budgets, budgets already exceeded and budgets forecast to exceed. It also shows which budget alerts actually fired.

  • Waste with a price on it. Orphaned disks, stopped VMs, unattached gateways and empty App Service plans are ranked by what they actually cost you over the last 30 days. Any finding on a billed resource shows its cost, so you can prioritize by money as well as severity.

  • AI spend by model. Track spend per AI model and deployment, alongside alerts for models approaching retirement.

  • Honest about gaps. Some Azure offers, like sponsorships, MSDN and trials, have no cost API. Praefic says so, instead of showing a cost of zero.

Who changed what, and why it keeps coming back

Praefic reads the Azure Activity Log for every connected subscription and keeps the history, so posture findings come with context.
Praefic change history showing who changed what
  • Who changed this. Every finding shows the likely change that introduced it and whether anyone has touched the resource since.

  • Fixes that don’t stick. When a fixed finding keeps coming back, Praefic names the identity behind the pattern. That’s often a pipeline or script quietly putting the old setting back.

  • Privileged access, measured by actual use. Standing Owner and Contributor grants are marked active or dormant from what the identity actually did. Praefic also flags PIM roles that stay active long after the work is done, and eligible roles nobody ever activates.

  • People vs automation. See how much of your change volume comes from people clicking in the portal and how much comes from code. Deployments are reconstructed with success rates and durations.

  • Early warning signals. Repeated access denials for one account, integrations failing the same call for days, and operations colliding with each other.

Benefits

Key benefits of Praefic

Benefits

Key benefits of Praefic

One governed list, not five noisy ones

Findings from 19 areas of Azure land in one place. Where an Advisor recommendation repeats one of Praefic’s own checks on the same resource, it’s shown once, not twice. Tenants without Defender keep the Advisor finding, so nothing is lost.

Decisions that stick

You can acknowledge a finding, assign it to a person or group, mark it in progress or accept the risk. All of it carries over from one scan to the next. Praefic records the history, so you can see who decided what, and when.

Exceptions with an expiry date

Approve deviations in the app, or declare them as a tag on the Azure resource in the same pull request that creates it. Every exception carries a reason and an end date. When it lapses, the finding comes back by itself.

Remediation as a project, not a list

Initiatives group findings into owned projects with burndowns, verified fixes, and hand-off documents for suppliers who don’t use Praefic.

Reporting management can read

Maturity levels (Level 1, 2, 3), a health-score trend, and a management report as a PDF or an interactive web page. It covers top risks, how fast findings get fixed and CIS/MCSB coverage.

Security and cost in one view

Daily spend per resource, budget hygiene, cost spikes and priced waste, on the same resources as the security findings.

Read-only and agentless

There’s nothing to install and no write permissions. Praefic is a multi-tenant app you consent to once, with the Reader role on the subscriptions you choose.

What's in Praefic

The capabilities that make Praefic a read-only, Azure-native governance layer with memory.

What's in Praefic

The capabilities that make Praefic a read-only, Azure-native governance layer with memory.
19 governance areas

Network exposure, Azure Advisor, orphaned resources, Key Vault, Defender for Cloud plans, RBAC, Privileged Identity Management, backup, resource inventory and tagging, storage, virtual machines, App Services, databases (SQL, PostgreSQL, MySQL, Cosmos DB), AKS, Container Registry, Container Apps, cost and budgets, activity log, and AI model lifecycle and spend.

19 governance areas

Network exposure, Azure Advisor, orphaned resources, Key Vault, Defender for Cloud plans, RBAC, Privileged Identity Management, backup, resource inventory and tagging, storage, virtual machines, App Services, databases (SQL, PostgreSQL, MySQL, Cosmos DB), AKS, Container Registry, Container Apps, cost and budgets, activity log, and AI model lifecycle and spend.

Privileged access that’s actually used

Finds standing Owner and Contributor grants, PIM roles activated without MFA or approval, and privileged access nobody has used in months.

Privileged access that’s actually used

Finds standing Owner and Contributor grants, PIM roles activated without MFA or approval, and privileged access nobody has used in months.

Remediation built in

Every check explains why it matters and how to fix it, with a copyable az command and a direct link into the Azure portal. Optional AI assistance writes a fix tailored to the specific resource.

Remediation built in

Every check explains why it matters and how to fix it, with a copyable az command and a direct link into the Azure portal. Optional AI assistance writes a fix tailored to the specific resource.

Cost and waste

Shows spend trends, budget coverage, and money billed for resources that open findings say you no longer need.

Cost and waste

Shows spend trends, budget coverage, and money billed for resources that open findings say you no longer need.

Expiry calendar

Certificates, budgets and lapsing exceptions in one view, with an ICS feed you can subscribe to in Outlook or Google Calendar.

Expiry calendar

Certificates, budgets and lapsing exceptions in one view, with an ICS feed you can subscribe to in Outlook or Google Calendar.

Alerts where you work

Notifications go to Teams, Slack, email or webhooks, with rules by severity and area, maintenance windows, and personal daily or weekly digests.

Alerts where you work

Notifications go to Teams, Slack, email or webhooks, with rules by severity and area, maintenance windows, and personal daily or weekly digests.

How Praefic works

Sign in, consent once, grant Reader, and your first findings arrive within minutes.

How Praefic works

Sign in, consent once, grant Reader, and your first findings arrive within minutes.
1
Sign in with your Microsoft work account

Your organization is set up automatically.

1
Sign in with your Microsoft work account

Your organization is set up automatically.

2
Consent to the Praefic Scanner app

Admin consent in your Entra tenant, once.

2
Consent to the Praefic Scanner app

Admin consent in your Entra tenant, once.

3
Grant Reader on your subscriptions

Choose the subscriptions you want scanned. The wizard shows you the exact command.

3
Grant Reader on your subscriptions

Choose the subscriptions you want scanned. The wizard shows you the exact command.

4
Scan and govern

The first findings arrive within minutes, and scheduled scans keep them current.

4
Scan and govern

The first findings arrive within minutes, and scheduled scans keep them current.

Who Praefic is for

Platform, security and IT teams who need to show that their Azure estate is under control, not just scanned.

Who Praefic is for

Platform, security and IT teams who need to show that their Azure estate is under control, not just scanned.
Platform and cloud operations teams

Keep a growing estate clean: orphaned resources, missing backups, retiring runtimes and AI models, untagged spend.

Security teams

Get continuous visibility of network exposure, privileged access and Key Vault posture, without another agent to deploy or another list to reconcile.

Compliance-driven organizations

Exceptions with an owner and expiry date, a complete finding history, and reports mapped to CIS and the Microsoft cloud security benchmark. It’s the evidence an auditor asks for.

FinOps and cost owners

Daily spend per resource, budget coverage across every subscription, spikes caught early, and waste ranked by what it actually costs.

IT leadership

A health score, a maturity level and Initiatives with burndowns answer “are we in control, and are we getting there?” in one page.

Start with your own tenant.

Book a demo and see what Praefic finds in your own Azure estate. It connects with read-only access, so nothing in your environment is ever changed.

Start with your own tenant.

Book a demo and see what Praefic finds in your own Azure estate. It connects with read-only access, so nothing in your environment is ever changed.

Start with your own tenant.

Book a demo and see what Praefic finds in your own Azure estate. It connects with read-only access, so nothing in your environment is ever changed.

FAQ's

Praefic FAQ

FAQ's

Praefic FAQ

Does Praefic change anything in my Azure environment?
How is this different from Azure Advisor or Defender for Cloud?
Do I need Defender for Cloud or Entra ID P2?
Can we connect more than one tenant?
How do exceptions work?
Is AI used on our data?
How do Initiatives work with our existing ticket system?
Does Praefic need access to our billing account?
Do you store who made changes in our tenant?

Ready to see what your Azure estate is really telling you?

Book a demo or talk with us about your Azure environment.

Ready to see what your Azure estate is really telling you?

Book a demo or talk with us about your Azure environment.