Onam Security
Identity and entitlements (CIEM) · ask both

Onam vs CIEM tools

Cloud infrastructure entitlement management is sold both as a specialist product and as one engine inside a wider platform. If you are deciding between a dedicated CIEM tool and Onam — or replacing Microsoft Entra Permissions Management, which Microsoft has retired — these are the questions that separate the options.

How to read this page. Everything said about the dedicated CIEM tools here is a quotation from their own public pages, with the address and the date we read it. We do not say what anyone else’s product cannot do — products change monthly, and second-hand assertions age into lies. Then seven questions, answered for Onam only, and plainly where we are not the right choice. Ask the dedicated CIEM tools the same seven.

The dedicated CIEM tools, in their own words

Quoted verbatim from their public pages. If a page has changed, the quote is out of date, not invented — tell us and we will update it.

Sonrai Security — Cloud Permissions Firewall
“A one-click solution to least privilege without disrupting DevOps.”
“The Cloud Permissions Firewall removes dangerous permissions before an attack can use them. Unused privileges, services, and regions are blocked in seconds with automated global policies.”
“When an agent, human or machine needs new access, an automated just-in-time workflow is routed through your ChatOps tool for seamless approval.”

Source: sonraisecurity.com, accessed 5 October 2026.

Microsoft Entra Permissions Management
“Microsoft Entra Permissions Management is a cloud infrastructure entitlement management (CIEM) solution that provides comprehensive visibility into permissions assigned to all identities.”
“Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product.”

Microsoft's own documentation now sits under previous versions. If you are on it, you are choosing a replacement either way.

Source: learn.microsoft.com, Permissions Management overview (previous versions), accessed 5 October 2026.

The seven questions

Our answers. Put the same list in front of the dedicated CIEM tools.

  1. 1

    Does it resolve effective permissions, or only list attached policies?

    Effective permissions. On AWS, group policies are expanded onto members, conditions are classified, explicit denies are netted out and SCP deny statements are checked; Azure assignments, GCP bindings and Kubernetes RoleBindings resolve into the same table. Trust relationships are analysed alongside.

  2. 2

    Is unused access measured against real activity?

    On AWS, yes: granted actions are compared with CloudTrail activity collected by Onam's threat detection, and the high-risk unused ones are listed. Usage-based analysis for the other clouds is not shipped yet. Findings that need no logs — escalation paths, shadow admins, cross-account trust — work as soon as the account is connected.

  3. 3

    Are machine identities first-class?

    Yes. AWS roles are classified by who can assume them — AWS services, execution roles, CI/CD over OIDC, EKS service accounts, cross-account principals — and Azure managed identities, GCP service accounts and Kubernetes service accounts are resolved like users, with the link from each VM, instance or pod to the identity it runs as.

  4. 4

    Which privilege-escalation paths have actually been used?

    Escalation paths found from policy are cross-checked against cloud detection and response: when the same identity has recently called escalation operations such as AssumeRole, PassRole or CreatePolicyVersion, the AWS finding is raised and marked CDR-confirmed. That shows the identity is exercising escalation operations; it does not prove each hop was walked.

  5. 5

    Does it look inside databases, or only at cloud IAM?

    Partly. Database CIEM connects to databases with credentials you provide and detects identity activity inside them — new superuser and admin role grants, failed-login spikes, bulk reads. It does not yet analyse table-level grants as effective permissions.

  6. 6

    How does an access review end?

    With a recorded decision. Each flagged identity carries a state — pending, needs remediation, reviewed or deferred — with the reviewer, the time and the evidence that triggered it, in an audit trail. Decisions expire and come back for review.

  7. 7

    Is identity risk connected to data and network exposure?

    On the same graph. An over-permissioned role becomes one step in an attack path that ends at a sensitive data store, so it is ranked by what it reaches, not by how many permissions it has.

Where we are not the right choice

A comparison page that hides its own limits is marketing, not evaluation. Weigh this one.

The honest gap

The honest gap: Onam finds dangerous and, on AWS, unused permissions, but it does not enforce anything. Nothing in Onam blocks a permission by policy or brokers just-in-time access — your team applies the change. If automated enforcement is what you are buying, Sonrai describes exactly that in its own words above, and we do not offer it.

Do not take our word for any of it

Run a scan against one account and tell us whether the attack paths we surface are real. If they are noise, we want to hear that — it is more useful to us than a signature. That is the same offer we make to everyone, and it is the only claim on this page you can check yourself today.

Other comparisons

Building a shortlist instead? Wiz alternatives in 2026 and the best CSPM tools in 2026, every vendor in its own published words.

Last reviewed 5 October 2026. Onam’s figures come from our published fact set. Quotations are from each vendor's own pages on the dates shown. If anything here is wrong or out of date — including anything about the dedicated CIEM tools — tell us at hello@onamsecurity.com and we will correct it.