Skip to content

Praefic FAQ

Access & permissions

Does Praefic change anything in my Azure environment?

No. Praefic uses Azure's built-in Reader role and holds no write permissions. It reads configuration, cost and Activity Log data and reports on it. Every fix stays in your hands.

What exactly do I grant?

Two things: admin consent for the multi-tenant Praefic Scanner app in your Entra tenant, and the Reader role for that app on the management group or subscriptions you want scanned. See On-boarding.

Can I limit Praefic to some subscriptions?

Yes. Assign Reader only where you want Praefic to look, and switch individual subscriptions off under Settings → Connections.

Can I connect more than one tenant?

Yes. One Praefic organization can hold several tenant connections.

What happens if I remove the Reader role?

Scans of the affected subscriptions fail and Praefic says so on the affected pages. It keeps the last data it read — labelled with its age — rather than reporting an empty estate, and it does not resolve findings it can no longer see.

Do I need Defender for Cloud or Entra ID P2?

No. Praefic's own checks work without Defender. Checks for Azure-resource PIM need Entra ID P2 where you use PIM; without it, those checks simply have nothing to read.

Findings

How is this different from Azure Advisor or Defender for Cloud?

Praefic reads Advisor alongside its own checks rather than replacing it. What it adds is memory and ownership: findings persist across scans, can be assigned, acknowledged or excepted, belong to initiatives and maturity levels, and show history and trends. Where Advisor restates one of Praefic's findings on the same resource, it appears under Duplicates instead of being counted twice.

How often does Praefic scan?

Every area is scanned on a schedule (daily by default), and Scan now starts one immediately.

A finding I fixed is still open. Why?

A finding resolves when the next scan no longer sees the problem. If it is still open after a scan, the change may not have reached that resource — check the workbench's Who changed this panel and the resource itself.

Can I change a check's severity or turn it off?

Yes, per organization, under Settings → Rules.

Cost

Does Praefic need access to our billing account?

No. Cost data is read per subscription with the same Reader access.

Why does a subscription show no cost data?

Some Azure offers — sponsorships, MSDN and Visual Studio subscriptions, free trials — have no Cost Management API. Praefic reports that rather than showing a cost of zero.

Data & privacy

What does Praefic store?

Resource configuration relevant to its checks, the findings and their history, daily spend per resource, and the Azure Activity Log for connected subscriptions. Secrets, keys and data inside your resources are never read.

Does Praefic store who made changes?

By default it stores the Activity Log's identity details (who and from where) so it can attribute changes. An administrator can switch this off under Settings → Organization.

Is AI used on our data?

Only where you choose to use it. AI-written report narratives are off by default and enabled per organization. AI remediation suggestions and plain-English search run only when a user asks for them.

Getting started

What is the "Contoso (sample data)" connection?

A fictional estate added to every new organization so you can explore Praefic before your own scan completes. It is never scanned. Remove it under Settings → Connections → Remove sample data whenever you like — your own scan history, including your trend lines, is kept.

Support

Contact us at support@just-software.com.