- Documentation
- Cleaning out permission given to individuals instead of groups
- Safe screening (groups/individuals that should not have access)
- Deleted identities still visible in the AIM list
- Preparing for features like Privileged identity management (PIM)
- Comparing changes in access since the last audit
- Etc
And the portal built in GUI works but is not particularly flexible or easy to use when you have multiple subscriptions