← Microsoft 365 audit scope

Entra ID (Identity)

17 checks · 3 sub-categories

Identity is the control plane of a Microsoft 365 tenant. Almost every real-world breach we read about starts with one account — usually an administrator or a long-forgotten staff login — that either had no multi-factor authentication or had far more privilege than the job required. This section of the audit establishes exactly who can sign in, who can change things, and what stands between an attacker with a stolen password and your data.

Multi-factor authentication coverage

  • MFA enforced on every administrator account

    Every account holding an admin role is checked for enforced MFA — whether that comes from Security Defaults, a Conditional Access policy, per-user MFA or a third-party provider such as Duo. A single unprotected Global Admin undermines every other control in the tenant.

    • Essential Eight — Multi-factor authentication
    • CIS 1.1.1
  • MFA enforced on every standard user account

    We report the exact list of staff mailboxes with no enforced second factor, including licensed accounts that were set up before MFA was rolled out and quietly exempted.

    • Essential Eight — Multi-factor authentication
    • CIS 1.1.2
  • MFA number matching enabled

    Number matching in the Microsoft Authenticator app defeats 'MFA fatigue' attacks, where an attacker spams approval prompts until someone taps Approve to make it stop.

    • Essential Eight — Multi-factor authentication
    • CIS 1.1.5
  • Legacy per-user MFA migrated to Conditional Access

    Per-user MFA is being retired by Microsoft. We flag tenants still relying on it and identify what has to move before enforcement dates hit.

  • MFA registration campaign configured

    Checks whether Microsoft's nudge campaign is on to move users off SMS onto the Authenticator app during their normal sign-ins, rather than through a disruptive big-bang rollout.

  • Phishing-resistant methods available

    Reviews whether FIDO2 security keys or passkeys are available and, where appropriate, required for your highest-privilege accounts — the only MFA methods a fake sign-in page cannot capture.

    • ACSC ISM — phishing-resistant MFA

Privileged access

  • Global Administrator count within recommended limits

    Microsoft recommends between two and four Global Admins. We count yours, name them, and flag any that are shared, unlicensed or attached to a former staff member.

    • Essential Eight — Restrict administrative privileges
    • CIS 1.1.7
  • Least-privilege role assignment

    Checks whether people holding Global Admin could do their job with a narrower role such as Exchange Administrator, User Administrator or Helpdesk Administrator.

    • Essential Eight — Restrict administrative privileges
  • Separate, non-mailbox admin accounts

    Day-to-day email and browsing should not happen from an account that can rewrite tenant security policy. We report where admin and user identities are the same person's single login.

    • ACSC ISM — privileged access management
  • Privileged Identity Management / just-in-time elevation

    Where licensing allows, we check whether privileged roles are permanently assigned or granted just-in-time with approval and an audit trail.

    • Essential Eight — Restrict administrative privileges
    • CIS 1.1.15
  • PowerShell access restricted for non-administrators

    Standard users generally have no need for remote PowerShell into Exchange Online. Leaving it open gives an attacker a scriptable path through your tenant.

    • Essential Eight — Application control

Account hygiene

  • Inactive and stale accounts

    Accounts with no sign-in or app activity for 30+ days are listed. These are both a licensing cost and an attack surface — nobody notices when a dormant account gets used.

    • Privacy Act — data minimisation
  • Self-service password reset enabled

    SSPR reduces helpdesk social-engineering risk (the classic 'reset my password, I'm locked out' call) and speeds recovery after a compromise.

    • CIS 1.1.8
  • Temporary Access Pass configured

    A safe, time-limited way to onboard staff or recover a user who has lost their MFA device — without falling back to an unprotected password.

  • Sign-in page branding applied

    A branded sign-in page makes credential-harvesting clones easier for your staff to spot.

  • Guest user access permissions restricted

    Controls who can invite guests and what guests can see of your directory — by default, guests can enumerate far more than most owners expect.

    • CIS 1.1.20
    • Privacy Act — access control
  • Idle session timeout configured

    Sets how long a Microsoft 365 web session stays alive on an unattended or shared device.

    • ACSC ISM — session termination
    • CIS 1.1.3

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.