Entra ID (Identity)
17 checks · 3 sub-categories
Identity is the control plane of a Microsoft 365 tenant. Almost every real-world breach we read about starts with one account — usually an administrator or a long-forgotten staff login — that either had no multi-factor authentication or had far more privilege than the job required. This section of the audit establishes exactly who can sign in, who can change things, and what stands between an attacker with a stolen password and your data.
Multi-factor authentication coverage
MFA enforced on every administrator account
Every account holding an admin role is checked for enforced MFA — whether that comes from Security Defaults, a Conditional Access policy, per-user MFA or a third-party provider such as Duo. A single unprotected Global Admin undermines every other control in the tenant.
- Essential Eight — Multi-factor authentication
- CIS 1.1.1
MFA enforced on every standard user account
We report the exact list of staff mailboxes with no enforced second factor, including licensed accounts that were set up before MFA was rolled out and quietly exempted.
- Essential Eight — Multi-factor authentication
- CIS 1.1.2
MFA number matching enabled
Number matching in the Microsoft Authenticator app defeats 'MFA fatigue' attacks, where an attacker spams approval prompts until someone taps Approve to make it stop.
- Essential Eight — Multi-factor authentication
- CIS 1.1.5
Legacy per-user MFA migrated to Conditional Access
Per-user MFA is being retired by Microsoft. We flag tenants still relying on it and identify what has to move before enforcement dates hit.
MFA registration campaign configured
Checks whether Microsoft's nudge campaign is on to move users off SMS onto the Authenticator app during their normal sign-ins, rather than through a disruptive big-bang rollout.
Phishing-resistant methods available
Reviews whether FIDO2 security keys or passkeys are available and, where appropriate, required for your highest-privilege accounts — the only MFA methods a fake sign-in page cannot capture.
- ACSC ISM — phishing-resistant MFA
Privileged access
Global Administrator count within recommended limits
Microsoft recommends between two and four Global Admins. We count yours, name them, and flag any that are shared, unlicensed or attached to a former staff member.
- Essential Eight — Restrict administrative privileges
- CIS 1.1.7
Least-privilege role assignment
Checks whether people holding Global Admin could do their job with a narrower role such as Exchange Administrator, User Administrator or Helpdesk Administrator.
- Essential Eight — Restrict administrative privileges
Separate, non-mailbox admin accounts
Day-to-day email and browsing should not happen from an account that can rewrite tenant security policy. We report where admin and user identities are the same person's single login.
- ACSC ISM — privileged access management
Privileged Identity Management / just-in-time elevation
Where licensing allows, we check whether privileged roles are permanently assigned or granted just-in-time with approval and an audit trail.
- Essential Eight — Restrict administrative privileges
- CIS 1.1.15
PowerShell access restricted for non-administrators
Standard users generally have no need for remote PowerShell into Exchange Online. Leaving it open gives an attacker a scriptable path through your tenant.
- Essential Eight — Application control
Account hygiene
Inactive and stale accounts
Accounts with no sign-in or app activity for 30+ days are listed. These are both a licensing cost and an attack surface — nobody notices when a dormant account gets used.
- Privacy Act — data minimisation
Self-service password reset enabled
SSPR reduces helpdesk social-engineering risk (the classic 'reset my password, I'm locked out' call) and speeds recovery after a compromise.
- CIS 1.1.8
Temporary Access Pass configured
A safe, time-limited way to onboard staff or recover a user who has lost their MFA device — without falling back to an unprotected password.
Sign-in page branding applied
A branded sign-in page makes credential-harvesting clones easier for your staff to spot.
Guest user access permissions restricted
Controls who can invite guests and what guests can see of your directory — by default, guests can enumerate far more than most owners expect.
- CIS 1.1.20
- Privacy Act — access control
Idle session timeout configured
Sets how long a Microsoft 365 web session stays alive on an unattended or shared device.
- ACSC ISM — session termination
- CIS 1.1.3
Want to know where you actually stand?
Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.