Entra ID

Entra ID security across customer tenants

Identity is where most Microsoft 365 compromise starts and where most posture regressions happen between reviews. SecurityScore.me assesses Entra ID per customer tenant through read-only Microsoft Graph and surfaces the gaps as ranked findings.

The identity surface across a tenant

An Entra ID review answers one question in five parts: who can sign in, from where, with what, with how much privilege, and what happens when that goes wrong.

Authentication methods and MFA

Which methods are enabled, which users have a strong method registered, and whether weaker options such as SMS are still primary. Registration is checked separately from enforcement, because a tenant can have MFA available while a meaningful share of accounts never use it.

Conditional Access

Policy coverage, exclusions, conditions, and whether report-only policies were ever moved to enforcement. Conditional Access is evaluated as a set, because the risk usually sits in the gap between policies rather than in any single one.

Privileged roles

Standing assignments to Global Administrator and other high-privilege roles, compared against how many people genuinely need them, and whether access is permanent or time-bound.

Guest and external access

How many guests exist, what they can enumerate, and whether invitations are restricted to administrators. Stale guests from finished projects accumulate quietly.

Sign-in risk and identity protection

Risky users and risky sign-in signals where the customer is licensed for them, so active identity risk is visible alongside configuration.

Gaps MSPs find over and over

MFA registered but not enforced

Accounts excluded from the MFA policy and included in nothing else have no second factor at all. These are the accounts that get phished successfully.

Standing Global Administrators

More permanent Global Admins than the environment needs, often including accounts that also carry a mailbox and a licence, which makes them phishing targets with tenant-wide rights attached.

Legacy authentication still reachable

IMAP, POP, and SMTP AUTH bypass Conditional Access and cannot present a second factor. They are frequently re-enabled for one device and never turned back off.

Break-glass accounts missing or misused

No emergency access account, an account that has drifted into everyday use, or one that is not actually excluded from the policies it needs to survive a misconfiguration.

How it is reviewed here

Per-customer workspace
Entra ID posture scoped to each tenant, comparable across the portfolio.
Ranked findings
Identity issues carry severity, remediation guidance, and customer context.
Scheduled re-assessment
Identity checks run on the monitoring schedule, not just at onboarding.
Drift raised as it happens
A disabled policy or a new exclusion becomes a finding shortly after the change.
Needs attention

Identity drift between reviews

A policy disabled to troubleshoot

Conditional Access switched off for a support case and left off. Invisible in the portal until policy state is checked.

A "temporary" exclusion

One account added to a policy exclusion and never removed, quietly widening the hole every week.

SMTP AUTH switched back on

Re-enabled tenant-wide or per mailbox for a single legacy device, reopening a path around MFA.

A new standing admin

A privileged role granted for a project and not revoked, adding blast radius no one is tracking.

Related pages

Frequently asked questions

Next steps

Review Entra ID posture across customer tenants