A policy disabled to troubleshoot
Conditional Access switched off for a support case and left off. Invisible in the portal until policy state is checked.
Entra ID
Identity is where most Microsoft 365 compromise starts and where most posture regressions happen between reviews. SecurityScore.me assesses Entra ID per customer tenant through read-only Microsoft Graph and surfaces the gaps as ranked findings.
An Entra ID review answers one question in five parts: who can sign in, from where, with what, with how much privilege, and what happens when that goes wrong.
Which methods are enabled, which users have a strong method registered, and whether weaker options such as SMS are still primary. Registration is checked separately from enforcement, because a tenant can have MFA available while a meaningful share of accounts never use it.
Policy coverage, exclusions, conditions, and whether report-only policies were ever moved to enforcement. Conditional Access is evaluated as a set, because the risk usually sits in the gap between policies rather than in any single one.
Standing assignments to Global Administrator and other high-privilege roles, compared against how many people genuinely need them, and whether access is permanent or time-bound.
How many guests exist, what they can enumerate, and whether invitations are restricted to administrators. Stale guests from finished projects accumulate quietly.
Risky users and risky sign-in signals where the customer is licensed for them, so active identity risk is visible alongside configuration.
Accounts excluded from the MFA policy and included in nothing else have no second factor at all. These are the accounts that get phished successfully.
More permanent Global Admins than the environment needs, often including accounts that also carry a mailbox and a licence, which makes them phishing targets with tenant-wide rights attached.
IMAP, POP, and SMTP AUTH bypass Conditional Access and cannot present a second factor. They are frequently re-enabled for one device and never turned back off.
No emergency access account, an account that has drifted into everyday use, or one that is not actually excluded from the policies it needs to survive a misconfiguration.
Conditional Access switched off for a support case and left off. Invisible in the portal until policy state is checked.
One account added to a policy exclusion and never removed, quietly widening the hole every week.
Re-enabled tenant-wide or per mailbox for a single legacy device, reopening a path around MFA.
A privileged role granted for a project and not revoked, adding blast radius no one is tracking.
The per-tenant checklist for MFA gaps, legacy auth, and break-glass accounts.
Identity as part of the wider posture program.
How identity fits the other Microsoft 365 security domains.
Where identity findings are prioritised per customer.
A structured review that includes the identity surface.
The identity-weighted score that sits behind many findings.