Back to category

Week 2

Perform a Microsoft Entra ID Identity Review

Beginner
Microsoft Security Engineer
Microsoft Security Best Practices
Microsoft Entra ID

Client Background

Sunrise Retail Group, a 600-store retailer, migrated identity to Microsoft Entra ID two years ago and relies on it for Azure, M365, and a custom point-of-sale cloud app. The platform team knows tenancy has grown faster than governance, and leadership wants an independent identity review after a guest user kept accessing reports for months after their contract ended.

Business Environment

Entra ID supports ~4,000 internal users and roughly 600 guest/external collaborators across merchandising, vendors, and franchisees, with B2B collaboration enabled tenant-wide. Administrative roles are self-managed by IT, Privileged Identity Management (PIM) is licensed but unused, and access reviews have never been configured.

Security Incident

No breach; the engagement is proactive. The trigger was the lingering guest-user access discovery plus an upcoming SOC 2 review requiring evidence of identity governance, prompting leadership to commission this review.

Scope

Standalone Microsoft Entra ID tenant review covering user and guest accounts, administrative and custom roles, PIM eligibility, conditional access posture, app registrations and service principals, and access-review/entitlement management coverage. Excludes on-prem Active Directory and workload/data-plane permissions.

Objectives

  • Review user identities
  • Identify guest accounts
  • Review administrator assignments
  • Evaluate identity hygiene

Required Deliverables

Identity Assessment Report
2 hrs estimated