Microsoft Entra ID Posture Report
Delivers a weekly Entra ID report on permanent privileged roles, Conditional Access changes, and expiring app credentials, with what changed since last week.
What this agent does
This read-only agent checks the health of a Microsoft Entra ID tenant every week. It measures which enabled users have no registered MFA method or only a weak one, and which privileged role holders lack a phishing-resistant method. It lists active and eligible role assignments, dormant accounts that are still enabled, and guest accounts with no recent sign-in. It lists app registrations whose credentials expire soon or never. It compares the Conditional Access policies with last week and names who changed what. It summarizes risky users, risky sign-ins, and any legacy authentication still in use.
The challenge
A Global Administrator is assigned as permanently active instead of eligible, so the role never expires. A Conditional Access policy is set to report-only during a rollout and never enforced. A privileged account syncs from on-premises Active Directory. A compromise on premises then reaches the cloud tenant. An app registration's client secret is renewed for two years with no owner. A guest invited for one project keeps access for years. Nobody reviews the role assignments, Conditional Access, and app credentials together.
The solution
The agent reads users, methods, role assignments, Conditional Access, applications, and sign-in logs each week. It compares them with the previous week and leads with what changed. It separates permanent role assignments from eligible ones. It reports a check that needs a higher license as not checked, never as fine. Provides a weekly briefing with the fix for each item.
Workflow
- 01
Check users and methods
List enabled users with their registered authentication methods and last sign-in, and flag weak methods, no methods, dormant accounts, and stale guests.
- 02
Check privileged roles
List active and eligible assignments for privileged roles, and check each holder's methods, last sign-in, source, and whether the assignment is permanent.
- 03
Check policies, apps, and sign-ins
Compare Conditional Access and authentication methods policies with last week, list app credentials and owners, and summarize risky and legacy sign-ins and admin audit events.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# Microsoft Entra ID Posture Report
## Measurable outcomes
Every week, the identity admin knows which privileged roles are permanent, what changed in Conditional Access, and which app credentials expire soon. Track the users without a strong method, the permanent privileged assignments, the expiring credentials, and the open action items on every run.
## Procedure
Once a week, list the enabled users in the tenant with their registered authentication methods and last sign-in. Count users with no MFA method registered, and list them by department. Count users whose strongest method is SMS or voice, and list them by department. Flag enabled users with no interactive sign-in in the last 90 days, unless I set another window. Flag guest users with no sign-in in 90 days. Flag guest users whose invitation was never redeemed. List every active and eligible assignment for the privileged roles. Start with Global Administrator, Privileged Role Administrator, Privileged Authentication Administrator, Security Administrator, Conditional Access Administrator, Application Administrator, Cloud Application Administrator, Hybrid Identity Administrator, and Exchange Administrator. Flag each holder without a phishing-resistant method such as a FIDO2 key, passkey, or certificate. Flag each permanent active assignment where an eligible one would do. Flag each holder with no sign-in in 30 days. Flag privileged role holders synced from on-premises Active Directory. Flag role-assignable groups whose owners are not admins. Flag more Global Administrators than the number I set. Confirm that the break-glass accounts I name are excluded from Conditional Access. Confirm that they signed in within the period I set. Compare the Conditional Access policies with last week's report. Name each policy created, deleted, changed, or left in report-only, and who changed it from the audit log. Flag any policy exclusion group that grew. Check whether security defaults are on in a tenant with no Conditional Access policies. Flag SMS and voice enabled in the authentication methods policy. List app registrations and service principals with client secrets or certificates. Flag credentials that expire within 30 days. Flag credentials valid for more than 2 years. Flag apps with no owner. Summarize risky users and risky sign-ins from Identity Protection. Summarize sign-ins that used legacy authentication. Summarize the admin audit events since the last report. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Microsoft Graph access to users, authentication method registration, directory roles and Privileged Identity Management assignments, Conditional Access and authentication methods policies, applications and service principals, Identity Protection, and the sign-in and audit logs, and nothing more. It runs as an app with Graph read permissions or under the Global Reader role. PIM, Identity Protection, and last sign-in need Entra ID P1 or P2. On a lower license, the agent reports those checks as not checked. It never changes users, methods, roles, policies, or applications. Reports show counts, departments, and policy names. User names appear as stable pseudonyms. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools