Skip to main content
{ Identity and Access / Reporting and Compliance }

Microsoft Entra ID Posture Report

Delivers a weekly Entra ID report on permanent privileged roles, Conditional Access changes, and expiring app credentials, with what changed since last week.

What this agent does

This read-only agent checks the health of a Microsoft Entra ID tenant every week. It measures which enabled users have no registered MFA method or only a weak one, and which privileged role holders lack a phishing-resistant method. It lists active and eligible role assignments, dormant accounts that are still enabled, and guest accounts with no recent sign-in. It lists app registrations whose credentials expire soon or never. It compares the Conditional Access policies with last week and names who changed what. It summarizes risky users, risky sign-ins, and any legacy authentication still in use.

The challenge

A Global Administrator is assigned as permanently active instead of eligible, so the role never expires. A Conditional Access policy is set to report-only during a rollout and never enforced. A privileged account syncs from on-premises Active Directory. A compromise on premises then reaches the cloud tenant. An app registration's client secret is renewed for two years with no owner. A guest invited for one project keeps access for years. Nobody reviews the role assignments, Conditional Access, and app credentials together.

The solution

The agent reads users, methods, role assignments, Conditional Access, applications, and sign-in logs each week. It compares them with the previous week and leads with what changed. It separates permanent role assignments from eligible ones. It reports a check that needs a higher license as not checked, never as fine. Provides a weekly briefing with the fix for each item.

Workflow

  1. 01

    Check users and methods

    List enabled users with their registered authentication methods and last sign-in, and flag weak methods, no methods, dormant accounts, and stale guests.

  2. 02

    Check privileged roles

    List active and eligible assignments for privileged roles, and check each holder's methods, last sign-in, source, and whether the assignment is permanent.

  3. 03

    Check policies, apps, and sign-ins

    Compare Conditional Access and authentication methods policies with last week, list app credentials and owners, and summarize risky and legacy sign-ins and admin audit events.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Microsoft Entra ID Posture Report

## Measurable outcomes

Every week, the identity admin knows which privileged roles are permanent, what changed in Conditional Access, and which app credentials expire soon. Track the users without a strong method, the permanent privileged assignments, the expiring credentials, and the open action items on every run.

## Procedure

Once a week, list the enabled users in the tenant with their registered authentication methods and last sign-in. Count users with no MFA method registered, and list them by department. Count users whose strongest method is SMS or voice, and list them by department. Flag enabled users with no interactive sign-in in the last 90 days, unless I set another window. Flag guest users with no sign-in in 90 days. Flag guest users whose invitation was never redeemed. List every active and eligible assignment for the privileged roles. Start with Global Administrator, Privileged Role Administrator, Privileged Authentication Administrator, Security Administrator, Conditional Access Administrator, Application Administrator, Cloud Application Administrator, Hybrid Identity Administrator, and Exchange Administrator. Flag each holder without a phishing-resistant method such as a FIDO2 key, passkey, or certificate. Flag each permanent active assignment where an eligible one would do. Flag each holder with no sign-in in 30 days. Flag privileged role holders synced from on-premises Active Directory. Flag role-assignable groups whose owners are not admins. Flag more Global Administrators than the number I set. Confirm that the break-glass accounts I name are excluded from Conditional Access. Confirm that they signed in within the period I set. Compare the Conditional Access policies with last week's report. Name each policy created, deleted, changed, or left in report-only, and who changed it from the audit log. Flag any policy exclusion group that grew. Check whether security defaults are on in a tenant with no Conditional Access policies. Flag SMS and voice enabled in the authentication methods policy. List app registrations and service principals with client secrets or certificates. Flag credentials that expire within 30 days. Flag credentials valid for more than 2 years. Flag apps with no owner. Summarize risky users and risky sign-ins from Identity Protection. Summarize sign-ins that used legacy authentication. Summarize the admin audit events since the last report. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Microsoft Graph access to users, authentication method registration, directory roles and Privileged Identity Management assignments, Conditional Access and authentication methods policies, applications and service principals, Identity Protection, and the sign-in and audit logs, and nothing more. It runs as an app with Graph read permissions or under the Global Reader role. PIM, Identity Protection, and last sign-in need Entra ID P1 or P2. On a lower license, the agent reports those checks as not checked. It never changes users, methods, roles, policies, or applications. Reports show counts, departments, and policy names. User names appear as stable pseudonyms.