Entra ID Configuration Health Checklist
Retrospective: this article looks back at events from July 2023, written in 2026 with the benefit of hindsight.
Use this checklist to review the health of your Microsoft Entra ID configuration.
Authentication
- Security Defaults or Conditional Access requiring MFA for all users.
- Legacy authentication blocked.
- Phishing-resistant MFA for admins.
- Authentication methods policy migrated from legacy MFA/SSPR settings.
- SMS and voice limited or disabled.
Privileged access
- Fewer than five permanent Global Administrators.
- Two break-glass accounts, tested, monitored.
- PIM for admin roles (if P2).
- Admin accounts cloud-only.
Applications
- User consent restricted; admin consent workflow enabled.
- High-privilege app registrations reviewed; owners assigned.
- Expired or long-lived app secrets cleaned up.
External identities
- Guest invitation restrictions set.
- Cross-tenant access settings reviewed.
- Guest access reviews scheduled.
Hybrid
- Entra Connect or cloud sync on a supported version.
- Entra Connect servers treated as Tier 0.
- Password hash sync enabled (for resilience and leaked credential detection).
Monitoring
- Sign-in and audit logs exported to a SIEM or retained adequately.
- Identity Protection risk policies configured (if P2).
- Alerts on role changes and break-glass sign-ins.
Tooling
- Scripts migrated from deprecated AzureAD and MSOnline modules.
Free assessment tools
- Microsoft Zero Trust Assessment, Maester and CISA ScubaGear can check many of these automatically.