Entra ID & IdentityHow-To & HardeningRetrospectives

Identity Security Program Checklist for Mid-Market Companies

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2022, written in 2026 with the benefit of hindsight.

Use this checklist to assess an identity security program for a mid-sized organization.

Strategy and ownership

  • An identity program owner is named.
  • Identity security metrics are reported to leadership.
  • A roadmap exists with funded priorities.

Authentication

  • MFA required for all users.
  • Phishing-resistant MFA for administrators and high-risk roles.
  • Legacy authentication blocked.
  • Passwordless rollout planned or underway.

Access control

  • Conditional Access baseline policies in place.
  • Access to sensitive data requires compliant devices.
  • SSO for major SaaS applications.

Privileged access

  • Fewer than five permanent Global Administrators.
  • Just-in-time access for admin roles.
  • Separate admin accounts.
  • Break-glass accounts tested.

Lifecycle

  • Joiners get access automatically based on role.
  • Movers lose old access.
  • Leavers are disabled within hours.
  • Quarterly access reviews for privileged roles and guests.

Non-human identities

  • Inventory of apps, service principals and service accounts.
  • Owners assigned.
  • Secretless authentication where possible.

Monitoring

  • Sign-in and audit logs retained and monitored.
  • Risk detections reviewed.
  • Help desk identity verification procedure enforced.
identity security program checklistMicrosoft Entra brand2022

More on this story