Skip to main content

Identity

Tier 1 Checks

#CheckLicense
I01High Global Administrator to privileged user ratio
I02Administrative privileges are tightly limited to prevent compromise
I03All privileged role assignments are activated just in time and not permanently activeP2
I04All Microsoft Entra privileged role assignments are managed with PIMP2
I05Privileged accounts are cloud native identities
I06Privileged accounts have phishing-resistant methods registered
I07Emergency access accounts are configured appropriately
I08Block legacy authentication policy is configuredP1
I09All users are required to register for MFAP1
I10SMS and Voice Call authentication methods are disabled
I11All user sign-in activity uses phishing-resistant authentication methodsP1
I12User consent settings are restricted
I13Admin consent workflow is enabled
I14Guest access is limited to approved tenants
I15Guests are not assigned high privileged directory roles
I16Guest access is protected by strong authentication methods
I17Diagnostic settings are configured for all Microsoft Entra logs
I18Privileged role activations have monitoring and alerting configuredP2
I19Token protection policies are configuredP1
I20Migrate from legacy MFA and SSPR policiesP1
I21Manage the local administrators on Microsoft Entra joined devices
I22Sign-in risk-based Conditional Access policy is configuredP2
I23User risk-based Conditional Access policy is configuredP2
I24Password Hash Sync is enabled for resilience and leaked-credential detection
I25Group-based licensing is used to manage license assignmentP1

Tier 2 / Tier 3 coverage

This is Tier 1 — the highest-impact starting set. Microsoft publishes ~120 additional Identity checks at the source page, spanning deeper privileged-identity governance, advanced conditional-access scenarios, and lifecycle-management automation. Tier 2 and Tier 3 coverage is scoped per engagement.

📩 Don't Miss the Next Solution

Join the list to see the real-time solutions I'm delivering to my GCC High clients.