The identity evidence a tenant review needs.
A checklist of the exports and screenshots to gather before an identity and access review — the same client-provided evidence a structured, point-in-time review works from. Print it, tick it, and you arrive at the review with the tenant already documented.
Seven bundles to gather before the review.
Each item is a client-provided export or screenshot. You pull it from your own admin surfaces; a reviewer never needs administrator credentials to read what you provide.
Administrative roles & privilege
- Admin-role inventory. Export of who holds each administrative role and whether the assignment is permanent or time-bound.Standing global admin and stale privilege are the highest-impact identity findings.
- Privileged-access approach. Note whether just-in-time elevation and break-glass accounts exist and how they are protected.
Authentication & access policy
- Conditional-access export. The full set of conditional-access policies, including which are report-only versus enforced.Gaps and disabled policies are where enforcement quietly fails.
- MFA registration report. Who has registered strong authentication and who is still exempt or unregistered.
- Legacy-authentication report. Evidence of whether legacy/basic authentication protocols are still permitted anywhere.Legacy protocols bypass modern access controls.
Applications & external access
- App registrations & consent grants. Registered applications, service principals, and the permissions users or admins have consented to.Over-permissioned or forgotten app grants are a common data-access path.
- Guest-access review. External/guest accounts, what they can reach, and the sharing settings that govern them.
Monitoring & retention
- Audit-log retention setting. The current audit-log retention configuration and how long sign-in and admin activity is kept.Short retention means the evidence to investigate an incident may already be gone.
Bring the evidence — we do the manual advisory review.
A free 30-minute Cyber Risk Check scopes a point-in-time review of your client-provided configuration and exports, ending in an evidence register, findings, and remediation priorities.
What this is and is not. A point-in-time, self-diagnostic evidence checklist. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice, and it is not an automated scan of your tenant. We review client-provided configuration and exports in a manual advisory review and make no Microsoft partnership, certification, or reseller claim.
Primary sources, verified.