§ Cybersecurity proof & diagnostic assets·print-friendly · evidence list

The identity evidence a tenant review needs.

A checklist of the exports and screenshots to gather before an identity and access review — the same client-provided evidence a structured, point-in-time review works from. Print it, tick it, and you arrive at the review with the tenant already documented.

About this asset

Audience
IT and security owners preparing for a point-in-time identity and access review of a Microsoft 365 tenant.
Owner service
Microsoft 365 & Identity Security Assessment
Classification
Classification: Public · Version 1.0 · July 2026
Methodology
The evidence list reflects the client-provided exports a manual advisory identity review works from, organized around identity and access-control outcomes in NIST Cybersecurity Framework 2.0 (NIST CSWP 29, category PR.AA) and the account-security goals in the CISA Cross-Sector CPGs. It is a document-gathering aid, not a control benchmark.
Limitations
Point-in-time, self-diagnostic checklist you complete yourself. It is not a DSE assessment, an audit, an attestation, a scan, or legal advice, and it produces no compliance result or certification.
Verification
The framework references were checked against the csrc.nist.gov and cisa.gov landing pages linked below. Feature and export names describe standard tenant administration surfaces and are not a capability claim about any product.
The evidence checklist

Seven bundles to gather before the review.

Each item is a client-provided export or screenshot. You pull it from your own admin surfaces; a reviewer never needs administrator credentials to read what you provide.

Administrative roles & privilege

  • Admin-role inventory. Export of who holds each administrative role and whether the assignment is permanent or time-bound.Standing global admin and stale privilege are the highest-impact identity findings.
  • Privileged-access approach. Note whether just-in-time elevation and break-glass accounts exist and how they are protected.

Authentication & access policy

  • Conditional-access export. The full set of conditional-access policies, including which are report-only versus enforced.Gaps and disabled policies are where enforcement quietly fails.
  • MFA registration report. Who has registered strong authentication and who is still exempt or unregistered.
  • Legacy-authentication report. Evidence of whether legacy/basic authentication protocols are still permitted anywhere.Legacy protocols bypass modern access controls.

Applications & external access

  • App registrations & consent grants. Registered applications, service principals, and the permissions users or admins have consented to.Over-permissioned or forgotten app grants are a common data-access path.
  • Guest-access review. External/guest accounts, what they can reach, and the sharing settings that govern them.

Monitoring & retention

  • Audit-log retention setting. The current audit-log retention configuration and how long sign-in and admin activity is kept.Short retention means the evidence to investigate an incident may already be gone.

Bring the evidence — we do the manual advisory review.

A free 30-minute Cyber Risk Check scopes a point-in-time review of your client-provided configuration and exports, ending in an evidence register, findings, and remediation priorities.

What this is and is not. A point-in-time, self-diagnostic evidence checklist. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice, and it is not an automated scan of your tenant. We review client-provided configuration and exports in a manual advisory review and make no Microsoft partnership, certification, or reseller claim.

Primary sources, verified.