Microsoft 365 and Entra configurations often accumulate over time as licensing, user populations, applications, and operating responsibilities change. The result may be a tenant where the basics work but identity governance, recovery planning, and evidence ownership need a more deliberate review.
Here is a reference baseline for an Entra and Microsoft 365 review. It is not universal: licensing, user populations, workload identities, regulatory context, existing access patterns, and the assessor’s control set can all change the implementation.
Conditional Access: four decisions to review early
These are common review areas, not a universal policy set or deployment order. Test every policy against licensing, emergency access, workload identities, legacy protocols, user populations, and business continuity.
-
Legacy authentication. Identify protocols and applications that cannot use modern authentication. Establish a retirement or exception plan before enforcing a broad block.
-
Authentication strength and MFA coverage. Review who is covered, which methods are allowed, where exceptions exist, and how privileged access differs from standard access.
-
Privileged access conditions. Evaluate device state, authentication strength, locations, administrative workstations, and activation controls for the roles in scope.
-
Risk and location signals. Named locations can support policy where business operations justify them, but travel, VPN egress, remote work, and false positives require a tested exception and recovery path.
Named locations: document what trust means
Useful named locations may include:
- Approved office or network egress addresses
- Corporate VPN egress addresses
- Countries or regions supported by a documented business requirement
Avoid treating location as identity proof. Document why a location is included, which policies consume it, who owns the addresses, and how changes are reviewed.
Emergency access: design, monitor, and test recovery
Emergency access must account for failure of normal identities, federation, authentication methods, or conditional-access configuration. The number of accounts, credential method, storage process, exclusions, alerting, and test cadence should follow the organization's threat model and recovery requirements.
Document the recovery procedure, monitor use, and test it on an approved cadence. A copied account recipe is not a substitute for validating the actual tenant and its dependencies.
Privileged Identity Management: just-in-time elevation
Privileged Identity Management can reduce unnecessary standing access by making selected assignments eligible and requiring activation. The right controls depend on role sensitivity, operational coverage, licensing, approval paths, and incident procedures.
For roles included in scope, review:
- Permanent and eligible assignments
- Activation duration and authentication requirements
- Approval, notification, and emergency procedures
- Access reviews and ownership
Activation history can support investigation and evidence collection, but the final control interpretation remains with the organization's control owner and assessor.
Logging: send sign-in logs to Log Analytics
Native Entra log retention varies by license and log type and may not meet your organization’s investigation or evidence needs. Export the required logs to an appropriate destination and set retention from your contractual, regulatory, incident-response, and assessor requirements. Confirm the final period with the control owner, assessor, and counsel rather than treating one number as universal.
Exporting and retaining the right logs materially improves investigation and evidence collection. The value depends on whether the organization also assigns an owner, monitors the signals, tests retrieval, and aligns retention with its actual control requirements.
What this baseline does not decide
The following may be relevant, but they require environment-specific decisions:
- B2B/B2C external collaboration policy
- Cross-tenant access settings
- Identity Protection risk policy and licensing
- Customer Lockbox and other workload-specific controls
This is a review framework, not a universal day-one configuration. The Security & Compliance service explains how Falstech scopes control assessment, implementation, evidence preparation, exclusions, and handoff. You can discuss your environment when the decision requires hands-on support.