Identity and access security notes. Turn the notes into a review brief.
Identity is where most Microsoft 365 security control actually lives. These notes cover Conditional Access rollout, MFA scope, passkeys, admin sprawl, OAuth consent, password spray defence and the boring break-glass design that saves you when policy goes wrong.
Notes in this cluster
Read the checks that match the control family, then capture the evidence and owner before making a change.
Entra ID Mandatory MFA Phase 2 Scripts Fix
Microsoft's mandatory MFA rollout affects PowerShell and Azure CLI. Learn how to migrate legacy credentials to certificate-based service principals.
Windows LAPS with Entra ID Cloud Setup Guide
Shared local admin passwords are an instant Cyber Essentials Plus failure. Windows LAPS with Entra ID automatically rotates unique passwords per device.
Conditional Access Resource Exclusions: 2026
A narrow Conditional Access enforcement change started rolling out in June 2026. Most tenants need no action, but affected custom apps can now receive challenges they did not receive before.
Entra Connect Sync: September 2026 Deadline
Microsoft says Entra Connect Sync services below version 2.5.79.0 will stop on 30 September 2026. Check the live server, then choose upgrade or migration deliberately.
Microsoft 365 Security Cleanup Checklist for UK SMEs
Most Microsoft 365 tenants do not need a new product first. They need old admin access removed, MFA gaps closed, risky mail routes checked, sharing defaults tightened and evidence collected before an audit or incident forces the issue.
Cyber Essentials MFA Cloud Auto-Fail
Cyber Essentials v3.3 is blunt on MFA. In-scope cloud service access must use it, and Microsoft 365 teams need to prove policy enforcement across users, admins, guests, exclusions and emergency accounts.
Intune Mobile Passkeys and Credential Provider: Small Change, Useful Control
A practical look at passkeys on mobile, what Intune can protect, and where phone access still weakens Microsoft 365 control.
Microsoft-Managed Conditional Access Policies: Useful, but Still Needs Ownership
What Microsoft-managed Conditional Access policies actually do, where they help, and why they still need local ownership before anyone treats them as finished security work.
Password Spray Controls for Microsoft 365
The Microsoft 365 controls that do the most to raise the cost of password spray attacks, without pretending the answer is one magic setting.
Passkeys in Entra ID: Practical Rollout for Microsoft 365 Admins
A grounded rollout plan for passkeys in Microsoft Entra ID, including pilot scope, recovery, and the policy choices that matter more than the launch announcement.
OAuth App Consent Audit: The Microsoft 365 Backdoor People Miss
How to review OAuth app consent in Microsoft 365 properly, including user consent settings, admin workflow, and the apps that quietly end up with far too much access.
Microsoft 365 Incident Response Plan
A good Microsoft 365 incident plan does not need to be huge. It needs to help a small team make clean decisions in the first hour, while evidence is fresh.
Guest Access Reviews in Teams
Guest access is usually not risky because it exists. It becomes risky when nobody can explain who still needs it, what they can see, and when it should end.
Break-Glass Accounts in Microsoft 365
How to design Microsoft 365 emergency access accounts that actually help in a lockout without turning into permanent unmanaged admin shortcuts.
Mail Forwarding and Inbox Rules: The Audit Nobody Should Skip
Password resets are not cleanup. If you have not checked forwarding, inbox rules and transport rules, you may be leaving the quiet part of an email compromise behind.
Device Compliance and Conditional Access
How to make device compliance matter at the access layer, instead of leaving it as a nice-looking dashboard.
MFA in Microsoft 365: Security Defaults, Conditional Access or Per-User MFA?
A practical comparison of Security Defaults, Conditional Access, and per-user MFA, including when each option still makes sense and when it does not.
Global Admin Cleanup in Microsoft 365
How to clean up Global Administrator sprawl in Microsoft 365 without turning the exercise into guesswork or politics.
Enforcement Rollout Strategy
A practical plan for moving Microsoft Entra Conditional Access policies from report-only to enforced, without pretending the hard parts are somebody else's problem.
Microsoft 365 Security Review for UK SMEs: The First 10 Checks
A decent first Microsoft 365 security review does not need to be dramatic. It needs to show which controls are weak, who owns them, what evidence exists and which fixes reduce tenant risk first.
Entra ID & Conditional Access
If the notes describe your current identity state, move to a scoped identity review. The practical trigger is a Conditional Access policy that nobody confidently owns or access exceptions that have never been formally reviewed.
From reading to a useful brief
Move from reading to action when access rules are trusted by memory rather than evidence. Identity controls need a clean map before enforcement gets tighter.
- 01
Name the control
Identity & access
- 02
Collect the evidence
Bring a named admin role list, the current Conditional Access policies, any recent audit log concerns and the last time access exceptions were reviewed. Guest users and OAuth app consents are worth listing separately.
- 03
Choose the next move
A typical review maps admin roles, MFA methods, Conditional Access policies, exclusions, guest users and break-glass accounts so the team can see which access paths are intentional and which are inherited drift.
Questions teams ask first
Are Conditional Access policies documented, tested and owned by someone current?
A typical review maps admin roles, MFA methods, Conditional Access policies, exclusions, guest users and break-glass accounts so the team can see which access paths are intentional and which are inherited drift.
Do privileged roles, guests, OAuth apps and break-glass accounts have a review habit?
A typical review maps admin roles, MFA methods, Conditional Access policies, exclusions, guest users and break-glass accounts so the team can see which access paths are intentional and which are inherited drift.
Can the team explain why each MFA exception still exists?
A typical review maps admin roles, MFA methods, Conditional Access policies, exclusions, guest users and break-glass accounts so the team can see which access paths are intentional and which are inherited drift.
Keep exploring
Ready to turn this into a scoped review?
Send the affected users, devices, policy names, evidence source and decision owner.