Microsoft 365 Identity Security
Audit the identity layer of your Microsoft 365 (Microsoft Entra ID) tenant — MFA gaps, Global Admin exposure, dormant admins, stale guests and risky password settings. Six checks, read-only, in minutes.
Read-only. It cannot reset passwords, register MFA or change roles.
Microsoft 365 identity security is about who can sign in and what they can do. A M365 Health Score identity audit reads your Microsoft Entra ID (Azure AD) directory, roles and authentication methods and flags the gaps that attackers exploit — starting with privileged accounts that have no MFA.
What the identity audit flags
| Check | Why it matters | Urgency |
|---|---|---|
| Global Admins with no MFA | A privileged account without MFA is the highest-value target in the tenant — flagged separately from ordinary users. | High |
| Any user with no MFA | Every account without a second factor is a phishable entry point. | High |
| Global Administrator sprawl | Too many Global Admins widens the blast radius of any single compromise. | Medium |
| Dormant admin accounts | Privileged accounts nobody uses are privileged accounts nobody watches. | Medium |
| Stale guest accounts | External guests that outlived their purpose are standing access you’ve forgotten about. | Medium |
| Never-expiring password + no MFA | A password that never changes and has no second factor is a permanent exposure. | High |
Why start with identity
Identity is the perimeter of Microsoft 365. Most tenant compromises begin not with a clever exploit but with a sign-in — a phished password on an account with no MFA, or a forgotten admin credential. These six checks are deliberately blunt about the highest-leverage fixes: turn on MFA everywhere (especially for admins), keep the number of Global Administrators small, and clean up accounts that no longer need access.
Dormant and disabled accounts show up in two places: as a security exposure here, and as wasted licenses in the license audit. Cleaning them up closes both at once.
Microsoft 365 identity security FAQ
What is a Microsoft 365 identity audit?
A Microsoft 365 identity audit reviews who can sign in and what they can do — checking MFA coverage, how many Global Administrators exist, whether admin accounts are dormant, whether guest accounts are stale, and whether any account combines a never-expiring password with no MFA.
How many Global Administrators should we have?
Microsoft recommends keeping Global Administrators to a minimum — commonly fewer than five, with emergency-access accounts and everyone else on least-privilege roles. The identity audit flags Global Administrator role sprawl so you can pare it back.
Does it check MFA for administrators specifically?
Yes. A Global Administrator with no registered MFA is flagged as its own, higher-urgency finding — separate from ordinary users missing MFA — because a privileged account without MFA is the single highest-value target in a tenant.
Is the identity audit read-only?
Yes. It reads directory, role and authentication-method data through Microsoft Graph. It cannot reset passwords, register MFA, remove roles or change any account.
Find your identity gaps in minutes
See which accounts are missing MFA and where admin access has sprawled — read-only, free to run.