Independent Microsoft 365 security assessment.Atlant Security
365/AuditBY ATLANT SECURITY
Build your scope Audit brief builder

IDENTITY

Conditional Access: audit the exclusions, not just the policy names

Review policy coverage, privileged identities, emergency access and licence dependencies in Entra ID.

Discuss your requirements
Layered glass partitions in an illustrative corporate atrium

For the engagement owner. The effective boundary is defined by assignments and exceptions as well as policy settings.

Read the effective design

A tenant can have policies named “All users MFA” and still have a materially narrower effective scope. Export the policy settings and the objects referenced by included and excluded groups. Record enabled, report-only and disabled states separately. Review the authentication requirements and applicable resources, conditions and devices. The aim is to establish what the selected user population encounters under the relevant conditions, without disrupting live sign-ins.

Inspect the boundary. Policy: Resources, controls and state.; Assignment: Users, roles and groups.; Exception: Membership and approved purpose.
Working model 01Inspect the boundaryIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Policy
Resources, controls and state.
Assignment
Users, roles and groups.
Exception
Membership and approved purpose.

Reconcile exception membership

An excluded group often outlives the migration or application issue that created it. Compare current membership with approved exceptions. For each exception, look for an accountable owner, a business dependency, an expiry or review date and compensating controls. Nested or dynamic relationships may need additional explanation. Do not assume an empty-looking list in one screen captures every route by which an identity receives an exclusion.

Architectural boundaries illustrated by smoked glass and stone
Operational perspectiveMake access boundaries explicit.Generated illustrative setting; not a client location.

Treat emergency access as a separate design

Emergency accounts exist to support recovery when normal administrative access is unavailable. They need resilient authentication, carefully designed policy treatment, monitoring and periodic validation. They should not become ordinary day-to-day administrator accounts. Follow current Microsoft guidance and validate your recovery dependency chain; copying an old “exclude from everything” recipe can create a dangerous gap. Review the design with the owner before making changes that could lock out the tenant.

Evaluate each exception. Owner: Who accepts the dependency?; Expiry: When is access reconsidered?; Alternative: What reduces the remaining exposure?
Working model 02Evaluate each exceptionIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Owner
Who accepts the dependency?
Expiry
When is access reconsidered?
Alternative
What reduces the remaining exposure?

Distinguish administrator and workload access

Human administrators, automation accounts and service principals are different populations. Do not assume a user MFA policy governs application-only access. Identify privileged roles, their assignment method and the relationships between administrators and applications. Assess standing access, approval and review practices against agreed criteria. Findings should describe exactly which identity class and assignment were examined.

Separate identity classes. Workforce: Interactive user sign-in.; Administrators: Privileged access and recovery.; Applications: Non-human permissions and credentials.
Working model 03Separate identity classesIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Workforce
Interactive user sign-in.
Administrators
Privileged access and recovery.
Applications
Non-human permissions and credentials.

Recommend controls that the tenant can operate

Conditional Access depends on applicable Entra licensing; Microsoft documents P1 requirements and Business Premium support, with additional requirements for risk-based capabilities. Verify the actual assigned entitlement rather than inferring features from a broad E3 or E5 label. When a proposed feature is unavailable, separate an immediate feasible improvement from a licensed enhancement. Procurement, operational ownership and recovery testing belong in the remediation plan.

Plan the operational handover

During an MSP handover, explicitly transfer ownership of exception registers and recovery procedures. Confirm that departing administrators lose access only after the receiving team has validated its own approved administrative and emergency paths.

Related Atlant Security guidance: preparing identity evidence and preserving responsibilities during provider changes. Use these to connect the review with the evidence and responsibilities needed after it.

Prepare the review

Our Conditional Access review and Entra ID audit describe the evidence to discuss. Begin with approximate counts, identity source and known exceptions through the homepage planner. Policy exports, group membership and recovery account details should be shared only through the agreed confidential channel, after the access and handling arrangements are approved.

Change safely. Prepare: Confirm entitlement and recovery.; Pilot: Assess expected sign-in effects.; Validate: Review effective scope after rollout.
Working model 04Change safelyIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Prepare
Confirm entitlement and recovery.
Pilot
Assess expected sign-in effects.
Validate
Review effective scope after rollout.

Sources & further reading

Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client assessments.

Published by Atlant Security. Sources, editorial policy and corrections.

PUT THE GUIDANCE TO WORK

Choose your next step.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your audit objectives, control boundaries and evidence period. A useful starting point for your assessment.

Discuss your requirements