Who can obtain or retain access, and who can grant it to someone else?
Understand identity lifecycle, privileged roles and the paths that connect your people, applications and tenant.
Begin with the business decision and the affected population. A targeted workload review may be sufficient; an interconnected tenant assessment may be more useful where the same identity, device or data dependency affects several services.
Evidence we agree to examine
- Role assignments and eligible/active privilege, with current owners and approval records
- Authentication-method policy, registration coverage and representative sign-in records
- Joiner, mover and leaver samples; guest and service-account ownership
- Cloud-only, synchronised and federated identity dependencies
Why context changes the conclusion
A disabled employee account does not establish that every guest identity, application credential or delegated access route owned by that employee has also been addressed.
Treat this as an assessment question, not a finding about your organisation. During an engagement, a conclusion must identify the dated evidence, the sampled population and any exceptions that could not be corroborated.
The output your team can use
A privilege and lifecycle exception register, with dependencies, owners and evidence needed for closure.
Each action should identify its accountable owner, licence or business dependency, proposed rollout safeguards and the record that will demonstrate successful closure. A policy screenshot alone is not enough when the finding concerns coverage or sustained operation.
Access and boundaries
On-premises Active Directory exploitation, password attacks and tenant takeover simulations are separate engagements.
We agree evidence access before work begins. Your team can lead supervised sessions and provide approved, minimised exports. The assessment does not require you to send passwords, grant access through this website or permit production changes. See access and data handling.
Include device code phishing exposure
Review where device code flow remains allowed, which dependencies justify an exception and whether sign-in evidence supports investigation. Our device code phishing guide explains the threat, Conditional Access considerations and a focused audit scope.
Prepare your audit request
Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.
Sources & further reading
- Microsoft emergency access guidance ↗
- Microsoft Entra security defaults ↗
- Microsoft consent phishing guidance ↗
Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

