01 /Identity & authentication
Review Microsoft Entra, MFA enforcement, legacy authentication, and Conditional Access. Match access controls to your users, devices, and available licenses.
02 /Privileged administration
Identify excessive roles and standing access. Separate administrative work from daily accounts and review emergency access procedures.
03 /Account lifecycle
Examine onboarding, role changes, guest access, and offboarding so access stays aligned with business need.
04 /Email & collaboration
Review Microsoft Defender capabilities, mail protection, external sharing, and application consent to reduce common exposure.
05 /Secure access
Assess access from unmanaged devices and remote locations. Plan policy changes with testing and recovery paths to avoid unnecessary disruption.
06 /Monitoring & response
Review sign-in visibility, audit coverage, alert routing, and ownership. Make sure someone can act on the signals that matter.