Walk through M365 and Entra ID controls, answer yes or no, and get a scored breakdown by category with findings and next steps. Built from the same checklist I use in identity security reviews.
Evaluates Microsoft 365 and Entra ID identity security posture across six control areas: MFA coverage, Conditional Access configuration, privileged access management, legacy authentication status, admin role hygiene, and monitoring coverage. Produces a scored posture report and prioritized action plan.
Each control area is weighted by real-world impact on identity-based attack paths. MFA and Conditional Access carry the most weight because they are the primary controls preventing phishing-based account takeover.
Identity is the most commonly exploited entry point in cloud and SaaS environments. Phishing, credential stuffing, password spray, and token theft all target authentication. The difference between a minor phishing incident and a full environment compromise often comes down to whether MFA and Conditional Access are properly configured.
This tool maps directly to the controls that stop the most common attack paths in Microsoft environments — the same checks that appear in every M365 security assessment and CIS Benchmark review.