Intermediate60 min · 13 evidence commands
Microsoft Tenant Readiness Assessment
Client-ready read-only assessment for Entra ID, Conditional Access, Microsoft 365 operations, mailbox exposure, and audit evidence readiness.
Audience: Microsoft cloud operators, tenant administrators, and 143IT readiness reviews
Evidence workflow
Tenant and identity baseline
Confirm the reviewed tenant, reader context, privileged roles, and identity inventory before making any recommendations.
Get-MgContextGet-MgUser -All -Property Id,DisplayName,UserPrincipalName,AccountEnabledGet-MgGroup -All | Select-Object Id,DisplayName,SecurityEnabled,MailEnabled
Expected evidenceGet-MgDirectoryRole -All | Select-Object Id,DisplayName- Tenant ID and account context
- Enabled/disabled user sample
- Security group inventory
- Privileged directory role list
Conditional Access posture
Inventory policies, states, coverage, and break-glass readiness without changing policy enforcement.
Get-MgIdentityConditionalAccessPolicy -All | Select-Object Id,DisplayName,State,CreatedDateTime,ModifiedDateTimeGet-MgUser -Filter "startsWith(displayName,'Break Glass')" -Property Id,DisplayName,UserPrincipalName,AccountEnabled
Expected evidenceGet-MgAuditLogSignIn -Top 20 | Select-Object CreatedDateTime,UserPrincipalName,AppDisplayName,ConditionalAccessStatus- Policy inventory with state
- Break-glass candidate list
- Recent sign-in Conditional Access status sample
Microsoft 365 operations posture
Review mailbox inventory, forwarding, direct mailbox permissions, and unified audit log availability.
Connect-ExchangeOnlineGet-EXOMailbox -ResultSize 25 -PropertySets Minimum | Select-Object DisplayName,UserPrincipalName,RecipientTypeDetailsGet-EXOMailbox -ResultSize 25 -Properties ForwardingSmtpAddress,DeliverToMailboxAndForward | Select-Object DisplayName,ForwardingSmtpAddress,DeliverToMailboxAndForwardGet-EXOMailboxPermission -Identity USER@DOMAIN.COM | Where-Object { -not $_.IsInherited }Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100
Expected evidenceDisconnect-ExchangeOnline -Confirm:$false- Mailbox sample
- Forwarding posture sample
- Mailbox permission evidence
- Unified audit search result sample
Deliverables
- Tenant scope and reviewer context summary
- Conditional Access policy inventory and risk notes
- Break-glass account readiness finding
- Mailbox forwarding and permission exposure findings
- Unified audit log evidence availability status
- Prioritized remediation backlog with read-only evidence references
Risk rules
- Run only read-only Graph, Exchange Online, and audit commands during assessment.
- Do not create, update, remove, delete, or enforce tenant policy from the assessment page.
- Confirm break-glass account exclusions before recommending Conditional Access enforcement.
- Redact user identifiers and tenant-specific evidence before sharing outside the client boundary.