← Master Class Commands

Readiness assessments

Client-ready evidence packs

Use these assessment flows to collect read-only evidence, map findings to guide content, and produce an implementation backlog without changing production systems.

Intermediate60 min · 13 evidence commands

Microsoft Tenant Readiness Assessment

Client-ready read-only assessment for Entra ID, Conditional Access, Microsoft 365 operations, mailbox exposure, and audit evidence readiness.

Audience: Microsoft cloud operators, tenant administrators, and 143IT readiness reviews

Evidence workflow

  1. Tenant and identity baseline

    Confirm the reviewed tenant, reader context, privileged roles, and identity inventory before making any recommendations.

    Get-MgContext
    Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AccountEnabled
    Get-MgGroup -All | Select-Object Id,DisplayName,SecurityEnabled,MailEnabled
    Get-MgDirectoryRole -All | Select-Object Id,DisplayName
    Expected evidence
    • Tenant ID and account context
    • Enabled/disabled user sample
    • Security group inventory
    • Privileged directory role list
  2. Conditional Access posture

    Inventory policies, states, coverage, and break-glass readiness without changing policy enforcement.

    Get-MgIdentityConditionalAccessPolicy -All | Select-Object Id,DisplayName,State,CreatedDateTime,ModifiedDateTime
    Get-MgUser -Filter "startsWith(displayName,'Break Glass')" -Property Id,DisplayName,UserPrincipalName,AccountEnabled
    Get-MgAuditLogSignIn -Top 20 | Select-Object CreatedDateTime,UserPrincipalName,AppDisplayName,ConditionalAccessStatus
    Expected evidence
    • Policy inventory with state
    • Break-glass candidate list
    • Recent sign-in Conditional Access status sample
  3. Microsoft 365 operations posture

    Review mailbox inventory, forwarding, direct mailbox permissions, and unified audit log availability.

    Connect-ExchangeOnline
    Get-EXOMailbox -ResultSize 25 -PropertySets Minimum | Select-Object DisplayName,UserPrincipalName,RecipientTypeDetails
    Get-EXOMailbox -ResultSize 25 -Properties ForwardingSmtpAddress,DeliverToMailboxAndForward | Select-Object DisplayName,ForwardingSmtpAddress,DeliverToMailboxAndForward
    Get-EXOMailboxPermission -Identity USER@DOMAIN.COM | Where-Object { -not $_.IsInherited }
    Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100
    Disconnect-ExchangeOnline -Confirm:$false
    Expected evidence
    • Mailbox sample
    • Forwarding posture sample
    • Mailbox permission evidence
    • Unified audit search result sample

Deliverables

  • Tenant scope and reviewer context summary
  • Conditional Access policy inventory and risk notes
  • Break-glass account readiness finding
  • Mailbox forwarding and permission exposure findings
  • Unified audit log evidence availability status
  • Prioritized remediation backlog with read-only evidence references

Risk rules

  • Run only read-only Graph, Exchange Online, and audit commands during assessment.
  • Do not create, update, remove, delete, or enforce tenant policy from the assessment page.
  • Confirm break-glass account exclusions before recommending Conditional Access enforcement.
  • Redact user identifiers and tenant-specific evidence before sharing outside the client boundary.

Source guides and labs