Microsoft Cloud4 min read218 lines

Learning state

Track this guide

Saved in this browser only. No account required.

Microsoft Cloud Identity & Security Master Class

Practical operator guide for Microsoft Entra ID, Microsoft 365 administration, Conditional Access, Microsoft Graph PowerShell, and safe identity-security rollout patterns.

Table of Contents


Operator Safety Model

Microsoft cloud identity changes can lock out real users quickly. Treat Entra ID, Microsoft 365, and Conditional Access as production infrastructure.

Safe default: start with read-only inventory, export current policy state, test in report-only mode, and keep at least two monitored break-glass accounts excluded from Conditional Access policies.

Connect-MgGraph -Scopes "Directory.Read.All","Policy.Read.All","AuditLog.Read.All"
Get-MgUser -Top 10 -Property Id,DisplayName,UserPrincipalName,AccountEnabled
Get-MgIdentityConditionalAccessPolicy -All

Notes

  • Use least-privilege delegated scopes for discovery.
  • Prefer report-only Conditional Access before enforcement.
  • Export existing policies before creating or modifying controls.
  • Do not rely on one global administrator account.

Microsoft Entra ID Baseline

Microsoft Entra ID is the identity control plane for Azure, Microsoft 365, SaaS applications, and device/user access policy.

Baseline questions

  • Who has privileged directory roles?
  • Which users are cloud-only, synchronized, guest, or service accounts?
  • Which groups drive application access and Conditional Access targeting?
  • Which applications have tenant-wide consent or high-risk permissions?
Connect-MgGraph -Scopes "User.Read.All","Group.Read.All","RoleManagement.Read.Directory"
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,UserType,AccountEnabled
Get-MgGroup -All -Property Id,DisplayName,SecurityEnabled,MailEnabled,GroupTypes
Get-MgDirectoryRole -All

Common mistakes

  • Confusing Azure RBAC roles with Entra directory roles.
  • Leaving stale guest accounts active.
  • Assigning users directly instead of through governed groups.
  • Using permanent privileged roles when Privileged Identity Management should be used.

Users, Groups, and Roles

Identity operations should be repeatable and reviewable. Use groups for access, roles for administration, and documented exceptions for service accounts.

Connect-MgGraph -Scopes "User.Read.All","Group.Read.All","RoleManagement.Read.Directory"
Get-MgUser -Filter "accountEnabled eq true" -Property Id,DisplayName,UserPrincipalName
Get-MgGroup -Filter "securityEnabled eq true" -Property Id,DisplayName
Get-MgDirectoryRole -All

Review cadence

  • Weekly: disabled users, risky users, and privileged assignments.
  • Monthly: guest users, app owners, and admin role membership.
  • Quarterly: Conditional Access exclusions, emergency access accounts, and application permissions.

App Registrations and Enterprise Apps

App registrations define application identity. Enterprise applications represent service principals in the tenant. Both can create risk through broad permissions, stale secrets, and unmanaged owners.

Connect-MgGraph -Scopes "Application.Read.All","Directory.Read.All"
Get-MgApplication -All -Property Id,AppId,DisplayName,SignInAudience
Get-MgServicePrincipal -All -Property Id,AppId,DisplayName,AccountEnabled

What to inspect

  • Applications with no owner.
  • Client secrets close to expiration.
  • Tenant-wide admin consent grants.
  • Multi-tenant apps with broad Graph permissions.
  • Service principals that are enabled but unused.

Conditional Access

Conditional Access is the policy engine for controlling sign-in risk, MFA, device requirements, app access, and location-based controls.

Connect-MgGraph -Scopes "Policy.Read.All"
Get-MgIdentityConditionalAccessPolicy -All
Get-MgIdentityConditionalAccessPolicy -ConditionalAccessPolicyId "00000000-0000-0000-0000-000000000000"

Recommended rollout path

  1. Inventory existing policies and exclusions.
  2. Confirm break-glass accounts exist and are excluded intentionally.
  3. Create policies in report-only mode.
  4. Review sign-in logs and report-only impact.
  5. Pilot with a small user group.
  6. Expand by department or role.
  7. Enforce only after rollback steps are documented.

High-value starter policies

  • Require MFA for administrators.
  • Require MFA for all users, with staged rollout.
  • Block legacy authentication.
  • Require compliant or hybrid joined devices for sensitive apps.
  • Require stronger controls for risky sign-ins.

Break-Glass Accounts

Break-glass accounts are emergency cloud-only administrator accounts used when normal identity controls fail. They should be rare, monitored, and protected from routine use.

Connect-MgGraph -Scopes "User.Read.All","Policy.Read.All"
Get-MgUser -Filter "startsWith(displayName,'Break Glass')" -Property Id,DisplayName,UserPrincipalName,AccountEnabled
Get-MgIdentityConditionalAccessPolicy -All

Requirements

  • At least two cloud-only emergency accounts.
  • Excluded from Conditional Access policies that could block tenant recovery.
  • Long, vaulted passwords and no daily operational use.
  • Alerting on every sign-in attempt.
  • Tested recovery procedure with executive approval.

Microsoft 365 Operations

Microsoft 365 operations include licensing, mailbox administration, Teams/SharePoint governance, audit logs, and compliance workflows. Start with read-only discovery before changing tenant settings.

Connect-ExchangeOnline
Get-EXOMailbox -ResultSize 10 -PropertySets Minimum
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100

Operational areas

  • Exchange Online mailbox inventory and forwarding review.
  • Teams and SharePoint external sharing posture.
  • OneDrive retention and governance.
  • License assignment consistency.
  • Audit log availability and retention.

Audit and Compliance

Audit evidence should answer who changed what, who accessed what, and which policies were active at the time.

Connect-MgGraph -Scopes "AuditLog.Read.All","Directory.Read.All"
Get-MgAuditLogDirectoryAudit -Top 20
Get-MgAuditLogSignIn -Top 20
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations UserLoggedIn

Evidence to preserve

  • Conditional Access policy export.
  • Admin role membership export.
  • Guest user inventory.
  • Application permissions inventory.
  • Unified audit log searches for sensitive operations.

Rollout Checklist

Use this checklist before enforcing new identity policy.

  • Current Conditional Access policies exported.
  • Break-glass accounts validated and monitored.
  • Pilot group created.
  • Report-only results reviewed.
  • Help desk and rollback notes prepared.
  • Enforcement window approved.
  • Post-change sign-in logs reviewed.
Connect-MgGraph -Scopes "Policy.Read.All","AuditLog.Read.All"
Get-MgIdentityConditionalAccessPolicy -All
Get-MgAuditLogSignIn -Top 50

Rollback pattern

Disable or revert the newest Conditional Access policy first, confirm sign-in recovery, then review logs before attempting a second change.