Skip to main content

Azure Entra ID Assessment

Updated over 5 months ago

Service Overview

The Entra ID (formerly Azure AD) Assessment is a security evaluation of Active Directory objects such as users, devices, and groups, as well as the trust relationships and interactions between them. The objective is to identify misconfigurations in access rules defined by Entra ID administrators.


Methodology

CYE conducts the assessment by analyzing AD object configurations and trust relationships to uncover security weaknesses and policy deviations.

The assessment focuses on:

  • Verifying whether entities and their relationships follow security best practices, including defense-in-depth and least privilege principle

  • Reviewing trusts with external environments, such as on-premises Active Directory (if applicable)

  • Reviewing policies such as network group configurations and conditional access policies


Deliverables

  • All discovered findings are shown in Hyver, CYE’s Continuous Threat Exposure Management (CTEM) platform

  • Activity report


Prerequisites

CYE requires an Azure user account with the following permissions:

  • Global Reader directory role

  • Security Reader directory role

Depending on the environment complexity, additional Microsoft Graph API permissions may be needed.


Customer Engagement

A meeting with the organization’s infrastructure engineer may be required during the assessment to clarify the purpose of specific accounts or applications.


Relevant Standards

The proprietary methodology is derived from the following sources:

  • NIST Cybersecurity Framework

  • Center for Internet Security (CIS)


Security Domains Covered

  • Cross-organization policies, procedures, and governance

  • Security operations, monitoring, and incident response

  • Network level security

  • Servers, network equipment, and endpoints security

  • Identity management and remote access

Did this answer your question?