Service Overview
The Entra ID (formerly Azure AD) Assessment is a security evaluation of Active Directory objects such as users, devices, and groups, as well as the trust relationships and interactions between them. The objective is to identify misconfigurations in access rules defined by Entra ID administrators.
Methodology
CYE conducts the assessment by analyzing AD object configurations and trust relationships to uncover security weaknesses and policy deviations.
The assessment focuses on:
Verifying whether entities and their relationships follow security best practices, including defense-in-depth and least privilege principle
Reviewing trusts with external environments, such as on-premises Active Directory (if applicable)
Reviewing policies such as network group configurations and conditional access policies
Deliverables
All discovered findings are shown in Hyver, CYE’s Continuous Threat Exposure Management (CTEM) platform
Activity report
Prerequisites
CYE requires an Azure user account with the following permissions:
Global Reader directory role
Security Reader directory role
Depending on the environment complexity, additional Microsoft Graph API permissions may be needed.
Customer Engagement
A meeting with the organization’s infrastructure engineer may be required during the assessment to clarify the purpose of specific accounts or applications.
Relevant Standards
The proprietary methodology is derived from the following sources:
NIST Cybersecurity Framework
Center for Internet Security (CIS)
Security Domains Covered
Cross-organization policies, procedures, and governance
Security operations, monitoring, and incident response
Network level security
Servers, network equipment, and endpoints security
Identity management and remote access
