Microsoft Entra ID security assessment
MagenX examines an Entra ID and Azure tenant alongside the on-premises estate.
What the assessment examines
Registration for multi-factor authentication is not the same as enforcement, so the two are reported separately.
- Whether multi-factor authentication is enforced at sign-in, not merely registered
- Conditional access gaps, and the exclusions carved out of each policy
- Privileged roles held permanently rather than activated when needed
- The accounts that bridge on-premises Active Directory and the cloud tenant
- Azure resources reachable from the internet
Scored with the rest of the estate
Entra ID is one of four layers MagenX reads. Directory, cloud, network topology and firewall policy are scored together into one graph, so a hybrid account that is weak in the cloud and privileged on premises is seen as one problem rather than two.
What you get
Attack simulation walks that graph from a chosen foothold and names the single change that closes the most routes. Crown jewels works backwards from an asset you name. Scheduled scans build an append-only change history. MagenX runs from one installer on hardware you control, including air-gapped networks.
FAQ
What is the difference between registered and enforced multi-factor authentication?
Registration means an account has a second factor available. Enforcement means sign-in actually requires it. The two are reported separately, because a tenant can show high registration and still admit password-only sign-ins.
Is Azure included, or only the directory?
Azure is included. Resources reachable from the internet are read alongside the directory, and both feed the same graph and the same score.
Every finding above is evidence you can hand to the person who owns the object.
Get a demo