Microsoft Entra ID security assessment

MagenX examines an Entra ID and Azure tenant alongside the on-premises estate.

What the assessment examines

Registration for multi-factor authentication is not the same as enforcement, so the two are reported separately.

  • Whether multi-factor authentication is enforced at sign-in, not merely registered
  • Conditional access gaps, and the exclusions carved out of each policy
  • Privileged roles held permanently rather than activated when needed
  • The accounts that bridge on-premises Active Directory and the cloud tenant
  • Azure resources reachable from the internet

Scored with the rest of the estate

Entra ID is one of four layers MagenX reads. Directory, cloud, network topology and firewall policy are scored together into one graph, so a hybrid account that is weak in the cloud and privileged on premises is seen as one problem rather than two.

What you get

Attack simulation walks that graph from a chosen foothold and names the single change that closes the most routes. Crown jewels works backwards from an asset you name. Scheduled scans build an append-only change history. MagenX runs from one installer on hardware you control, including air-gapped networks.

FAQ

What is the difference between registered and enforced multi-factor authentication?

Registration means an account has a second factor available. Enforcement means sign-in actually requires it. The two are reported separately, because a tenant can show high registration and still admit password-only sign-ins.

Is Azure included, or only the directory?

Azure is included. Resources reachable from the internet are read alongside the directory, and both feed the same graph and the same score.

Every finding above is evidence you can hand to the person who owns the object.

Get a demo