Azure Hardening Checklist
Identity (Entra ID / Azure AD) 10 controls
Require multi-factor authentication for every user.
How to verify / fix
In the Microsoft Entra admin center → Protection → Conditional Access, confirm a policy requires MFA for all users (or enable Security Defaults under Identity → Overview → Properties for small tenants). Check the Authentication methods registration report to find users without MFA registered.
Enforce MFA on every Global Administrator account.
How to verify / fix
Under Entra → Roles and administrators → Global Administrator, list members, then confirm a Conditional Access policy targeting admin roles requires MFA. Never leave a Global Admin reachable with password alone — these accounts own the tenant.
Block legacy authentication protocols.
How to verify / fix
Create a Conditional Access policy under Protection → Conditional Access with Client apps = Exchange ActiveSync clients + Other clients and grant Block. Legacy protocols (POP, IMAP, SMTP AUTH, older Office) bypass MFA and are the top vector for password spray. Review the Sign-in logs filtered to legacy clients first to avoid breaking workloads.
Assign privileged roles just-in-time through PIM, not permanently.
How to verify / fix
In Entra → Identity Governance → Privileged Identity Management → Microsoft Entra roles, make privileged role holders Eligible rather than Active so they must activate (and re-MFA) for a time-boxed window. Requires Entra ID P2.
Keep only 2–4 permanent Global Administrator assignments.
How to verify / fix
In PIM → Microsoft Entra roles → Global Administrator, review Active assignments. Convert extra admins to Eligible and keep just two to four permanent (including break-glass). Too many standing admins widens the breach blast radius.
Make admin accounts cloud-only, not synced from on-prem AD.
How to verify / fix
In Entra → Users, filter by On-premises sync enabled = No for accounts holding privileged roles. Adjust Microsoft Entra Connect sync scope to exclude admin OUs so a compromise of on-prem AD can't pivot to cloud admin rights.
Maintain documented break-glass accounts excluded from CA policies.
How to verify / fix
Create two cloud-only emergency Global Admin accounts, exclude them from all Conditional Access policies, store credentials offline, and monitor their sign-ins. Set a high-priority alert in Entra → Monitoring → Sign-in logs (or Sentinel) so any use is investigated immediately.
Require justification and approval for PIM role activation.
How to verify / fix
In PIM → Microsoft Entra roles → (role) → Role settings, enable Require justification on activation and Require approval to activate, naming approvers. This creates an audit trail and a second pair of eyes for every privilege escalation.
Run quarterly access reviews on privileged roles.
How to verify / fix
In Entra → Identity Governance → Access reviews, create a recurring (quarterly) review scoped to privileged role assignments, with reviewers required to attest each member is still needed. Auto-remove on denial.
Run access reviews on guest (external) accounts.
How to verify / fix
Create an Access review targeting Guest users in your directory and groups. Have sponsors confirm continued need; stale B2B guests accumulate access nobody owns. Pair with External collaboration settings review.
78 more controls — unlock the full checklist
The full Azure Hardening Checklist has 88 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.
Not ready to buy? Try the free Cyber Insurance Readiness Score.