Entra ID & M365
Identity is the new perimeter
In a cloud and hybrid IT estate, the firewall no longer protects much: the authentication token is what opens the doors. Entra ID is the control plane through which every access to Microsoft 365, Azure and your SaaS applications flows — it is the Tier 0 of your cloud. Most modern compromises start with an identity: phishing, password spraying, token theft, consent granted to a malicious application.
A tenant moves fast: roles assigned "temporarily", applications registered then forgotten, B2B guests piling up, Conditional Access exclusions never reviewed. This silent drift is exactly what an attacker looks for — and what we measure.
Classic attack paths
AiTM phishing
Phishing proxies that capture the session after MFA: only phishing-resistant MFA (FIDO2) holds.
Password spray & legacy auth
Slow attempts on legacy protocols (IMAP, SMTP) that bypass MFA and Conditional Access.
Consent phishing
A malicious application granted durable Graph permissions by the user — no stolen password needed.
Token theft and replay
Tokens exfiltrated from a compromised workstation and replayed elsewhere while still valid.
Privileged role abuse
Standing Global Administrators, nested roles, Conditional Access exclusions: so many escape hatches for the attacker.
Applications & secrets
Long-lived application secrets, service principals holding high-privilege permissions with no owner.
Our approach to Entra ID security
Three phases, as for the on-premises directory: measure the tenant's actual posture with our EntraGUARD tool (323 checks aligned with ANSSI, CIS, SCuBA, NIS2, DORA and MCSB), lock down the control plane — Conditional Access, phishing-resistant MFA, PIM, application governance — then industrialize with automation (PowerShell, Graph API, Logic Apps) so the posture holds over time. Each service opposite covers one step of this trajectory.
Video demo
See EntraGUARD in action: connector setup, audit run and report review.