Top 10 Entra ID misconfigurations to fix first
From one audit to the next, the same Entra ID weaknesses come back. None of them is exotic — they are ordinary gaps that attackers actively exploit. Here are the ten to fix first, roughly in order of impact.
1. Legacy authentication left open
Legacy protocols (POP, IMAP, SMTP AUTH, old Office clients) bypass modern controls, MFA included. Leaving them enabled is one of the most exploited gaps on Entra ID. Block legacy authentication with a Conditional Access policy — after checking the sign-in logs for what still uses it.
2. Privileged accounts without MFA
Global Administrators and other privileged roles without enforced MFA are the highest-value target in your tenant. Every admin account must require phishing-resistant MFA, no exceptions.
3. Too many Global Administrators
The more Global Administrators you have, the wider your attack surface. Keep the count minimal, use least-privilege roles for day-to-day work, and reserve Global Administrator for the few people who genuinely need it.
4. No Privileged Identity Management (PIM)
Standing privileged access is a liability. PIM makes privileged roles activatable on demand and time-bound, with approval and traceability. Without it, admin rights are permanent — and permanent rights eventually get abused.
5. Wide-open guest access
Default settings often let external users enumerate far more than necessary, and guests frequently escape MFA. Restrict guest permissions and require MFA for external identities.
6. Weak or missing Conditional Access
Conditional Access is the policy engine of Entra ID. The holes — no baseline MFA policy, no device or location condition, unprotected admin portals — leave the door ajar. Build a coherent policy set and review it regularly.
7. Insufficient log retention
If sign-in and audit logs are not kept long enough (or exported to a SIEM), you cannot investigate after the fact. Make sure retention covers your investigation and compliance needs — commonly 180 days or more.
8. Over-permissive self-service settings
Users who can register applications, consent to third-party apps, or invite externals with no oversight create a constant stream of risk. Tighten self-service and consent settings, and require admin consent for anything sensitive.
9. Dormant accounts and unused credentials
Accounts disabled but never deleted, unused service principals, leftover credentials: the attack surface expands silently. Review and clean them up on a regular cadence.
10. No break-glass account strategy
Emergency access accounts must exist, be excluded from the Conditional Access policies that could lock you out, use strong unique credentials, and be monitored. Getting this wrong means choosing between total lockout and an unmonitored super-account.
How to spot them fast. An automated audit surfaces these ten gaps (and 313 others) in minutes, ranked by criticality, each with its framework reference and its remediation — so you know exactly where to start.