m365expertise MICROSOFT SECURITY EXPERTISE
Home · Blog · Security
Security

Top 10 Entra ID misconfigurations to fix first

m365expertise·24 March 2026·9 min

From one audit to the next, the same Entra ID weaknesses come back. None of them is exotic — they are ordinary gaps that attackers actively exploit. Here are the ten to fix first, roughly in order of impact.

1. Legacy authentication left open

Legacy protocols (POP, IMAP, SMTP AUTH, old Office clients) bypass modern controls, MFA included. Leaving them enabled is one of the most exploited gaps on Entra ID. Block legacy authentication with a Conditional Access policy — after checking the sign-in logs for what still uses it.

2. Privileged accounts without MFA

Global Administrators and other privileged roles without enforced MFA are the highest-value target in your tenant. Every admin account must require phishing-resistant MFA, no exceptions.

3. Too many Global Administrators

The more Global Administrators you have, the wider your attack surface. Keep the count minimal, use least-privilege roles for day-to-day work, and reserve Global Administrator for the few people who genuinely need it.

4. No Privileged Identity Management (PIM)

Standing privileged access is a liability. PIM makes privileged roles activatable on demand and time-bound, with approval and traceability. Without it, admin rights are permanent — and permanent rights eventually get abused.

5. Wide-open guest access

Default settings often let external users enumerate far more than necessary, and guests frequently escape MFA. Restrict guest permissions and require MFA for external identities.

6. Weak or missing Conditional Access

Conditional Access is the policy engine of Entra ID. The holes — no baseline MFA policy, no device or location condition, unprotected admin portals — leave the door ajar. Build a coherent policy set and review it regularly.

7. Insufficient log retention

If sign-in and audit logs are not kept long enough (or exported to a SIEM), you cannot investigate after the fact. Make sure retention covers your investigation and compliance needs — commonly 180 days or more.

8. Over-permissive self-service settings

Users who can register applications, consent to third-party apps, or invite externals with no oversight create a constant stream of risk. Tighten self-service and consent settings, and require admin consent for anything sensitive.

9. Dormant accounts and unused credentials

Accounts disabled but never deleted, unused service principals, leftover credentials: the attack surface expands silently. Review and clean them up on a regular cadence.

10. No break-glass account strategy

Emergency access accounts must exist, be excluded from the Conditional Access policies that could lock you out, use strong unique credentials, and be monitored. Getting this wrong means choosing between total lockout and an unmonitored super-account.

How to spot them fast. An automated audit surfaces these ten gaps (and 313 others) in minutes, ranked by criticality, each with its framework reference and its remediation — so you know exactly where to start.

Applies to Entra ID & M365
All articles
23 articles on Microsoft security auditing.
Back to the blog →