Administrative roles
Assignments, eligibility and intent behind privileged access.
Include in the scope discussionIndependent IT security review
Start with the question your organization needs resolved. Evidence requests are then tailored to your tenant, licences and agreed boundary.
Scope reference
Assignments, eligibility and intent behind privileged access.
Include in the scope discussionMFA coverage and available authentication methods by role.
Include in the scope discussionWhether recovery arrangements match how the organization actually runs.
Include in the scope discussionUsers, roles, apps, conditions and intentionally excluded paths.
Include in the scope discussionLicences, devices, service accounts and legacy workflows.
Include in the scope discussionReport-only evaluation, pilot groups and recovery planning.
Include in the scope discussionProtection and authentication settings within scope.
Include in the scope discussionSharePoint, OneDrive and Teams collaboration boundaries.
Include in the scope discussionApproval paths and administrative consent posture.
Include in the scope discussionNext step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.