Konfirmity
Microsoft Entra ID logo

Secure your Microsoft Entra ID surface

Standing privileged roles, conditional access gaps, and legacy authentication left enabled. We don’t connect to Microsoft Entra ID to collect evidence for its own sake — we connect to secure it, and the compliance artefacts follow from that work.

Book a Demo

[01] What This Surface Exposes

Where Microsoft Entra ID goes wrong

Entra ID goes wrong through standing privilege: permanent Global Administrator assignments outnumber the people who genuinely need them.

  • Global Administrator and other privileged roles assigned permanently rather than through just-in-time elevation
  • Conditional access policies in report-only mode, or with exclusion groups that have grown over time
  • Legacy authentication protocols still enabled, bypassing conditional access entirely
  • Application consent grants allowing users to authorise third-party apps against corporate data
  • Guest accounts retained indefinitely with access to internal resources

[02] What We Secure

What we watch, catch and fix on Microsoft Entra ID

On Entra ID we audit conditional access exclusion groups, which is where exceptions accumulate until the policy protects almost nobody.

  • Standing privilege identified and moved toward PIM-based elevation with approval and time limits
  • Conditional access exclusion groups audited, because that is where exceptions accumulate unnoticed
  • Legacy authentication usage measured before disabling, so the change lands without breaking business
  • OAuth consent grants inventoried against what each application actually needs
  • Guest lifecycle reconciled so external access expires rather than persisting

[03] Where It Lands

Where Microsoft Entra ID lands in your registers

Directory data drives your access reviews directly: reviewers see live entitlements rather than a spreadsheet exported three weeks ago, and leaver revocation is verified against the systems themselves. The asset register records each identity provider as a critical dependency, and the risk register carries the concentration risk that comes with it — because if this tier fails, everything behind it fails with it.

[04] How We Engage

On Microsoft Entra ID specifically

On Microsoft Entra ID, we remove expired guests, revoke risky consent grants, and tighten exclusion groups. PIM rollout, legacy authentication shutdown, and conditional access redesign we run as a staged project with measurement first.

Platform licence

Everything you need to find and fix it yourself, with no ceiling on the depth of the answer.

  • Every connected tool monitored for misconfiguration and drift, with findings mapped to the assets and risks they affect
  • Remediation guidance that tells you what is wrong and exactly how to fix it — however deep or awkward the issue is. We are engineers running a security company, so the answer is the real one, not a link to vendor documentation
  • Assets, access reviews, and risk register populated from the tools themselves rather than from spreadsheets
  • Unlimited integrations and unlimited users, with anything missing built within two weeks

Managed service

Every tool you connect through Konfirmity comes under our care, with our team doing the work.

  • Continuous misconfiguration and drift monitoring across every connected tool, watched by our analysts rather than by a dashboard waiting for you
  • Incident response led by us, with containment coordinated with your team
  • Remediation performed directly wherever you have granted us the authority to act — and where we cannot act, we project-manage the fix to completion rather than handing you a ticket
  • Decision support on the tools themselves: where something is failing you on capability or costing more than it returns, we will tell you, and help you replace it

[05] Microsoft Entra ID FAQs

What Entra ID permissions does Konfirmity need?

Konfirmity needs an app registration with Directory.Read.All, Policy.Read.All, AuditLog.Read.All and RoleManagement.Read.Directory. That covers directory, conditional access, privileged roles and sign-in analysis. We request Global Reader rather than any write role for assessment.

Can you help us turn off legacy authentication safely?

Yes, and measurement comes first. Disabling legacy authentication without knowing what still uses it breaks business processes and gets reverted. Konfirmity reports actual legacy authentication usage by application and user so the change lands once rather than being rolled back.

[06] Related Integrations

Other identity & access tools we secure:

View all integrations