Governance & Identity These views combine Azure Resource Manager, Policy Insights, and Microsoft Graph evidence. They are analysis-first: Policy simulation does not deploy, Identity does not rotate credentials, and RBAC does not alter assignments.
Guide Use it to Azure Policy Inventory definitions/assignments/exemptions, analyze compliance and effective policy, plan rollout, and assess drift. Entra ID Start here for tenant identity posture: the nine tabs, the snapshot model, and what the score does and does not mean. IAM Review effective Azure/Entra access, privileged and data-plane exposure, scopes, roles, and diagnostics.
Entra ID deep dives Guide Use it to Setup and coverage Grant the read-only consent tiers and read the domain coverage table behind every blind spot. Posture and score Understand the weighted pillar score, coverage, history, and the refresh-to-refresh diff. Conditional Access Read the coverage matrix, conflicts, break-glass candidates, policy-as-code export, and the simulator. Privileged access Compare standing and eligible privilege, PIM configuration health, activations, and cross-plane power. Applications and consent Assess app risk, credential expiry, ownership, granted permissions, and tenant consent posture. Risk and sign-ins Interpret MFA registration, legacy authentication, failure clusters, and Identity Protection risk. Governance Review access reviews, entitlement expiry, lifecycle workflows, and governance coverage. Guests (B2B) Review the external population as a lifecycle, roll it up per partner organization, and see which partners no cross-tenant policy names. Blast radius Trace derived escalation paths from an entry point to tenant-level power. Findings and scanners Work the inbox, run proactive scanners, and apply finding workflow state. Investigate a principal Correlate one identity’s cached access and findings, inspect an explicit warning when an account is disabled, request audited activity, and export provenance.
IAM deep dives Guide Use it to Findings and scanners Work the access-findings inbox, read its two-level grouping and server tallies, and run the ten scanners without consuming their delta. Access paths Evaluate an action against a scope, trace the routes to full control, and inventory the doors that are not Azure RBAC. Change and simulation Read the classified access diff and its Activity Log attribution, and model a change before making it. Reviews and PIM Run certification campaigns with evidence and rollback-carrying scripts, and read standing privilege against JIT eligibility. Insights, scopes, roles and diagnostics Read the thirteen pivots, inspect per-scope freshness and the directory layer, and diagnose collectors that could not read.
Before drawing conclusions, check the selected connection, cache age, partial-collection errors, and Connection Capability .
Table of contents