GDCIdentity & Access

Identity & Access – Microsoft Entra ID

MFA coverage
98%
of active users
Conditional Access
7
policies active
PIM-managed roles
12
eligible · 0 standing
Inactive guests
9
> 90 days, cleanup due
Legacy auth
2
service accounts, open
Entra ID · the strongest area at 88 / 100

MFA, Conditional Access and Privileged Identity Management govern who can invoke Copilot and with what rights. Two items remain – neither blocks a scoped pilot.

ControlDetailOwnerStatusAction
MFA & Conditional Access baselineAll users covered; legacy locations blocked, compliant device required for admin roles.ZertainConfiguredDone
Privileged Identity ManagementAdmin roles are eligible-only with approval and justification – no standing access.ZertainConfiguredDone
Access reviewsQuarterly reviews configured for privileged roles and guest access.ZertainConfiguredDone
Legacy authentication blockTwo service accounts still use legacy auth (bypasses CA). Owning application not yet identified.GDC ITOpen
Inactive guest cleanupNine guests inactive beyond 90 days retain Copilot-relevant Graph access. Removal batch approved.Security & ComplianceScheduled