identity
139 TopicsI built a free, open-source M365 security assessment tool - looking for feedback
I work as an IT consultant, and a good chunk of my time is spent assessing Microsoft 365 environments for small and mid-sized businesses. Every engagement started the same way: connect to five different PowerShell modules, run dozens of commands across Entra ID, Exchange Online, Defender, SharePoint, and Teams, manually compare each setting against CIS benchmarks, then spend hours assembling everything into a report the client could actually read. The tools that automate this either cost thousands per year, require standing up Azure infrastructure just to run, or only cover one service area. I wanted something simpler: one command that connects, assesses, and produces a client-ready deliverable. So I built it. What M365 Assess does https://github.com/Daren9m/M365-Assess is a PowerShell-based security assessment tool that runs against a Microsoft 365 tenant and produces a comprehensive set of reports. Here is what you get from a single run: 57 automated security checks aligned to the CIS Microsoft 365 Foundations Benchmark v6.0.1, covering Entra ID, Exchange Online, Defender for Office 365, SharePoint Online, and Teams 12 compliance frameworks mapped simultaneously -- every finding is cross-referenced against NIST 800-53, NIST CSF 2.0, ISO 27001:2022, SOC 2, HIPAA, PCI DSS v4.0.1, CMMC 2.0, CISA SCuBA, and DISA STIG (plus CIS profiles for E3 L1/L2 and E5 L1/L2) 20+ CSV exports covering users, mailboxes, MFA status, admin roles, conditional access policies, mail flow rules, device compliance, and more A self-contained HTML report with an executive summary, severity badges, sortable tables, and a compliance overview dashboard -- no external dependencies, fully base64-encoded, just open it in any browser or email it directly The entire assessment is read-only. It never modifies tenant settings. Only Get-* cmdlets are used. A few things I'm proud of Real-time progress in the console. As the assessment runs, you see each check complete with live status indicators and timing. No staring at a blank terminal wondering if it hung. The HTML report is a single file. Logos, backgrounds, fonts -- everything is embedded. You can email the report as an attachment and it renders perfectly. It supports dark mode (auto-detects system preference), and all tables are sortable by clicking column headers. Compliance framework mapping. This was the feature that took the most work. The compliance overview shows coverage percentages across all 12 frameworks, with drill-down to individual controls. Each finding links back to its CIS control ID and maps to every applicable framework control. Pass/Fail detail tables. Each security check shows the CIS control reference, what was checked, what the expected value is, what the actual value is, and a clear Pass/Fail/Warning status. Findings include remediation descriptions to help prioritize fixes. Quick start If you want to try it out, it takes about 5 minutes to get running: # Install prerequisites (if you don't have them already) Install-Module Microsoft.Graph, ExchangeOnlineManagement -Scope CurrentUser Clone and run git clone https://github.com/Daren9m/M365-Assess.git cd M365-Assess .\Invoke-M365Assessment.ps1 The interactive wizard walks you through selecting assessment sections, entering your tenant ID, and choosing an authentication method (interactive browser login, certificate-based, or pre-existing connections). Results land in a timestamped folder with all CSVs and the HTML report. Requires PowerShell 7.x and runs on Windows (macOS and Linux are experimental -- I would love help testing those platforms). Cloud support M365 Assess works with: Commercial (global) tenants GCC, GCC High, and DoD environments If you work in government cloud, the tool handles the different endpoint URIs automatically. What is next This is actively maintained and I have a roadmap of improvements: More automated checks -- 140 CIS v6.0.1 controls are tracked in the registry, with 57 automated today. Expanding coverage is the top priority. Remediation commands -- PowerShell snippets and portal steps for each finding, so you can fix issues directly from the report. XLSX compliance matrix -- A spreadsheet export for audit teams who need to work in Excel. Standalone report regeneration -- Re-run the report from existing CSV data without re-assessing the tenant. I would love your feedback I have been building this for my own consulting work, but I think it could be useful to the broader community. If you try it, I would genuinely appreciate hearing: What checks should I prioritize next? Which security controls matter most in your environment? What compliance frameworks are most requested by your clients or auditors? How does the report land with non-technical stakeholders? Is the executive summary useful, or does it need work? macOS/Linux users -- does it run? What breaks? I have tested it on macOS, but not extensively. Bug reports, feature requests, and contributions are all welcome on GitHub. Repository: https://github.com/Daren9m/M365-Assess License: MIT (free for commercial and personal use) Runtime: PowerShell 7.x Thanks for reading. Happy to answer any questions in the comments.5.2KViews2likes4CommentsProject Lifeline: Biometric Security Ecosystem for Lock-Screen Password Recovery
Title: Project Lifeline: Biometric Security Ecosystem for Lock-Screen Password Recovery Overview The Lifeline application is a proactive biological and digital security ecosystem specifically designed to protect smartphone users from data loss and the erasure of personal memories caused by forgetting the screen lock code (PIN/Password). How it Works • Secure Registration: While the phone is unlocked, the user registers their name, phone number, and email, and securely saves their screen lock code in an encrypted format within the isolated system vault (SecureStore). • Persistent Notification: This immediately generates a persistent, silent notification in the notification drawer that functions even when the screen is locked with a password and automatically restarts upon device boot. • Emergency Rescue: In the event of an emergency when the code is forgotten, the user simply pulls down the notification drawer from the lock screen and taps the rescue button. Identity Verification & Decryption The application invokes the phone’s biometric security system (face scan or fingerprint) or the "System Credential Fallback" (such as a backup code or a secret security question) to ensure maximum privacy protection and block intruders. Once identity verification succeeds, the app decrypts the code and displays it instantly on the screen inside the app, allowing the user to unlock their device in seconds, at zero material cost, and without the need for an enforced factory reset or losing any filesMicrosoft Authenticator backup not recognized by the same recovery account
My old Android phone has completely failed, so I can no longer access Microsoft Authenticator on that device. I had previously enabled Cloud Backup in Microsoft Authenticator, and I am certain that I am signing in with the same Microsoft personal account that was originally used as the recovery account. On my new Android phone, I reinstalled Microsoft Authenticator and selected “Restore from backup / Begin recovery” before adding any accounts. I then signed in with the same Microsoft personal account. However, Authenticator says that the backup is not stored under this account and asks me to try another personal Microsoft account. I am certain that this is the correct recovery account. Both the old phone and the new phone are Android devices, so this is not a cross-platform restore issue. I would like to know: Could this be a problem with the association between the cloud backup and the recovery account? Is there any way for the Microsoft Authenticator team to verify whether a backup still exists? Is there any supported way to recover the original backup instead of manually resetting and re-enrolling every third-party 2FA account? My old device is completely inaccessible, so I cannot open Authenticator there or create a new backup. Any guidance from the Microsoft Authenticator or Identity team would be appreciated.51Views0likes1CommentHelp me recover my account.
Hi, My other Microsoft account was recently compromised but it was compromised before as well. When it was compromised before, the hacker added a recovery email for verification and to remove that I added my another email and the request was sent and it was supposed to change in October and I was not able to change the password or use other features of Microsoft because at some point it keep redirecting me to the page that I have sent a request but during that time period, my account was compromised again and I keep receiving emails of unusual sign-in activity by the hacker and I wanted to change the password but I couldn't because of that request so I was being patient. Now I received an email that someone accessed my Microsoft account and now I have to verify my identity to log in and to log in it ask me to type the email that the hacker set up because it's not changed and since I don't know what that is it takes me to the account recovery page where I put all the information that I know, I write in my postal code, my old and current passwords, date of birth etc. I have never used skype, Hotmail or outlook and Xbox so I just uncheck those boxes and then it asks me if I have ever bought any product but since I didn't so I uncheck that as well but then I just receive the email that the information I provided is nonsufficient even thou I provided all the information that is correct. Unfortunately Sign-in helper didn't work. Kindly help me resolve the issue. Looking forward to your positive response. Yours sincerely.32Views0likes0CommentsMinha conta Microsoft foi comprometida e o e-mail original deixou de ser reconhecido
Olá, preciso de ajuda para recuperar minha conta Microsoft. Minha conta originalmente usava o endereço email address removed for privacy reasons. Recentemente perdi o acesso e, quando tento entrar ou usar o formulário de recuperação com esse endereço, aparece a mensagem de que “a conta Microsoft inserida não existe”. Acredito que o endereço de e-mail e as informações de segurança da conta tenham sido alterados sem minha autorização. O endereço email address removed for privacy reasons ainda aparece no meu Microsoft Authenticator. Ainda tenho o Authenticator associado à conta antiga, mas o código de verificação não é aceito. Durante uma tentativa de recuperação apareceu o endereço email address removed for privacy reasons, que não reconheço. A conta também ainda aparece associada ao meu perfil de administrador do Windows e ainda consigo acessar minha conta do Minecraft pelo site. Já tentei o Assistente de Entrada e o formulário de recuperação, mas o endereço original não é mais reconhecido. Gostaria de saber qual é o procedimento correto para recuperar a conta ou entrar em contato com o suporte responsável por contas Microsoft comprometidas. Obrigado pela ajuda!74Views0likes0CommentsMicrosoft Account connected apps management
Why is there no visible “Connected apps” management page in Microsoft Account? I noticed that third-party applications connected to a personal Microsoft account can be managed at: https://account.live.com/consent/Manage However, I cannot find any obvious navigation path to this page from the main Microsoft Account portal: https://account.microsoft.com/ The main account portal provides sections such as Security, Privacy, Devices, Subscriptions, and Your info, but there does not appear to be a visible “Connected apps”, “Apps and services”, or “App permissions” entry. I only discovered the consent management page after receiving a Microsoft security notification that a new application had been granted access to my Microsoft account. The “Manage your apps” button in that email links to the older account.live.com consent page. This creates two usability and security concerns: Users may not know where to review or revoke third-party OAuth permissions unless they still have the original security notification email. Microsoft Account management currently uses both microsoft.com and live.com domains, which can be confusing for users trying to verify whether an account-management page is an official Microsoft page. Would it be possible to add a visible “Connected apps”, “Apps and services”, or “App permissions” entry under Security or Privacy in account.microsoft.com? This would not require redesigning the existing consent system. Even a simple link from account.microsoft.com to the existing account.live.com/consent/Manage page would make third-party permission management much easier to discover. Is there currently an official navigation path to this page that I may have missed?219Views0likes2CommentsConditional Access enforces MFA but Service Account still ask to secure account
Hi, I've setup Conditional Access policies to enforce MFA. But it excludes a group for service accounts. Whenever we login to a Service Account, they all ask to secure your account. Hit next > It says no MFA options are available > Skip. Both our own MFA conditional access policy and MS per-user conditional access policy excludes this group. The Legacy per-user authentication policy has all accounts disabled there in favour of the conditional access policy. We must be missing something here. Some of these are shared inboxes, others regular user accounts. Many of these services requires login through the typical Microsoft sign in screen to authorize access. Some does not support OpenID. So how do I 100% exclude service accounts from MFA? And how do I get rid of this popup to secure these accounts when it says no MFA options are available? TIA1.1KViews0likes2CommentsWho Can Access What? Designing RBAC and Identity in Azure
Who should be allowed to access an Azure resource? Azure makes it easy to create resources. The harder question comes afterwards: who should be allowed to access them? A Function App may need to read secrets from Key Vault. A Logic App may need to call APIs through API Management. A developer may need to deploy to Dev but have no access to Production. A CI/CD pipeline may need to deploy infrastructure without becoming an Owner of the entire subscription. This is where Azure Role-Based Access Control (RBAC) and Managed Identity become critical. In this article, I look at how to design access around people, applications and deployment pipelines, while keeping permissions as narrow as practical. The article covers: Azure RBAC and access scopes Least-privilege access Managed Identities Developer vs Production access boundaries Application identities CI/CD deployment permissions RBAC vs API authentication Privileged access and PIM Common RBAC design mistakes One of the key principles is simple: Give an identity only the permissions it actually needs. For example, if a Function App only needs to read secrets from Key Vault, giving it Contributor access to the entire Resource Group solves the problem with a much broader permission than necessary. Good RBAC design is not about assigning more permissions. It is about understanding: Who needs access? Why do they need it? What exactly do they need to do? At what scope should access be granted? How can that access be managed securely over time? I would be interested to hear how others approach RBAC and identity design in enterprise Azure environments. Full article: https://www.linkedin.com/pulse/who-can-access-what-designing-rbac-identity-azure-chethan-raj-ud6gc/159Views0likes0CommentsHow much of your Microsoft 365 environment can you actually see at once?
Not how many users you have. Not how many sites, teams, apps or flows you have. How much of it can you actually see connected together? I've been working across Microsoft 365 environments for a while, and I kept running into the same thing. There is no shortage of information. If anything, there is probably too much of it. Users, groups, permissions, SharePoint, Teams, Power Apps, Power Automate, Power BI, Dataverse, OneDrive, Exchange, Intune, licensing, configuration... It's all there. But when you're actually trying to understand how everything fits together, it can be a different story. You open one blade. Find something. Open another. Cross-check it. Go back. Open something else. Before long, you're jumping between different parts of the tenant trying to build the bigger picture in your head. And if you're working with larger environments, that gets difficult pretty quickly. The information isn't necessarily missing. The relationships between the information are what can be difficult to see. That got me thinking about a slightly different question: Instead of "where do I find this information?" "Show me what's connected to this." That's where VisibleState started. Start anywhere. Follow the connections. Imagine starting with a single user. Instead of seeing that user simply as a record with a list of properties, imagine being able to explore the relationships around them: User → Groups → SharePoint → Teams → Power Apps → Power Automate → Power BI → Dataverse → OneDrive → Exchange → Intune Then the questions become different: What does this user have access to? Is that access direct or coming through a group? What resources are connected to them? What depends on something they're associated with? Which licenses are involved? Are there relationships that look unusual? If something changes, what else might be affected? Those questions aren't necessarily about finding another piece of information. They're about putting information that already exists into context. A report can tell you that something exists. A connected view helps you understand what it is connected to. Illustrative example below — not a real customer environment. I'm not suggesting Microsoft 365 doesn't already give us this information Quite the opposite. Microsoft 365 already gives administrators an incredible amount of information and tooling. The thing I've been thinking about is what happens when you want to look across those boundaries. Sometimes I don't want another export. I don't want another list. I don't necessarily want another dashboard. I want to start with something I'm looking at and ask: "What's connected to this?" And then keep following the trail. That's the idea I'm exploring with VisibleState. The interesting part is what happens when you change the viewpoint The same relationships can be useful for completely different reasons. For example: Administrators may want to understand access, permissions and dependencies. Security and governance teams may want to find unusual relationships or exceptions. Compliance teams may need to understand who can access something and why. People managing multiple environments may want a consistent way to understand what's there without rebuilding the picture manually every time. Leadership may not need to see the graph at all. They may simply want to know what's important, what's exposed and what could be affected. It's still the same underlying environment. You're just looking at it from a different angle. And that's where I think things get interesting. Where I'm at with it VisibleState started as something I was building to make my own work easier. I was spending a lot of time investigating environments, tracing access and putting information together for reports. The individual tasks weren't necessarily difficult. It was the jumping between different places and reconstructing the bigger picture that took the time. So I started building something that would let me approach the environment through the relationships instead. It's grown quite a bit from where it started, and I'm continuing to build it. I'm not posting this as a product launch, and I'm not looking for people to sign up. I'm genuinely interested in whether the problem I'm seeing is familiar to other people working with Microsoft 365. So I'm curious... If you could start with any object in your Microsoft 365 environment and immediately see what it's connected to, where would you start? Would it be: Users and access Groups and permissions SharePoint and Teams Power Apps, Power Automate, Power BI and Dataverse Licensing and resources Governance and unusual relationships Something completely different Maybe you've already got a good way of doing this. Maybe you still find yourself jumping between different services and piecing things together manually. Or maybe I'm looking at the problem from the wrong direction. What's the one relationship in your Microsoft 365 environment that you wish you could see instantly?196Views0likes0Comments**bleep**. Security Update (like KB5101650) breaking SmartCard Authentication for Office 2024 apps to O365
Looking for some support on this issue. I have Win11 clients that were upgraded from 24H2 to 25H2 last year. They were functioning well until earlier this year when the Cumulative Updates started breaking smartcard authentication on our clients (day after installing/rebooting/cache clearing). This seems to be a known issue but are there any real fixes? Symptom is that after the update is installed, next day (after a reboot or cache cleared) the user starts their Outlook or Teams application, when receiving the prompt that says "you will be prompted for your PIN" nothing follows, you will see the blue dots circling and after 5 or so minutes it times out. Clicking on the "..." shows an informational message error #50058, which says that not enough information was provided. The authentication process is failing... BTW - web authentication works just fine, it's just the local application (Teams, Outlook, etc.) that fail. I found that creating a new account on the system seems to work just fine, but for people that have established accounts and program environments that are setup for them to work, creating a new account is very unappealing to them. I'd like to be able to just get their current accounts working. Creating a new profile, wiping current profile info from registry doesn't seem to work thanks to automagic backups the OS is doing, but even that would still require setting up a new profile and copying over non AAPDAT file structure info... Does Microsoft not have a fix to this "known" issue? I spent a few weeks really digging into this and the best I can find as a work around is to disable the automatic backups of the NTUSER.DAT, blow away current profile info in registry, rename current profile structure, and then have the user login "anew". Again, this still requires a copy of the non-AAPDAT data back into the new structure (at least permissions won't be an issue) but that will not restore all application-based information for that user--that still will have to be re-created, which I think the users will not want to do because it means starting over from scratch.458Views0likes2Comments