Create two cloud-only, Global Administrator emergency accounts excluded from Conditional Access, declare them as break-glass principals in…~a few hours
Why: We could not confirm a dedicated emergency admin account. Without one, an outage or lockout can lock you out of your own tenant.
Action: Create two cloud-only, Global Administrator emergency accounts excluded from Conditional Access, declare them as break-glass principals in your configured settings, and remove any other unexplained exclusions.
Licensed controls mapped to detected Microsoft entitlements, grouped by workload.
▸
Owned SKUs (2)
SKU
Service plans
Licenses
Microsoft 365 E5
Microsoft Entra ID P2, Microsoft Entra ID Multifactor Authentication, Microsoft Defender for Cloud Apps, Microsoft 365 Advanced eDiscovery, Microsoft 365 Customer Lockbox, Microsoft Purview Information Protection P2, Microsoft Defender for Office 365 (Plan 2), Microsoft Defender for Endpoint P2
What it does Decide who can sign in, from where, on which devices, and whether they must prove it is really them (for example with multi-factor authentication).
▸ Why it matters and what's covered
Why it matters Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.
If left off Your licenses include advanced sign-in rules, but they may still be loose or incomplete.
Microsoft controlConditional Access
LicenseMicrosoft 365 E5
Service planMicrosoft Entra ID P2
Incomplete
Deep protection and visibility on PCs and devices
What it does See attacks on laptops and servers in more detail, find weak software, and respond before a single infected PC becomes a company-wide problem.
▸ Why it matters and what's covered
Why it matters Devices are where people work. If they are not enrolled in advanced protection, you are flying partly blind.
If left off You may be paying for advanced device protection on seats that are not fully enrolled.
Microsoft controlMicrosoft Defender for Endpoint P2
LicenseMicrosoft 365 E5
Service planMicrosoft Defender for Endpoint P2
Incomplete
Watchdogs on your on-site directory (if you still have one)
What it does Spot attackers moving through traditional office servers and Active Directory, not only cloud sign-ins.
▸ Why it matters and what's covered
Why it matters Many organizations still rely on on-site domain controllers. Cloud-only tools cannot see every attack path there.
If left off Identity threat sensors may be missing or unhealthy, so on-site directory attacks stay invisible.
Microsoft controlMicrosoft Defender for Identity
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Incomplete
Safe Attachments and Safe Links essentials
What it does Detonate risky attachments and rewrite dangerous links for licensed users even when the full P2 investigation pack is not present.
▸ Why it matters and what's covered
Why it matters Many tenants own P1-level email protections that never leave default off states.
If left off Safe content policies may be missing, scoped to pilots, or left in evaluation mode.
Microsoft controlMicrosoft Defender for Office 365 P1
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Incomplete
Stronger email and file threat protection
What it does Open risky attachments and links in a safe way, catch advanced phishing, and investigate email threats faster when something slips through.
▸ Why it matters and what's covered
Why it matters Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.
If left off Extra email protections in your license may still be off, in test mode, or only covering a few people.
Microsoft controlMicrosoft Defender for Office 365 P2
LicenseMicrosoft 365 E5
Service planMicrosoft Defender for Office 365 (Plan 2)
Operational
Cross-product incident correlation
What it does Connect identity, email, endpoint, and cloud signals into incidents that show the full attack story instead of isolated alerts.
▸ Why it matters and what's covered
Why it matters Attackers hop products. Siloed alerts hide the path from phishing to privilege.
If left off XDR correlation may be licensed while automated investigation and response stay idle.
Microsoft controlMicrosoft Defender XDR
LicenseMicrosoft 365 E5
Service planMicrosoft Defender for Endpoint P2, Microsoft Defender for Office 365 (Plan 2)
Action required
Stronger control over admin accounts
What it does Give people powerful admin rights only when they need them, and get better tools to catch risky sign-ins on high-value accounts.
▸ Why it matters and what's covered
Why it matters Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.
If left off You are paying for stronger admin protections that are not fully turned on yet.
Microsoft controlMicrosoft Entra ID P2
LicenseMicrosoft 365 E5
Service planMicrosoft Entra ID P2
Incomplete
Business email and calendar in the cloud
What it does Host mailboxes in Microsoft 365 and apply tenant email security and sharing controls that protect everyday business communication.
▸ Why it matters and what's covered
Why it matters Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.
If left off Mailboxes may be licensed while core protection and audit settings stay at weak defaults.
Microsoft controlExchange Online
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Operational
Baseline spam and malware filtering for email
What it does Filter obvious junk and malware before it reaches inboxes, as the foundation under optional Defender for Office 365 controls.
▸ Why it matters and what's covered
Why it matters Without baseline filtering, every advanced email control sits on a weak floor.
If left off Core anti-spam or anti-malware policies may be off, overly permissive, or unmonitored.
Microsoft controlExchange Online Protection
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Action required
Alerts when a sign-in looks suspicious
What it does Automatically spot odd sign-in behavior (impossible travel, leaked passwords, unfamiliar locations) and require extra proof or block access.
▸ Why it matters and what's covered
Why it matters Attackers often use valid passwords. Risk detection helps catch the session even when the password was correct.
If left off Suspicious-sign-in protection is included in your plan but may not be enforcing anything yet.
Microsoft controlMicrosoft Entra ID Protection
LicenseMicrosoft 365 E5
Service planMicrosoft Entra ID P2
Action required
Manage and protect company devices and apps
What it does Require healthy devices, push secure settings, and protect work data on phones and PCs people already use.
▸ Why it matters and what's covered
Why it matters Unmanaged devices are a common path around strong cloud identity controls.
If left off Compliance or configuration profiles may be missing, unassigned, or never enforced.
Microsoft controlMicrosoft Intune
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Action required
The log store behind security analytics
What it does Land security and operational logs in a workspace that detections and investigations can query.
▸ Why it matters and what's covered
Why it matters Sentinel without healthy log ingestion is an empty command center.
If left off Workspaces may exist while critical tables are missing, short-retained, or never connected.
Microsoft controlAzure Log Analytics
LicenseMicrosoft Sentinel
Service planNo matching service plan reported
Action required
A central security command center in the cloud
What it does Bring security signals together in one place, detect patterns humans miss, and automate parts of incident response.
▸ Why it matters and what's covered
Why it matters Without a place that correlates events, teams drown in alerts from many products and miss the story that ties them together.
If left off A security workspace may exist, but few detections or smart analytics are turned on.
Microsoft controlMicrosoft Sentinel
LicenseMicrosoft Sentinel
Service planMicrosoft Sentinel
Operational
Personal work files in the cloud
What it does Give people a private work drive while still enforcing sharing limits, device access, and retention expectations.
▸ Why it matters and what's covered
Why it matters Personal work drives often hold the same sensitive files as shared libraries.
If left off OneDrive sharing or sync controls may lag behind the SharePoint tenant baseline.
Microsoft controlOneDrive for Business
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Operational
Shared interactive business reports
What it does Publish and share interactive reports with colleagues under tenant-level export, sharing, and guest boundaries.
▸ Why it matters and what's covered
Why it matters BI content often contains concentrated business truth; loose sharing leaks strategy.
If left off Tenant sharing or export settings may still allow broader distribution than intended.
Microsoft controlPower BI Pro
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Operational
Low-code apps, flows, and environments
What it does Let teams build useful apps and automations inside governed environments with DLP and tenant isolation boundaries.
▸ Why it matters and what's covered
Why it matters Ungoverned makers can connect business data to personal connectors overnight.
If left off Environment creation, connector policies, or tenant isolation may still be wide open.
Microsoft controlMicrosoft Power Platform
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Incomplete
A searchable record of important activity
What it does Reconstruct who did what across mail, files, and admin actions when something goes wrong.
▸ Why it matters and what's covered
Why it matters Without audit history, investigations stall and compliance questions go unanswered.
If left off Audit logging may be off, truncated, or never queried after an incident.
Microsoft controlMicrosoft Purview Audit
LicenseMicrosoft 365 E5
Service planMicrosoft 365 Advanced eDiscovery
Incomplete
Oversight for risky business communications
What it does Detect harassment, threats, or sensitive-data sharing patterns in business conversations.
▸ Why it matters and what's covered
Why it matters Toxic or noncompliant communication creates legal and cultural risk that identity tools miss.
If left off Communication compliance may be entitled but never scoped to the channels that matter.
Microsoft controlMicrosoft Purview Communication Compliance
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Action required
Guardrails so sensitive data is harder to leak
What it does Warn or block people when they try to share credit cards, health data, or other sensitive information in the wrong place.
▸ Why it matters and what's covered
Why it matters Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.
If left off Data-protection rules may be missing or still in "test only" mode, so nothing is enforced yet.
Microsoft controlMicrosoft Purview Data Loss Prevention
LicenseMicrosoft 365 E5
Service planMicrosoft Purview Information Protection P2
Operational
Legal hold and investigation search
What it does Preserve and search relevant content when legal or investigative work demands it.
▸ Why it matters and what's covered
Why it matters Missing holds destroy evidence and create legal and regulatory exposure.
If left off eDiscovery tools may be licensed while no one can run a defensible case workflow.
Microsoft controlMicrosoft Purview eDiscovery
LicenseMicrosoft 365 E5
Service planMicrosoft 365 Advanced eDiscovery, Microsoft 365 Customer Lockbox
Operational
Early warning for risky insider activity
What it does Spot patterns that suggest data theft, leak, or policy abuse by people who already have access.
▸ Why it matters and what's covered
Why it matters Trusted access is powerful. Without signals, insider incidents surface only after damage.
If left off Insider risk policies may be unlicensed in practice or never moved past trial defaults.
Microsoft controlMicrosoft Purview Insider Risk Management
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Operational
Retention rules that keep or remove content on schedule
What it does Keep content for legal or regulatory periods and remove it when it is no longer needed, reducing both evidence risk and storage cost.
▸ Why it matters and what's covered
Why it matters Retention protects evidence and reduces over-retention risk and storage cost.
If left off Retention policies may be absent, so content is either deleted too early or kept indefinitely without a defensible schedule.
Microsoft controlMicrosoft Purview Data Lifecycle Management
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Action required
Labels that classify and protect files and mail
What it does Mark sensitive content and apply encryption or access limits that travel with the file.
▸ Why it matters and what's covered
Why it matters Classification without enforcement is a sticker; labels with protection change outcomes.
If left off Labels may exist but remain unpublished, unused, or never auto-applied.
Microsoft controlMicrosoft Purview Sensitivity Labels
LicenseMicrosoft 365 E5
Service planMicrosoft Purview Information Protection P2
Incomplete
Team sites and shared file libraries
What it does Host shared libraries with clear external sharing boundaries and default link permissions that match how the business actually works.
▸ Why it matters and what's covered
Why it matters Over-broad sharing turns one mistaken link into a public data leak.
If left off Tenant sharing defaults may still allow anyone links or unmanaged access.
Microsoft controlSharePoint Online
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Action required
Chat, meetings, and teamwork hub
What it does Keep collaboration fast while controlling guests, anonymous join, apps, and recording exposure.
▸ Why it matters and what's covered
Why it matters Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.
If left off External access, lobby, or app policies may still favor convenience over control.
Microsoft controlMicrosoft Teams
LicenseMicrosoft 365 E5
Service planNo matching service plan reported
Findings
Findings
Every assessed control, most critical first. Expand a row for what we
expected, what we observed, and what to do next. Select several values in
a group to match any of them; different groups combine. Filter by
compliance mappings (Mapped / Unmapped) to isolate controls with NIST or
MITRE references.
▸ Findings at a glance
Findings by status
Action required40
Incomplete17
Operational91
Not licensed6
Not assessed12
Horizontal bars showing how many findings carry each status, out of 166 findings.
Findings by status
Status
Findings
Action required
40
Incomplete
17
Operational
91
Not licensed
6
Not assessed
12
Findings by workload
Azure2
Collaboration24
Defender27
Endpoint13
Exchange12
Identity52
Power BI10
Power Platform8
Purview13
Sentinel5
Horizontal bars showing where findings concentrate across workloads, out of 166 findings.
Findings by workload
Workload
Findings
Azure
2
Collaboration
24
Defender
27
Endpoint
13
Exchange
12
Identity
52
Power BI
10
Power Platform
8
Purview
13
Sentinel
5
Findings by severity
Critical1
High100
Info1
Low2
Medium62
Horizontal bars showing how bad the findings are, out of 166 findings.
We could not confirm a dedicated emergency admin account. Without one, an outage or lockout can lock you out of your own tenant.
Action required
No documented emergency admin account, or exclusions without a reason
Severity: HighEffort: ~a few hoursScope: Administrator scopeWorkload: IdentityConfidence: High confidenceEvaluation: Read directlyCompliance: MITRE: T1078; NIST: AC-2, AC-6
We could not confirm a dedicated emergency admin account. Without one, an outage or lockout can lock you out of your own tenant.
Expected
A documented break-glass account exists with justified sign-in rule exclusions.
Observed
No break-glass account was identified among the Global Administrators; no principal is declared as break-glass in this report's configuration.
Why it matters
Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.
Value impact: High
Recommended action
Create two cloud-only, Global Administrator emergency accounts excluded from Conditional Access, declare them as break-glass principals in your configured settings, and remove any other unexplained exclusions.
Evidence▸ Technical evidence
Data sources: microsoft.graph
global_admin_principal_count: 2
declared_break_glass_principal_count: 0
identified_break_glass_accounts: None reported
enabled_ca_policy_count: 3
report_only_ca_policy_count: 0
unjustified_exclusion_issues: None reported
unjustified_exclusion_count: 0
global_admin_exclusion_issues: None reported
Limitations: The break-glass account could not be confidently identified from the scanned Global Administrator assignments and eligibilities — verify the emergency access account in the Entra portal before relying on this check
Some activation guardrails are missing, so an attacker with a stolen admin account can hold powerful access longer and with less traceability.
Action required
Keep privileged-role activation short, explained, and context-bound
Severity: HighEffort: ~a few hoursScope: Administrator scopeWorkload: IdentityConfidence: High confidenceEvaluation: Read directlyCompliance: MITRE: T1078; NIST: AC-2, AC-6
Some activation guardrails are missing, so an attacker with a stolen admin account can hold powerful access longer and with less traceability.
Expected
Privileged-role activation requires justification, an authentication context, and a short time limit.
Observed
PIM activation guardrails are incomplete: activation duration is not capped at 8 hours or less; activation does not require an authentication context; activation does not require justification.
Why it matters
Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.
Value impact: High
Recommended action
In PIM role settings for each privileged role, require justification on activation, attach an authentication context, and set the maximum activation duration to a short window (8 hours or less).
Security Defaults already includes baseline MFA protection and blocks outdated sign-in methods. Your plan also includes smarter sign-in rules you can customize, but that paid capability remains unused.
Action required
Move from Security Defaults to customizable sign-in rules
Severity: HighEffort: ~a few hoursScope: All usersWorkload: IdentityConfidence: High confidenceEvaluation: Read directlyCompliance: MITRE: T1078; NIST: IA-2, IA-5
Security Defaults already includes baseline MFA protection and blocks outdated sign-in methods. Your plan also includes smarter sign-in rules you can customize, but that paid capability remains unused.
Expected
Conditional Access policies replace Security Defaults for MFA and legacy-authentication blocking.
Observed
Security defaults are enabled, providing baseline MFA protections and blocking legacy authentication. Licensed Conditional Access customization remains unused.
Why it matters
Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.
Value impact: High
Recommended action
Create equivalent Conditional Access policies for MFA and legacy-authentication blocking in report-only mode. Validate coverage, exclusions, emergency access, and sign-in impact; then perform a controlled cutover from Security Defaults to the validated policies.
Without an authoritative eligible-device inventory we cannot confirm how much of the intended device population is actually managed.
Incomplete
Some paid device-management seats may not be enrolled
Severity: HighEffort: ~daysScope: All devicesWorkload: EndpointConfidence: Low confidence — verify in portalEvaluation: Read directlyCompliance: MITRE: T1059; NIST: CM-6, SI-2
Without an authoritative eligible-device inventory we cannot confirm how much of the intended device population is actually managed.
Expected
Licensed devices are enrolled in Intune management.
Observed
Observed 2 Intune-managed device(s) vs ~100 purchased seats. Without an authoritative eligible device inventory this is a licensing-leverage signal, not confirmed enrollment coverage.
Why it matters
Unmanaged devices are a common path around strong cloud identity controls.
Value impact: High
Recommended action
Compare Intune licenses to enrolled devices and enroll the missing ones through the device management tools you already use.
Evidence▸ Technical evidence
Data sources: graph.deviceManagement, graph.subscribedSkus (proxy licensing signal)
managed_device_count: 2
licensed_units: 100
truncated: False
proxy: True
Limitations: Enrollment is compared against purchased license seats, not an authoritative device inventory; license counts do not necessarily equal the device population, so this is a licensing-leverage signal, not proven device coverage. Verify eligible devices in the Microsoft Intune admin center; Based on Microsoft Secure Score signals — confirm the real setting in the Microsoft 365 / security admin portal before treating this as definitive
Without an authoritative eligible-device inventory we cannot confirm how much of the intended device population is actually protected.
Incomplete
Some PCs may not be enrolled in advanced device protection
Severity: HighEffort: ~daysScope: All devicesWorkload: EndpointConfidence: Low confidence — verify in portalEvaluation: Read directlyCompliance: —
Without an authoritative eligible-device inventory we cannot confirm how much of the intended device population is actually protected.
Expected
Licensed devices are onboarded to Defender for Endpoint with healthy sensors.
Observed
Observed 40 onboarded Defender for Endpoint machine(s) vs ~100 purchased seats (40% of seats). This is a licensing-leverage signal and is not treated as device coverage; an eligible device inventory is required to confirm coverage.
Why it matters
Devices are where people work. If they are not enrolled in advanced protection, you are flying partly blind.
Value impact: High
Recommended action
Compare licensed seats to enrolled devices and enroll the missing ones (often through your device management tools).
Evidence▸ Technical evidence
Data sources: mde.api.machines, graph.subscribedSkus (proxy licensing signal)
onboarded_machines: 40
sample_size: 40
count_method: demo
truncated: False
licensed_units: 100
proxy: True
coverage_ratio: 0.4
Limitations: Coverage is reported against purchased license seats, not an authoritative device inventory; license counts do not necessarily equal the device population, so this is a licensing-leverage signal, not proven device coverage. Verify actual eligible devices in the Defender portal; Based on Microsoft Secure Score signals — confirm the real setting in the Microsoft 365 / security admin portal before treating this as definitive
Sensitivity labels are available for people to apply to content.
Operational
Publish sensitivity labels
Severity: HighEffort: ~a few hoursScope: All usersWorkload: PurviewConfidence: High confidenceEvaluation: Read directlyCompliance: —
Sensitivity labels are available for people to apply to content.
Expected
Sensitivity labels are published to users through an enabled label policy.
Observed
2 sensitivity label(s) are defined and published to users.
Why it matters
Classification without enforcement is a sticker; labels with protection change outcomes.
Value impact: High
Recommended action
Create a label policy that publishes your sensitivity labels to the people who handle sensitive content, then confirm the labels appear in Office apps.
Evidence▸ Technical evidence
Data sources: Microsoft Purview / Security & Compliance PowerShell (powershell.bridge)
Periodic confirmation of powerful admin access does not look set up at all, so privilege can accumulate without review.
Action required
Prove your admin-role reviews actually run and repeat
Severity: MediumEffort: ~a few hoursScope: Administrator scopeWorkload: IdentityConfidence: High confidenceEvaluation: Read directlyCompliance: MITRE: T1078; NIST: AC-2, AC-6
Periodic confirmation of powerful admin access does not look set up at all, so privilege can accumulate without review.
Expected
Access reviews for privileged roles recur on a schedule and have completed at least one round.
Observed
No access review definitions were found, so privileged roles are not covered by recurring, executed reviews.
Why it matters
Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.
Value impact: Medium
Recommended action
Create or correct an access review that targets privileged directory roles, set a recurring cadence (monthly or quarterly), and complete the first review round with decisions applied.
Some powerful accounts are still switched on but have not been used recently. Unused admin accounts and workload identities are a favorite target for attackers.
Action required
Powerful accounts that nobody uses are still switched on
Some powerful accounts are still switched on but have not been used recently. Unused admin accounts and workload identities are a favorite target for attackers.
Expected
Dormant privileged accounts are disabled or moved to just-in-time access.
Observed
Found 2 enabled privileged principal(s) with no successful sign-in or workload activity in the last 90 days (2 user(s), 0 workload identities of 4 privileged principal(s)).
Why it matters
Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.
Value impact: Medium
Recommended action
Review enabled admin accounts that have not signed in for a long time; disable or remove access you no longer need.
Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.
Value impact: High
Recommended action
Start with a simple policy for email and cloud files that detects obvious sensitive data, then move from "test" to "enforce" after a short tuning period.
dlp_graph_error: demo: direct Graph DLP read unavailable
proxy: True
source: secureScore.controlScores (proxy)
note: Uses Microsoft Secure Score DLP/information-protection controls as a proxy when direct Purview policy APIs are unavailable to the app.
Limitations: Secure Score proxy — verify DLP enforce mode in Purview portal; Based on Microsoft Secure Score signals — confirm the real setting in the Microsoft 365 / security admin portal before treating this as definitive
We could not confirm whether your tenant accepts other tenants' multi-factor authentication claims by default.
Incomplete
Do not take other tenants' word for multi-factor auth
Severity: MediumEffort: ~a few hoursScope: All usersWorkload: IdentityConfidence: High confidenceEvaluation: Read directlyCompliance: MITRE: T1078; NIST: IA-2, IA-5
We could not confirm whether your tenant accepts other tenants' multi-factor authentication claims by default.
Expected
Multi-factor authentication claims from external tenants are not trusted by default.
Observed
Cross-tenant inbound MFA trust setting was not conclusive; verify it in Entra External Identities.
Why it matters
Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.
Value impact: Medium
Recommended action
In Entra external collaboration cross-tenant access default settings, disable 'Trust multi-factor authentication from Microsoft Entra tenants' for inbound access, and re-enable it only for specific trusted partners.
We could not confirm whether on-site directory attack sensors are installed. If you still run office domain controllers, ask IT to verify.
Incomplete
On-site directory servers may lack attack sensors
Severity: MediumEffort: ~daysScope: All usersWorkload: DefenderConfidence: Low confidence — verify in portalEvaluation: Approximated — verify in portalCompliance: —
We could not confirm whether on-site directory attack sensors are installed. If you still run office domain controllers, ask IT to verify.
Expected
Defender for Identity sensors are healthy on every domain controller.
Observed
No Defender for Identity–related Secure Score controls were found. Cannot confirm sensor deployment from this signal alone.
Why it matters
Many organizations still rely on on-site domain controllers. Cloud-only tools cannot see every attack path there.
Value impact: High
Recommended action
Confirm whether you still use on-site directory servers; if yes, install and health-check the identity sensors on each one.
Evidence▸ Technical evidence
Data sources: secureScore.controlScores (proxy)
source: secureScore.controlScores
proxy: True
matched_controls: 0
score_ratio: None reported
controls: None reported
note: Defender for Identity sensor health is approximated from Secure Score controls when the MDI API is not configured.
Limitations: Secure Score proxy — verify MDI sensors in the Defender portal; Based on Microsoft Secure Score signals — confirm the real setting in the Microsoft 365 / security admin portal before treating this as definitive