The current product version of remivis includes 11 implemented Entra ID baseline checks. This does not mean public availability or a complete assessment of every tenant.
The checks are one part of the assessment. Alongside them, remivis inventories nine areas covering applications, permissions and configuration. Explore the inventory
Available data, permissions, licences and, for some checks, declared accounts or apps determine the actual assessment scope. Results belong to a dated assessment: Passed, Finding, Not assessed or Not applicable.
Product status:
ENTRA-001
Declared emergency accounts
Checks whether at least two explicitly selected emergency accounts are enabled and cloud-only.
Prerequisites and scope
Emergency accounts must be specified in advance.
How to interpret this
Only the specified accounts are checked. This does not demonstrate a successful test of an emergency sign-in.
ENTRA-003
Number of Global Administrators
Checks whether no more than four active accounts hold the Global Administrator role.
Prerequisites and scope
Covers active accounts with the Global Administrator role.
How to interpret this
This check uses a threshold of no more than four. Its result does not cover every privileged access path.
ENTRA-005
Privileged guest accounts
Checks whether active guest accounts hold privileged directory roles.
Prerequisites and scope
Covers active guest accounts and their privileged directory roles.
How to interpret this
This check covers directory roles. It does not assess all sharing settings or guest access rights.
ENTRA-006
MFA registration of privileged accounts
Checks the recorded MFA registration of active privileged accounts.
Prerequisites and scope
Requires complete, valid Microsoft registration reports.
How to interpret this
A registered MFA method does not prove that MFA is enforced or actually used at every sign-in.
ENTRA-007
Everyday account with privileged roles
Checks whether active accounts explicitly declared as everyday accounts hold directory roles.
Prerequisites and scope
Everyday accounts must be explicitly specified.
How to interpret this
The check applies to the specified everyday accounts. It does not automatically detect how an account is actually used day to day.
ENTRA-008
Security defaults and baseline protection
Checks security defaults and baseline protection in Microsoft Entra ID.
Prerequisites and scope
The relevant configuration data must be available with the required permissions.
How to interpret this
The check does not replace a complete review of all safeguards. It evaluates the configuration captured in the assessment.
ENTRA-009
MFA requirement for Global Administrators
Checks the MFA requirement for Global Administrators against the defined assessment criteria.
Prerequisites and scope
The role and policy data required for the assessment must be available. Permissions and licences affect what can be assessed.
How to interpret this
This check is separate from MFA registration (ENTRA-006). It does not provide proof for every actual sign-in.
ENTRA-010
Active Conditional Access policies
Checks active Conditional Access policies in the captured Entra ID configuration.
Prerequisites and scope
The required policy data must be readable. Permissions and licences determine what can be assessed.
How to interpret this
An active policy alone does not demonstrate complete protection. The defined criteria for each check are what matter.
ENTRA-011
Blocking legacy authentication
Checks whether legacy authentication is blocked according to the defined assessment criteria.
Prerequisites and scope
The relevant configuration and policy data must be available. Permissions and licences affect what can be assessed.
How to interpret this
The result describes the criteria evaluated in that assessment. It is not a blanket statement about all protocols and access paths.
ENTRA-022
Expiry of critical app credentials
Checks whether certificates or client secrets for selected critical app registrations have expired or will expire within 30 days.
Prerequisites and scope
Critical applications must be selected in advance.
How to interpret this
The check evaluates the expiry of credentials for selected app registrations. It does not renew certificates or client secrets.
ENTRA-023
Owners of critical app registrations
Checks whether each app registration included in the assessment has at least one user listed as an owner. With at least one user, the check passes. No owners, or only service principals as owners, result in a finding.
Prerequisites and scope
Requires Application.Read.All. This read permission is already mandatory; no additional read permission is needed.
How to interpret this
If the owner list cannot be read in full or an owner type is unknown, the result is “Not assessed”. The absence of a user as an owner is an organisational finding, not evidence of a security vulnerability.
What happens after the assessment?
remivis shows all check results and provides practical review steps for findings. Tasks can be assigned and prioritised. The responsible team makes changes itself; remivis reads Microsoft configurations.
A completed task alone does not prove technical resolution. A new scan assesses the defined criteria at a new point in time. It confirms neither complete security nor a specific cause of improvement.
What is outside the current scope?
The pilot is not a complete Microsoft 365 audit or a compliance certification. AD synchronisation is planned and has not been implemented. Intune and Defender are not included in the available assessment scope described here.