Identity is the perimeter now, wherever you sign in from.
A review of the Entra ID and Microsoft 365 tenant Australian businesses sign in to, delivered Australia-wide by Brisbane practitioners who run tenants of their own.
Black Shard is an Australian software engineering and cybersecurity firm. Most Australian organisations run identity through Microsoft Entra ID and Microsoft 365, and for most of them it is the perimeter that matters most now: a compromised password, an over-permissioned third-party app, or a forgotten offboarding step can be the entire path to an attacker signing in as someone real. An Entra ID security review examines that tenant properly, the way we examine our own.
We run Azure and Microsoft 365 tenants in production ourselves, for our own ventures and for client organisations, and that operating experience is where the review's judgement comes from: identity rarely breaks in the controls Microsoft ships by default, it breaks in the exception granted under pressure and never revisited. The review is delivered by hand, every finding validated, with a remediation plan tied to controls you already pay for.
What the review covers
The review is built around your tenant, not a generic checklist. Conditional access and multi-factor authentication coverage is checked across every account that matters, including break-glass accounts, the ones that exist for when everything else fails and are too often left unmonitored or unprotected themselves. Privileged roles get a full audit: who holds Global Administrator and the other high-impact roles, whether each assignment is still justified, and whether access is standing or granted just in time.
App consent is examined with the same scrutiny: which applications, third-party and internal, your users have granted access to the tenant, what permissions those grants actually carry, and whether any are broad enough that a single phishing click turns into a mailbox-wide compromise. Offboarding hygiene closes the loop: whether a departing user's access is genuinely removed on the day they leave, and whether the tenant can recover if an administrator account is lost.
- Conditional access and MFA coverage across every account that matters, including break-glass accounts
- Privileged-role audit: who holds high-impact roles, and whether the assignment still stands up
- App-consent audit across the tenant, including over-broad third-party grants
- Offboarding hygiene: whether access is actually removed the day someone leaves
- Recovery readiness, so a lost administrator account cannot lock the business out
- Legacy authentication, guest accounts, and dormant accounts, checked rather than assumed clean
Why identity is the perimeter now
The network edge used to be the thing worth defending first. For most organisations running Microsoft 365, that edge has moved: an attacker rarely needs to breach a firewall when a valid set of credentials or a consented third-party app gets them into the tenant directly. Once inside, mailbox rules, file shares, and Teams conversations often hand over more than a network intrusion ever would.
That is why conditional access, privileged-role discipline, and app-consent hygiene carry more weight than almost any other control in a modern Microsoft 365 environment, and why most tenants have never had those three areas reviewed together by someone who did not configure them.
How this differs from an Azure security review
Our Azure security review covers identity as one of six areas, alongside network, secrets, logging, misconfiguration, and over-privilege, and for most tenants that depth is the right call. This page is the deeper version, for organisations that need the Microsoft 365 identity estate examined on its own footing: every conditional access policy, every privileged role, every app consent, and the offboarding and recovery processes behind them.
If you are not sure which one fits, say so in the brief. We will give an honest answer on whether a wider Azure review or a dedicated Entra ID review is the right scope, rather than default to the bigger engagement.
Delivered Australia-wide from our Brisbane head office
The review does not need us in your building. It needs read access to your tenant, an honest brief on what your organisation runs on Microsoft 365, and time with the people who can answer the real-world questions a config export cannot. Scoping and the debrief run by video call, the same way in every state.
If your organisation is in Brisbane and would rather scope and debrief across a table, that option exists too: our Entra ID security review, Brisbane page covers the same service with the local option made explicit.
Who does the review
The same practitioners who review Azure tenants, run penetration tests, and do remediation engineering when an incident actually happens. Reviewing identity well is a judgement call, not a config export against a checklist, and that judgement comes from having granted and revoked access under real pressure ourselves.
Access to review your tenant is least-privilege throughout: reader-level roles scoped to the engagement, agreed at scoping and removed when it ends. Our own posture, including SMB1001:2026 Gold verifiable on CyberCert's registry, is set out on our trust page.
What does an Entra ID security review cost?
We do not publish a figure. Effort is driven by the size of your identity estate: how many users, guest accounts, and privileged roles you carry, and how many third-party applications have accumulated access over the years.
The engagement runs with a defined target, timeframe, and deliverable agreed before work starts. Send a brief with the rough shape of your tenant and we will scope it.
Every engagement includes
A director on the work
A director reads the brief, scopes the engagement, and stays accountable for the result.
Fixed scope, quoted first
Scope, timeframe, and price are agreed before work starts.
Findings validated by hand
Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.
A re-test to prove it
Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.
Least-privilege access
We take only the access the work requires, and client data sits in Australian regions.
A report that is yours
Written for your engineers and your board, and kept confidential.
Questions, answered
- What access do you need to our tenant?
- Reader-level roles scoped to the review, typically Global Reader in Entra ID with read access to Conditional Access policies and Enterprise Applications, agreed at scoping and removed when the engagement ends.
- Is this the same as your Azure security review?
- No, though they overlap. The Azure review covers identity as one of six areas across your whole tenant. This review goes deeper into Entra ID and Microsoft 365 specifically: conditional access, privileged roles, app consent, and offboarding. Tell us your situation in the brief and we will recommend the one that actually fits.
- Can you fix what you find?
- Yes. We are a software engineering firm as well as a cybersecurity firm, so remediation can run as advisory support or hands-on configuration change after the review, and the plan is written so your own team can execute it without us.
- How long does a review take?
- It runs as a fixed-scope engagement, so the target, timeframe, and deliverable are agreed before we start. The size of your identity estate, users, guest accounts, privileged roles, and app consents drives the effort.
- Do you review break-glass accounts?
- Yes, specifically. Break-glass accounts exist for when everything else fails, which makes them one of the most consequential things in a tenant to leave unreviewed. We check whether they exist, how they are protected, and whether anyone would notice if one were used.
- Do you work with organisations outside Brisbane?
- Yes. Black Shard is a national firm and delivers Australia-wide; scoping and the debrief run remotely as standard, and organisations in Brisbane can choose an in-person debrief instead.
Related reading
The full practice: Security advisory & vCISO.
Know who can sign in, and what they can reach, wherever you operate.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.