Black Shard

Identity is the perimeter now. Know if yours holds.

A review of the Entra ID and Microsoft 365 tenant your business signs in to: conditional access, privileged roles, app consent, and offboarding hygiene, from our Eagle Street office.

Black Shard is an Australian software engineering and cybersecurity firm with its head office on Eagle Street in Brisbane. Most Australian businesses run their identity through Microsoft Entra ID and Microsoft 365, and for most of them it is also the perimeter that matters most: the thing a compromised password, an over-permissioned app, or a forgotten offboarding step can turn into an attacker signing in as someone real. An Entra ID security review examines that tenant the way we examine our own.

We run Azure and Microsoft 365 tenants in production ourselves, and we know from operating them where identity actually breaks: not in the controls Microsoft ships by default, but in the exceptions granted under pressure and never revisited. The review is delivered by hand, every finding validated, with a remediation plan tied to controls you already pay for.

What the review covers

The review examines your tenant, not a generic checklist. Conditional access and multi-factor authentication coverage is checked across every account that matters, including the break-glass accounts that exist for when everything else fails and are too often left unmonitored or, worse, unprotected themselves. Privileged roles get a full audit: who holds Global Administrator and the other high-impact roles, whether the assignment is still justified, and whether it is standing access or something granted just in time.

App consent is reviewed with the same scrutiny: which third-party and internal applications your users have granted access to the tenant, what permissions those grants actually carry, and whether any of them are the kind of over-broad consent that turns a single phishing click into a mailbox-wide compromise. Offboarding hygiene closes the loop: whether a departing user's access is actually removed on the day they leave, and whether recovery is possible if an administrator account is lost, so a lost admin never locks the business out of its own tenant.

  • Conditional access and MFA coverage across every account that matters, including break-glass accounts
  • Privileged-role audit: who holds high-impact roles, and whether the assignment still stands up
  • App-consent audit across the tenant, including over-broad third-party grants
  • Offboarding hygiene: whether access is actually removed the day someone leaves
  • Recovery readiness, so a lost administrator account cannot lock the business out
  • Legacy authentication, guest accounts, and dormant accounts, checked rather than assumed clean

Why identity is the perimeter now

The network edge used to be the thing worth defending. For most businesses running Microsoft 365, that edge has moved: an attacker rarely needs to breach a firewall when a set of valid credentials, or a consented third-party app, gets them into the tenant directly. Once inside, mailbox rules, file shares, and Teams conversations often hand over more than a network intrusion would have.

That is why conditional access, privileged-role discipline, and app-consent hygiene do more work than almost any other control in a modern Microsoft 365 environment. Most tenants have never had those three areas reviewed together by someone who is not the person who configured them.

How this differs from an Azure security review

Our Azure security review covers identity as one of six areas, alongside network, secrets, logging, misconfiguration, and over-privilege, and for most tenants that is the right depth: enough to catch privileged-role sprawl and missing conditional access as part of a wider tenant review. This page is the deeper version, for when the Microsoft 365 identity estate is the thing you actually need examined on its own footing: every conditional access policy, every privileged role, every app consent, and the offboarding and recovery processes around them.

If you are not sure which one you need, say so in the brief. We will tell you honestly whether a wider Azure review or a dedicated Entra ID review fits your situation, rather than sell you the bigger engagement by default.

Why scope it from Brisbane?

Scoping decides what a review actually covers, and that conversation goes better across a table than through a discovery form. At Eagle Street we can walk through your tenant's shape with you before anything is touched: how many licences, how many guest accounts, whether break-glass accounts even exist yet.

The debrief works the same way. Findings about who can sign in and what they can reach land differently when the engineer who found them is in the room to explain the real-world path from a compromised account to something that matters, and where remediation should start first.

Who does the review

The same engineers who review Azure tenants, run penetration tests, and do remediation engineering when an incident actually happens. Reviewing identity well is not a config export against a checklist; it takes knowing which exception was granted under real pressure and never revisited, because we have granted and revoked access under the same pressure ourselves.

Access to review your tenant is least-privilege throughout: reader-level roles scoped to the engagement, agreed at scoping and removed when it ends. Our own posture, including SMB1001:2026 Gold verifiable on CyberCert's registry, is on our trust page.

What does an Entra ID security review cost?

We do not publish a figure. The effort is driven by the size of your identity estate: how many users, guest accounts, and privileged roles you carry, and how many third-party applications have been granted access over the years.

The engagement runs with a defined target, timeframe, and deliverable agreed before work starts. Send a brief with the rough shape of your tenant and we will scope it.

Do you only review Brisbane tenants?

No. The review runs Australia-wide from our Brisbane head office, the same way it runs locally: scoping and the debrief by video call instead of across a table.

If you are outside Brisbane, our Entra ID security review, Australia-wide page covers the national service.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Fixed scope, quoted first

    Scope, timeframe, and price are agreed before work starts.

  • Findings validated by hand

    Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.

  • A re-test to prove it

    Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

What access do you need to our tenant?
Reader-level roles scoped to the review, typically Global Reader in Entra ID with read access to Conditional Access policies and Enterprise Applications, agreed at scoping and removed when the engagement ends.
Is this the same as your Azure security review?
No, though they overlap. The Azure review covers identity as one of six areas across your whole tenant. This review goes deeper into Entra ID and Microsoft 365 specifically: conditional access, privileged roles, app consent, and offboarding. Tell us your situation in the brief and we will recommend the one that actually fits.
Can you fix what you find?
Yes. We are a software engineering firm as well as a cybersecurity firm, so remediation can run as advisory support or hands-on configuration change after the review, and the plan is written so your own team can execute it without us.
How long does a review take?
It runs as a fixed-scope engagement, so the target, timeframe, and deliverable are agreed before we start. The size of your identity estate, users, guest accounts, privileged roles, and app consents drives the effort.
Do you review break-glass accounts?
Yes, specifically. Break-glass accounts exist for when everything else fails, which makes them one of the most consequential things in a tenant to leave unreviewed. We check whether they exist, how they are protected, and whether anyone would notice if one were used.
Do you only work with Brisbane businesses?
No. We are a national firm and deliver Australia-wide. The review runs the same way either way; Brisbane businesses have the option of an in-person debrief.

Know who can sign in, and what they can reach.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au