Method and data
Read-only. Nothing was changed.
Vestholm Gruppen · 20 Aug 2026, 09:14 · Report VL-2608-0114
What was read
Read-only, against Microsoft Graph.
- 412 identities
- 968 devices
- 187 groups
- 34 guests
- 18 companies
- 7 countries
- 2,411,806 sign-in events
The read runs on four delegated permissions. None of them can create, change or delete an object in the directory.
- Directory.Read.All
- AuditLog.Read.All
- DeviceManagementManagedDevices.Read.All
- Reports.Read.All
How it is scored
Five categories, 100 points.
Each category has a fixed maximum. Points are deducted per finding, weighted by severity and by how many objects it affects. No benchmark and no peer comparison is applied — the score describes this tenant only.
- Identity lifecycle
- 19 / 30
- Privileged access
- 14 / 25
- Licenses and cost
- 13 / 20
- Devices
- 12 / 15
- Data quality
- 8 / 10
- Total
- 66 / 100
22 points recoverable by closing the 5 critical findings
What could not be evaluated
- N1Not evaluatedMFA registration on privileged accountsscope not granted
- N2Not evaluatedEligible vs permanent role assignmentsrequires Entra ID P2
- N3Not evaluatedService activity older than 30 daysbeyond log retention
- N4Not evaluatedLeave date coverage, all users82% of users populated
Checked and did not find
- No accounts with passwords set to never expire — checked 412 users
- No groups nested more than two levels deep — checked 187 groups
- No devices running unsupported operating system versions — checked 968 devices
- No guest accounts holding privileged roles — checked 34 guests
Sample report. Fictional group, fictional data.