Checklist
advanced

Privileged Access Security Audit Checklist

Comprehensive checklist for auditing privileged access in Microsoft 365 and Entra ID. Use this for quarterly reviews or pre-audit preparation.

15 items
4-8 hours
Security teams conducting privileged access audits

Prerequisites

  • Global Reader or Security Reader role
  • Access to Entra ID admin center
  • PowerShell with Microsoft Graph module

Global Administrator Review

Audit all Global Administrator assignments.

Verify Global Admin count is between 2-4critical

Export list of all Global Admins and verify count.

Related: PA-01

Tips:

  • Run: Get-MgDirectoryRole | Where DisplayName -eq "Global Administrator" | Get-MgDirectoryRoleMember
Confirm all Global Admins have MFA enabledcritical

Check authentication methods for each Global Admin.

Related: ID-01
Verify Global Admins use dedicated admin accountshigh

Admins should not use their daily accounts for privileged access.

Related: PA-02
Review Global Admin sign-in activity (90 days)high

Identify any Global Admins with no recent activity.

Privileged Role Review

Audit all privileged role assignments beyond Global Admin.

Export full privileged role inventoryhigh

Document all users with privileged roles.

Related: PA-03
Verify PIM is enabled for privileged roleshigh

Check that roles use eligible assignments, not permanent.

Related: PA-04
Verify business justification for each assignmentmedium

Document why each user needs their privileged role.

Check for least-privilege violationshigh

Identify users with more access than their job requires.

Emergency Access Review

Audit break-glass account configuration.

Verify 2 break-glass accounts existcritical

Check for properly configured emergency access accounts.

Related: PA-05
Confirm break-glass accounts excluded from CAcritical

Verify accounts are excluded from all Conditional Access policies.

Verify break-glass accounts were tested this quarterhigh

Check documentation for recent test of emergency access.

Confirm alerting on break-glass sign-inshigh

Verify alerts are configured for any break-glass account usage.

Service Account Review

Audit service accounts and managed identities.

Document all service accountshigh

List all service accounts with their purpose and owner.

Review service account permissionshigh

Verify service accounts have minimum required permissions.

Check service account authenticationmedium

Verify appropriate authentication for service accounts.

Automate this checklist with TrueConfig

TrueConfig automatically monitors your Microsoft 365 configuration against these best practices and alerts you when settings drift.