Azure AD配置审计
原名:auditing-azure-active-directory-configuration
审计 Microsoft Entra ID(Azure Active Directory)配置,以
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-21
- TRACE 评分
- 3.6 / 5
内容概览
- When performing a security assessment of an Azure tenant's identity configuration - When compliance audits require review of authentication policies, MFA enforcement, and role assignments - When onboarding a new Azure tenant after merger or acquisition - When investigating suspicious sign-in activity or compromised accounts - When validating conditional access policies adequately protect against identity-based attacks Do not use for on-premises Active Directory auditing (use PingCastle or BloodHound AD), for Azure resource-level RBAC auditing without identity context, or for real-time threat detection (use Microsoft Defender for Identity). - Global Reader or Security Reader role in the target Microsoft Entra ID tenant - Microsoft Graph PowerShell SDK installed (Install-Module Microsoft.Graph) - Az CLI authenticated to the target tenant (az login --tenant TENANT ID) - ScoutSuite with Az…