September 12, 2026

Who Has Access to What: Where a Cloud Security Assessment Actually Starts

In cloud environments the perimeter is identity, not the network. What a posture assessment examines, why a findings list is not a risk assessment, and what you should expect to receive.
An access matrix where most accounts hold a few permissions and two hold nearly all of them

An assessment that starts with the firewall is looking in the wrong place. In cloud environments the perimeter is identity, and the findings that carry real risk are almost always in the account list: who holds administrator rights, who kept access after changing roles, and which accounts nobody can name an owner for.

The short answer

Count your Global Administrators, check whether legacy authentication is blocked, and review who is excluded from your conditional access policies. If those three answers surprise you, an assessment will find more.

Why identity, not the network

The traditional model assumed a boundary. Inside was trusted, outside was not, and the firewall decided which was which.

A Microsoft 365 tenant has no such boundary. Staff sign in from home, from a client site, from a phone on mobile data. The thing deciding whether a request is legitimate is not its network location but the credential presenting it.

Which means the controls that matter are the ones governing accounts: what they can do, how they prove who they are, and whether anyone reviews them.

What an assessment actually examines

Privileged roles

How many Global Administrators exist, and can each be named and justified? Two to four is the range most organisations should sit in. We regularly find double figures, often including a former consultant and a service account created during a migration years ago.

Conditional access

Which policies exist, which are actually enabled, and which have been sitting in report-only since a pilot that ended months ago. A tenant can display a respectable list of policies and enforce none of them.

Legacy authentication

Whether protocols that cannot present a multifactor challenge are blocked tenant-wide. This is the single highest-value identity control available, it is free, and it is frequently still open.

MFA registration coverage

A policy requiring multifactor authentication only protects users who have registered a method. Unregistered users get excluded to unblock them, and the exclusion outlives the reason.

Application permissions

Which applications hold tenant-wide Microsoft Graph permissions. An application with directory write access or mailbox read access holds it permanently, without multifactor authentication, and appears in no user access review. Compromised application credentials are among the hardest intrusions to detect.

Guest and service accounts

What guests can read in your directory, who can invite them, and which service accounts exist with no named owner and no expiry.

Stale accounts

Accounts enabled but unused for months. Departed staff and old contractors are a recurring finding, and they are the accounts nobody is watching.

Findings are not the same as risk

A scanner produces a list ranked by severity score. That score is calculated without knowing anything about your environment.

A finding scored medium may be the first link in a chain leading straight to your tenant administrator. A finding scored high may be irrelevant because the affected service is not reachable and holds nothing.

What makes an assessment useful is the judgement applied afterwards: which of these findings could an attacker realistically use, in what order, and what would they reach? That is the difference between a report you act on and a report you file.

What you should receive

  • Findings ranked by exploitability in your environment, not by a generic severity score
  • Specific remediation steps, naming the setting and where to change it
  • Clear identification of anything that could not be checked, and why
  • Mapping to a recognised benchmark such as CIS Microsoft 365 Foundations
  • A retest or verification path, so you can confirm the fixes landed

The third point is worth insisting on. If a permission was missing and a check could not run, that must appear as "not assessed" rather than quietly as a pass. A gap reported as clean is worse than no report.

How this differs from a penetration test

A posture assessment reads configuration and reports what is exposed. A penetration test attempts to exploit it and reports what an attacker achieved.

For most organisations that have never assessed their environment, configuration review finds more real risk, costs considerably less, and produces fixes you can make the same week. Testing is worth commissioning afterwards, once the obvious is closed.

Frequently asked questions

Will an assessment disrupt anything?

No. It reads configuration through the Microsoft Graph API using read-only permissions. Nothing is changed and no system is taken offline.

What access do you need?

Read-only application permissions, granted by an administrator through Microsoft's own consent screen. No password is shared and consent can be withdrawn at any time from your Enterprise applications blade.

How long does it take?

Collection takes minutes. The valuable part is the analysis and the conversation about which findings matter in your context, which is usually a week end to end.

How often should we repeat it?

Annually as a baseline, and after any significant change: a migration, a merger, a new line-of-business application, or a change of IT provider. Tenants drift, and exclusions accumulate.

Does this help with Data Privacy Act compliance?

It produces evidence of the technical security measures the National Privacy Commission expects to see, particularly around access control. Documented findings with remediation records demonstrate that you assessed your risks and acted; an untested policy document does not.

Where to start

Onprem2Cloud IT Solutions Co. is a Microsoft Cloud Solution Provider based in Muntinlupa City, serving businesses and government agencies across Metro Manila and beyond. Our cloud security posture assessments cover Microsoft 365 and Azure environments, mapped to the CIS Microsoft 365 Foundations Benchmark and ranked by exploitability.

See our cybersecurity services, or get in touch to discuss an assessment of your tenant.