Black Shard

Microsoft Azure security review.

Azure and Entra ID environments reviewed across identity, privilege, networking, secrets, logging and workload configuration, using read-only access wherever possible.

We review Azure and Entra ID environments across identity, privilege, networking, secrets, logging and workload configuration. The engagement uses read-only access wherever possible. Findings are prioritised by the risk they create in your environment and mapped to the Azure controls required to address them.

Black Shard runs production workloads on Azure in the Australia East region. Aurii, a clinical software platform the firm built and operates, runs on Container Apps with PostgreSQL row-level security isolating tenant health data, Key Vault for secrets, and GitHub Actions deploying through workload identity federation so no long-lived credential sits in the pipeline. Client tenants are reviewed against the same configuration decisions.

What the review covers

Each area is assessed against what the tenant runs, who touches it, and what an attacker positioned inside it could reach.

  • Identity: privileged role assignments in Entra ID, conditional access coverage, multi-factor authentication on administrative accounts, guest and dormant accounts, legacy authentication, and every service principal holding a credential.
  • Privilege: Owner and Contributor assignments at subscription scope, service principals holding more than their job requires, and access that outlived the project that justified it.
  • Networking: what is internet-facing and why, public network access on storage and database endpoints, network security group rules, and where private endpoints should replace public exposure.
  • Secrets: where credentials live, Key Vault usage and access policies, secrets in app settings, pipeline variables or code, rotation, and whether deployments authenticate through workload identity federation or long-lived client secrets.
  • Logging: diagnostic settings across subscriptions, activity and sign-in log retention, and whether the telemetry exists to detect an attack while it is happening and reconstruct it afterwards.
  • Workload configuration: resource-level settings on storage accounts, databases, container platforms and TLS, checked against the platform's own hardening guidance.

What the review produces

Two documents. The findings report records where the tenant stands, with each finding manually verified and the evidence to reproduce it. The remediation plan lists what to change, in what order, using controls the tenant already licenses: Entra ID conditional access, Azure Policy, Key Vault, private endpoints, diagnostic settings, and Defender for Cloud where it applies.

Findings are ordered by the risk they create in the environment, so remediation starts with the changes that remove the most exposure. The plan is written for the team that will do the work.

Common findings

The same patterns recur. Privilege accretes: an Owner assignment handed out during a migration is still there years later, attached to an account nobody has reviewed. Service principals carry client secrets that never expire, created before workload identity federation was available. Secrets drift out of Key Vault into app settings, pipeline variables and the occasional repository.

On the network side, storage accounts keep public network access because an integration needed it once. Legacy authentication stays enabled for one workload nobody can name. Diagnostic settings were never configured, so when something happens the activity log has aged out and there is nothing to investigate. Underneath sits ambiguous ownership: a tenant stood up by a partner who has since moved on, with nobody inside the organisation holding the whole picture.

How the review runs

Scoping records the tenancy layout, the workloads that matter and the obligations the organisation carries. Access is read-only wherever possible: typically Global Reader in Entra ID and Reader at the relevant subscription scopes, agreed at scoping and removed when the engagement ends. The timeframe is agreed before work starts, and the review is delivered remotely.

It runs as a one-off assessment or as the opening of an ongoing advisory arrangement. Remediation can follow as advisory support or hands-on engineering. Black Shard holds SMB1001:2026 Gold, verifiable on CyberCert's public registry, and self-assesses against the ASD Essential Eight at Maturity Level 2.

How much does an Azure security review cost?

No rate card is published. Effort is driven by the number of subscriptions and environments, the workload running in the tenant, and the size of the identity estate: users, service principals and privileged roles.

Scope, timeframe and deliverable are agreed before any work starts. Send a brief to info@blackshard.com.au with the shape of the environment.

Questions, answered

What access do you need to our tenant?
Reader-level roles scoped to the review: typically Global Reader in Entra ID and Reader at the relevant subscription scopes, agreed at scoping and removed when the engagement ends. Write access is not required to run a review.
How long does an Azure security review take?
The review runs as a fixed-scope engagement, with the target, timeframe and deliverable agreed before work starts. Subscriptions, environments and workload count drive the effort; a single-subscription tenant reviews faster than a multi-subscription estate.
Is this an audit or a certification?
No. It is an engineering review of the tenant and carries no certificate. Black Shard holds SMB1001:2026 Gold, verifiable on the CyberCert public registry, and works against the ASD Essential Eight as a framework. If certification is the goal, the review's findings feed compliance readiness work.
We already have Defender for Cloud and a secure score. Do we still need a review?
Secure score is read as part of the review. It does not judge whether a permission is proportionate to its purpose, whether an exposure is deliberate, or whether anyone would act on an alert. The review adds that judgement.
Do you review Entra ID as part of this?
Yes. Entra ID is the identity control plane of the tenant, so privileged roles, conditional access, service principals and their credentials are in scope by default. Where the Microsoft 365 identity estate needs examining on its own, the Entra ID security review is the deeper engagement.
Can you fix what you find?
Yes. Black Shard is a software engineering firm as well as a cybersecurity firm, so remediation can run as advisory support or hands-on engineering after the review. The plan is also written so your own team can execute it.

Tell us what you need built, reviewed or secured.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au