Entra ID security review in Brisbane.
A review of the Entra ID and Microsoft 365 tenant your business signs in to: conditional access, privileged roles, app consent and offboarding, scoped and debriefed at our Brisbane office or by video call.
Black Shard is an Australian software engineering and cybersecurity firm headquartered on Eagle Street in Brisbane. Most Australian businesses run identity through Microsoft Entra ID and Microsoft 365, where a compromised password, an over-permissioned application or a missed offboarding step gives an attacker a valid sign-in. An Entra ID security review examines that tenant: conditional access, multi-factor authentication, privileged roles, app consent and offboarding.
Black Shard operates Azure and Microsoft 365 tenants in production for its own systems and for client organisations. Findings are manually verified before they are reported, and the remediation plan is tied to controls already in the Microsoft 365 licence.
What the review covers
Conditional access and multi-factor authentication coverage is checked across every account that matters, including the break-glass accounts that exist for when everything else fails and are often left unmonitored or unprotected. Privileged roles are audited in full: who holds Global Administrator and the other high-impact roles, whether each assignment is still justified, and whether access is standing or granted just in time.
App consent is reviewed the same way: which third-party and internal applications users have granted access to the tenant, what permissions those grants carry, and whether any are broad enough that a single phishing click becomes a mailbox-wide compromise. Offboarding closes the loop: whether a departing user's access is removed on the day they leave, and whether the tenant can be recovered if an administrator account is lost. For an organisation on Microsoft 365, valid credentials or a consented application reach mailbox rules, file shares and Teams conversations directly, which is why these controls carry the weight they do.
- Conditional access and MFA coverage across every account that matters, including break-glass accounts
- Privileged-role audit: who holds high-impact roles, and whether each assignment still stands up
- App-consent audit across the tenant, including over-broad third-party grants
- Offboarding: whether access is removed the day someone leaves
- Recovery readiness, so a lost administrator account cannot lock the business out
- Legacy authentication, guest accounts and dormant accounts
How this differs from an Azure security review
The Azure security review covers identity as one area alongside privilege, networking, secrets, logging and workload configuration, and for many tenants that depth is sufficient. The Entra ID review examines the Microsoft 365 identity estate on its own: every conditional access policy, every privileged role, every app consent, and the offboarding and recovery processes around them.
If it is unclear which fits, say so in the brief and we will recommend the scope.
Scoping and debrief in Brisbane
Scoping decides what the review covers. At Eagle Street it can run across a table: licence count, guest accounts, whether break-glass accounts exist yet. The debrief can run the same way, with the engineer who did the review walking through the path from a compromised account to something that matters, and where remediation should start.
Both also run by video call. Access to the tenant is reader-level and scoped to the engagement: typically Global Reader in Entra ID with read access to Conditional Access policies and Enterprise Applications, agreed at scoping and removed when the review ends. Black Shard holds SMB1001:2026 Gold, verifiable on CyberCert's registry.
What does an Entra ID security review cost?
No figure is published. Effort is driven by the size of the identity estate: how many users, guest accounts and privileged roles the tenant carries, and how many third-party applications have been granted access over the years.
The engagement runs with a defined target, timeframe and deliverable agreed before work starts. Send a brief to info@blackshard.com.au with the rough shape of the tenant.
Do you only review Brisbane tenants?
No. The review runs Australia-wide from the Brisbane head office, with scoping and the debrief by video call.
Questions, answered
- What access do you need to our tenant?
- Reader-level roles scoped to the review, typically Global Reader in Entra ID with read access to Conditional Access policies and Enterprise Applications, agreed at scoping and removed when the engagement ends.
- Is this the same as your Azure security review?
- No, though they overlap. The Azure review covers identity as one area across the whole tenant. This review goes deeper into Entra ID and Microsoft 365: conditional access, privileged roles, app consent and offboarding. Describe the situation in the brief and we will recommend the scope.
- Can you fix what you find?
- Yes. Black Shard is a software engineering firm as well as a cybersecurity firm, so remediation can run as advisory support or hands-on configuration change after the review. The plan is written so your own team can execute it.
- How long does a review take?
- It runs as a fixed-scope engagement, with the target, timeframe and deliverable agreed before work starts. The size of the identity estate (users, guest accounts, privileged roles and app consents) drives the effort.
- Do you review break-glass accounts?
- Yes. Break-glass accounts exist for when everything else fails, which makes them among the most consequential accounts in a tenant. We check whether they exist, how they are protected, and whether anyone would notice if one were used.
- Do you only work with Brisbane businesses?
- No. Black Shard is an Australian firm headquartered in Brisbane and delivers Australia-wide. The review runs the same way either way; Brisbane businesses have the option of an in-person debrief.
Related reading
Entra ID security review, Australia-wide
Azure security review
vCISO services
Cyber security company in Brisbane
The full practice: Security advisory & vCISO.
Tell us what you need built, reviewed or secured.
Brisbane head office. Work delivered across Australia.