The Microsoft Entra Quarterly Check-In exists for moments like this. It’s the rhythm that reveals hidden shifts in your identity and access landscape. Once every quarter, you dig into what changed, what broke, and what’s quietly growing into a risk.
Start with conditional access policies. Audit every one. Remove or update those tied to old projects or unused apps. Then move to role assignments—check who got new privileges in the last three months and make them justify the request. Look at guest accounts. If they haven’t logged in since last quarter, cut them loose.
Next, examine sign-in logs for patterns. Failed login attempts in odd geographies, sudden spikes in API calls, or unfamiliar devices connecting at scale—these often show up in hindsight after major incidents. Don’t wait for hindsight.