5 things the best IT leaders know about their Microsoft tenant

I have been inside a lot of Microsoft tenants. The weakness is rarely in the setup, but in everything that has happened since. Nobody builds a messy tenant on purpose, it just ends up that way, a bit like the garage.
People join and leave, consultants are never offboarded, and apps live on after the project has ended. Our health check runs 18 checks across security, compliance and cost. The best IT leaders I've met know where the mess is. Here are the five things they keep track of.
1. You need to know how big your attack surface is, and how well it is protected
Ten years ago, identity was about employees. Today it also covers guests, devices, apps and AI agents. Our sample report shows a fictional organization with 4,260 employees, 465 guests, 3,470 devices, 384 apps and 68 agents. Only the employees have an HR process that automatically brings them in and takes them out.
The next question is who can change the tenant. An admin role that is always active means one wrong click or one stolen sign-in can hit the entire tenant. We also look for guests with admin roles. Their accounts follow another organization's policy, so you don't know whether they are used by the right person or have been compromised.
2. MFA being required doesn't mean everyone has it
Most organizations require MFA with Conditional Access, regardless of size, industry and region. The question is whether users have actually registered it. An account without MFA is asked to register at the next sign-in, and then whoever knows the password can add their own phone. A policy in Report-only doesn't enforce anything either.
Three gaps show up in almost every tenant. Old accounts, often with privileged roles, waiting for someone to guess the password. Old trusted locations that exempt entire networks from the rules, so a guessed password is enough. And very few protect the registration itself with a location requirement or a Temporary Access Pass (TAP).
We also check who only has SMS or voice. A phone number can be moved with a SIM swap, and one-time codes can be relayed through a fake sign-in page. A passkey can be neither moved nor relayed. From February 2027 these users must register a passkey before they can sign in, so it's worth knowing who they are now.
3. The identities that aren't people are growing fastest
Employees have a manager and an end date. Apps, agents and guests have neither. They are created to solve a task, and nothing deletes them when the task is done.
In the sample, 37 percent of the apps have no owner. The oldest is called "Payroll Export (legacy)" and dates from 2019. Nobody knows who owns it, and nobody dares to delete it.
The agents are growing fastest. They are built in Copilot Studio, often by people who don't work with identity, and they act on their own with their own keys. One conference speaker compared them to a tiger cub: small and cute at first, but more dangerous with every month out of control. Set ownership now, while the numbers are small.
For guests, the sponsor plays the role of owner. Without a sponsor, an access review has no one to ask.
4. Accounts and devices don't leave when people do
An account nobody uses is an account nobody watches. Go through inactive users with their manager and disable them. A disabled account can't sign in, and it's quick to enable again if someone needs it.
Devices stay in Entra long after they have been retired. Disable before you delete, because the recovery keys for disk encryption are stored on the device object.
5. How much are you spending on licenses you don't need?
Money spent on unused licenses can be freed up for other initiatives. An unused E5 license never complains. It just sends an invoice every month.
In the sample, 380 paid licenses sit unused, 756 licensed users haven't signed in for three months, and 32 disabled users still have a license. Start with the disabled users, where the decision has already been made. If the mailbox still needs to be readable, convert it to a shared mailbox. It doesn't need a license. Inactive users may be on leave, so send the list to their managers. Do this on an ongoing basis, not just before renewal. A freed license can go to the next new hire, so you don't have to buy more on a fixed term. Whatever you still have left over, you cut at renewal.
How to find this in your own tenant
You won't find these five things in one place, and they rarely raise an alert. You can find them by clicking through the portal and putting together reports from several places, but it takes time. Our health check does the same in under five minutes.
It's free and needs one consent from an administrator. It only reads, and your data never leaves your browser. You get a score from 0 to 100, and every finding comes with what you should do.
Take the health check at healthcheck.bsure.io
If you'd like help prioritizing, we're happy to do a 30-minute walkthrough. You don't need to clean up everything today. What the best IT leaders have in common is that they know where the mess is and where to start.
Hear when the next article is out
Our newsletter tells you when a new article is out. About once a month.






