Runbook 02 — Azure Identity Assessment
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook ID | GHC-AZ-RB-002 |
| Category | Cloud Identity Security |
| Platform | Microsoft Azure |
| Difficulty | Intermediate |
| Estimated Duration | 2–4 Hours |
| Owner | GoHackersCloud |
| Version | 1.0 |
Purpose
Section titled “Purpose”This runbook provides a structured methodology for reviewing Microsoft Entra ID and Azure Identity & Access Management (IAM) during an authorised Azure cloud security assessment.
The objective is to evaluate how identities are managed, determine whether the principle of least privilege has been implemented, and identify identity-related security risks that could increase organisational exposure.
Objectives
Section titled “Objectives”During this assessment you will:
- Review Microsoft Entra ID configuration.
- Assess Azure RBAC implementation.
- Review administrative accounts.
- Evaluate privileged access.
- Review Managed Identities.
- Assess Service Principals.
- Review Conditional Access implementation.
- Validate Multi-Factor Authentication.
- Identify identity-related security risks.
- Produce professional assessment documentation.
Assessment Scope
Section titled “Assessment Scope”The assessment includes:
- Microsoft Entra ID
- Users
- Groups
- Administrative Roles
- Azure RBAC
- Managed Identities
- Service Principals
- Enterprise Applications
- Conditional Access Policies
- Multi-Factor Authentication
- Privileged Identity Management (PIM)
- Authentication Methods
Prerequisites
Section titled “Prerequisites”Before beginning:
- Review customer scope.
- Confirm Rules of Engagement.
- Verify assessment permissions.
- Obtain read-only access where applicable.
- Prepare documentation templates.
Identity Assessment Workflow
Section titled “Identity Assessment Workflow”Review Identity Architecture
↓
Review Administrative Accounts
↓
Assess Azure RBAC
↓
Review Managed Identities
↓
Review Service Principals
↓
Review Conditional Access
↓
Validate MFA
↓
Identify Security Risks
↓
Document Findings
↓
Prepare ReportPhase 1 — Review Identity Architecture
Section titled “Phase 1 — Review Identity Architecture”Understand how identities are managed.
Review:
- Microsoft Entra ID Tenant
- Tenant configuration
- Domains
- Identity synchronization
- Hybrid identity (if applicable)
- Authentication methods
Document:
- Tenant overview
- Identity model
- Authentication architecture
Phase 2 — Review Users & Groups
Section titled “Phase 2 — Review Users & Groups”Assess:
- Administrative users
- Standard users
- Guest accounts
- Disabled accounts
- Emergency (“Break Glass”) accounts
- Security Groups
- Microsoft 365 Groups
- Dynamic Groups
Verify:
- Naming conventions
- Account ownership
- Account lifecycle
- Least privilege
Phase 3 — Administrative Role Assessment
Section titled “Phase 3 — Administrative Role Assessment”Review privileged roles including:
- Global Administrator
- Privileged Role Administrator
- Security Administrator
- User Administrator
- Cloud Application Administrator
- Authentication Administrator
- Billing Administrator
For each role verify:
- Number of assigned users
- Business justification
- Permanent assignments
- Temporary assignments
- Separation of duties
Phase 4 — Azure RBAC Assessment
Section titled “Phase 4 — Azure RBAC Assessment”Review Azure Role-Based Access Control.
Assess:
- Subscription Roles
- Resource Group Roles
- Resource Roles
- Built-in Roles
- Custom Roles
Verify:
- Owner assignments
- Contributor assignments
- Reader assignments
- Privileged custom roles
- Scope inheritance
Identify excessive permissions.
Phase 5 — Managed Identity Assessment
Section titled “Phase 5 — Managed Identity Assessment”Review:
- System-assigned Managed Identities
- User-assigned Managed Identities
- Associated resources
- Role assignments
- Resource permissions
Verify:
- Least privilege
- Resource ownership
- Unused identities
- Privileged identities
Phase 6 — Service Principal Assessment
Section titled “Phase 6 — Service Principal Assessment”Review:
- Enterprise Applications
- Application Registrations
- Client Secrets
- Certificates
- API Permissions
- OAuth Permissions
Identify:
- Over-privileged applications
- Unused Service Principals
- Long-lived credentials
- Excessive API permissions
Phase 7 — Conditional Access Assessment
Section titled “Phase 7 — Conditional Access Assessment”Review existing Conditional Access Policies.
Assess:
- MFA enforcement
- Trusted locations
- Device compliance
- Risk-based authentication
- Administrator protection
- Guest access controls
Document any gaps or inconsistencies.
Phase 8 — Multi-Factor Authentication Assessment
Section titled “Phase 8 — Multi-Factor Authentication Assessment”Review:
- MFA coverage
- Administrative MFA
- User MFA
- Authentication methods
- Passwordless authentication
- Legacy authentication controls
Identify accounts not protected by MFA.
Phase 9 — Risk Identification
Section titled “Phase 9 — Risk Identification”Evaluate the environment for:
- Excessive administrative privileges
- Privilege escalation opportunities
- Unused privileged accounts
- Weak identity governance
- Over-privileged Service Principals
- Inactive Managed Identities
- Weak authentication controls
- Missing Conditional Access
- Missing MFA
- Identity governance gaps
Evidence Collection
Section titled “Evidence Collection”Collect evidence for:
- Microsoft Entra ID configuration
- Azure RBAC assignments
- Administrative roles
- Managed Identity configuration
- Service Principal configuration
- Conditional Access Policies
- MFA configuration
- Authentication Methods
- PIM configuration
- Azure Portal screenshots
Risk Classification
Section titled “Risk Classification”For every finding document:
| Risk | Description |
|---|---|
| Critical | Immediate business impact requiring urgent remediation |
| High | Significant exposure affecting security posture |
| Medium | Moderate security weakness |
| Low | Minor configuration issue |
| Informational | Improvement opportunity or observation |
Deliverables
Section titled “Deliverables”At the end of the assessment prepare:
- Identity Assessment Report
- Administrative Role Review
- Azure RBAC Assessment
- Managed Identity Review
- Service Principal Review
- Conditional Access Assessment
- MFA Assessment
- Risk Register
- Executive Summary
- Technical Report
- Remediation Roadmap
Best Practices
Section titled “Best Practices”Always:
- Follow the Principle of Least Privilege.
- Minimise permanent administrative access.
- Use Privileged Identity Management (PIM).
- Enable Multi-Factor Authentication.
- Review Service Principals regularly.
- Remove unused accounts.
- Monitor privileged activity.
- Protect emergency access accounts.
- Apply Conditional Access consistently.
- Document every observation.
Success Criteria
Section titled “Success Criteria”The assessment is complete when:
- Identity architecture has been reviewed.
- Administrative roles have been validated.
- Azure RBAC has been assessed.
- Managed Identities have been reviewed.
- Service Principals have been assessed.
- MFA coverage has been validated.
- Conditional Access has been reviewed.
- Findings have been prioritised.
- Reports have been completed.
Related Lessons
Section titled “Related Lessons”- Lesson 03 — Microsoft Entra ID Fundamentals
- Lesson 08 — Azure Identity & Access Attack Surface
- Lesson 11 — Azure Offensive Security Methodology
Related Labs
Section titled “Related Labs”- Lab 01 — Microsoft Entra ID Assessment
- Lab 04 — Azure Privilege Escalation Assessment
- Lab 05 — Enterprise Azure Cloud Penetration Test
Next Runbook
Section titled “Next Runbook”➡️ Runbook 03 — Enterprise Azure Security Review
In the next runbook, you will perform a complete enterprise Azure security review by combining identity, networking, compute, storage, monitoring, governance, and reporting into a comprehensive cloud security assessment suitable for consulting engagements.