Microsoft EntraID logo

Microsoft EntraID

AccessPeople
Access & Identity

Mycroft reads Entra ID users, groups, directory roles and conditional access policies to build the account inventory behind access reviews.

Entra ID is the identity boundary for Microsoft 365, Azure and anything federated to it. Mycroft reads both what conditional access requires and who is excluded from it, and inventories guest accounts separately.

How Mycroft connects to Entra ID

How it connects
A directory administrator authorizes the connection.
What Mycroft can access
Read-only directory data: the user roster behind access reviews and the personnel controls.

Which controls Entra ID evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Entra ID to satisfy it. Collection runs on a schedule and every result is timestamped.

Microsoft EntraID compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Entra ID
SOC 2CC6.1Logical access controls restrict access to information assets.User, group and application assignment inventory, directory role holders, and service principal inventory with their granted permissions.
SOC 2CC6.2Access is authorized before credentials are issued and reviewed periodically.Account creation events matched to HRIS hire dates, plus completed access review records covering every account and its reviewer decision.
SOC 2CC6.3Least privilege is enforced and access removed when no longer needed.Account disablement and deletion events with timestamps, guest account inventory with last sign-in, and the measured removal interval against your offboarding SLA.
SOC 2CC6.7Authentication mechanisms protect against unauthorized access.Conditional access policy inventory with their assignments, exclusions and grant controls; authentication method registration per user; legacy authentication block status.
ISO 27001A.5.16The full identity lifecycle is managed.Directory audit log records for create, enable, disable and delete operations on every identity, with actor and timestamp.
ISO 27001A.5.17Authentication information is managed securely.Registered authentication methods per user, identification of users without a strong second factor, and self-service password reset configuration.
ISO 27001A.8.2Privileged access rights are restricted and controlled.Global Administrator and other privileged directory role holders, whether roles are permanent or assigned through Privileged Identity Management, and MFA state for each.
ISO 27001A.5.18Access rights are provisioned, reviewed and revoked.Periodic access review records with reviewer, decision, exception and completion date for every account in scope.
HIPAA§164.308(a)(4)Access to ePHI is authorized, established and modified under policy.Group and role membership history for accounts with access to regulated workloads, with the authorization record for each change.
HIPAA§164.308(a)(3)(ii)(C)Access is terminated when workforce membership ends.Disablement timestamp per departure, reconciled against the HRIS termination date and the removal of downstream accounts.

What Mycroft collects automatically

Gathered from Entra ID on a schedule, dated and stored against the controls above.

  • User roster with account status, licences, group membership and last sign-in
  • Directory role assignments, including Global Administrators and PIM-eligible roles
  • Conditional access policies with assignments, exclusions and grant controls
  • Authentication method registration per user, and users without a strong factor
  • Guest and external identity inventory with sponsor and last activity
  • Service principal and enterprise application inventory with granted API permissions
  • Legacy authentication status and security defaults configuration
  • Directory audit events for account creation, enablement, disablement and deletion

Manual work this removes

The tasks that disappear from someone's quarter once Entra ID is connected.

  • Exporting user lists from the portal and consolidating them for review
  • Reading each conditional access policy to determine who is excluded from MFA
  • Tracking guest accounts invited for projects that have ended
  • Screenshotting the Global Administrator list at audit time
  • Reconciling the leaver list against disabled accounts each quarter

Entra ID and Mycroft: frequently asked questions

It is read-only directory data: the user roster behind access reviews and the personnel controls. The exact permission set depends on how the tenant is connected, and Mycroft confirms it as part of a security review.
No, and most teams need both. Entra ID covers identity: users, groups, roles, conditional access and the workforce roster behind access reviews. The Azure integration covers subscription infrastructure: encryption, networking, RBAC on resources and Defender findings. They answer different audit questions.
By reading both sides. Conditional access policies show what is required and, importantly, who is excluded; authentication method registration shows what each user has actually enrolled. A policy that mandates MFA with a standing exclusion group is a finding, and that is precisely the gap a screenshot of the policy alone would hide.
Yes, and separately, because they behave differently. Guest identities are inventoried with their sponsor and last activity so an access review can act on them. External accounts that outlive the project they were invited for are among the most common findings in a first audit.
Yes. Where PIM is in use, Mycroft distinguishes permanent role assignments from eligible ones, which materially strengthens the privileged access evidence under ISO 27001 A.8.2. A role that must be activated with justification is a stronger control than one held permanently, and the evidence should reflect that.

We turn the compliance nightmare into a dream

Talk to us