
Microsoft EntraID
AccessPeople
Access & Identity
Mycroft reads Entra ID users, groups, directory roles and conditional access policies to build the account inventory behind access reviews.
Entra ID is the identity boundary for Microsoft 365, Azure and anything federated to it. Mycroft reads both what conditional access requires and who is excluded from it, and inventories guest accounts separately.
How Mycroft connects to Entra ID
- How it connects
- A directory administrator authorizes the connection.
- What Mycroft can access
- Read-only directory data: the user roster behind access reviews and the personnel controls.
Which controls Entra ID evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Entra ID to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Entra ID |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | User, group and application assignment inventory, directory role holders, and service principal inventory with their granted permissions. |
| SOC 2 | CC6.2 | Access is authorized before credentials are issued and reviewed periodically. | Account creation events matched to HRIS hire dates, plus completed access review records covering every account and its reviewer decision. |
| SOC 2 | CC6.3 | Least privilege is enforced and access removed when no longer needed. | Account disablement and deletion events with timestamps, guest account inventory with last sign-in, and the measured removal interval against your offboarding SLA. |
| SOC 2 | CC6.7 | Authentication mechanisms protect against unauthorized access. | Conditional access policy inventory with their assignments, exclusions and grant controls; authentication method registration per user; legacy authentication block status. |
| ISO 27001 | A.5.16 | The full identity lifecycle is managed. | Directory audit log records for create, enable, disable and delete operations on every identity, with actor and timestamp. |
| ISO 27001 | A.5.17 | Authentication information is managed securely. | Registered authentication methods per user, identification of users without a strong second factor, and self-service password reset configuration. |
| ISO 27001 | A.8.2 | Privileged access rights are restricted and controlled. | Global Administrator and other privileged directory role holders, whether roles are permanent or assigned through Privileged Identity Management, and MFA state for each. |
| ISO 27001 | A.5.18 | Access rights are provisioned, reviewed and revoked. | Periodic access review records with reviewer, decision, exception and completion date for every account in scope. |
| HIPAA | §164.308(a)(4) | Access to ePHI is authorized, established and modified under policy. | Group and role membership history for accounts with access to regulated workloads, with the authorization record for each change. |
| HIPAA | §164.308(a)(3)(ii)(C) | Access is terminated when workforce membership ends. | Disablement timestamp per departure, reconciled against the HRIS termination date and the removal of downstream accounts. |
What Mycroft collects automatically
Gathered from Entra ID on a schedule, dated and stored against the controls above.
- User roster with account status, licences, group membership and last sign-in
- Directory role assignments, including Global Administrators and PIM-eligible roles
- Conditional access policies with assignments, exclusions and grant controls
- Authentication method registration per user, and users without a strong factor
- Guest and external identity inventory with sponsor and last activity
- Service principal and enterprise application inventory with granted API permissions
- Legacy authentication status and security defaults configuration
- Directory audit events for account creation, enablement, disablement and deletion
Manual work this removes
The tasks that disappear from someone's quarter once Entra ID is connected.
- Exporting user lists from the portal and consolidating them for review
- Reading each conditional access policy to determine who is excluded from MFA
- Tracking guest accounts invited for projects that have ended
- Screenshotting the Global Administrator list at audit time
- Reconciling the leaver list against disabled accounts each quarter
Entra ID and Mycroft: frequently asked questions
What Graph permissions does Mycroft need for Entra ID?
Is Entra ID the same as the Azure integration?
How does Mycroft evidence MFA enforcement in Entra ID?
Does this cover guest and external accounts?
Can Mycroft use Privileged Identity Management data?
We turn the compliance nightmare into a dream
Talk to us


