Microsoft Entra ID Security Assessment
Service Overview ⫘
The Secureworks Entra ID Security Assessment (ESA) enables you to leverage the experience and insights of the Secureworks Incident Response team to understand how attackers can exploit Microsoft Entra ID configuration to achieve their objectives.
Service Methodology ⫘
Secureworks will provide step-by-step instructions for you to provision a read-only account in your Entra ID environment to be used for this service. Secureworks uses this account to collect the Entra ID configuration data required to perform the technical assessment.
Secureworks will examine the following:
- Access controls
- Identity management
- Authentication methods
- Application consent settings
- Compliance with industry best practices
- Attack paths between Entra ID and Active Directory
The ESA is performed remotely (through online collaboration tools) and consists of an initial meeting, the assessment process, and a debrief. Additionally, a final report will be delivered to your point of contact.
Outcome ⫘
Secureworks will provide a point-in-time evaluation of the security of your organization’s Entra ID configuration. The outcome of the evaluation will consist of the following:
- Actionable recommendations to rectify identified deficiencies
- Recommendations for further strengthening Entra ID and Active Directory security, based on Secureworks' and industry-accepted best practices
- Identification of design flaws and vulnerable configurations
- Risk-prioritized action items and remediation guidance that includes levels of effort to implement
- Virtual debrief session with your key stakeholders to review findings and recommendations as well as provide a forum for customer-driven question and answer session
Scoping Information ⫘
Scope | Description |
---|---|
Microsoft Entra ID Security Assessment - Small | Assessment of up to 2 Entra ID tenants |
Microsoft Entra ID Security Assessment - Medium | Assessment of up to 5 Entra ID tenants |
Microsoft Entra ID Security Assessment - Large | Assessment of up to 10 Entra ID tenants |
Complex environments, optional service elements, and onsite visits may require additional Service Units and will be estimated in advance of engagement commencement.
Scheduling and Booking Information ⫘
See Service Scheduling for information about scheduling this service.