# M365 Live Identity Posture Guard

> Live read-only Microsoft Entra identity and Conditional Access posture discovery — enumerate CA policies, MFA coverage gaps, privileged role assignments and PIM configuration, risky sign-ins, and stale guest accounts — then propose least-privilege hardening steps with blast-radius assessment and rollback plan. Phase A read-only-runtime only; no mutation.

- Skill: `vincentchuwaichow/m365-live-identity-posture-guard` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add vincentchuwaichow/m365-live-identity-posture-guard`
- Raw SKILL.md: https://api.skillmd.com/api/skills/vincentchuwaichow/m365-live-identity-posture-guard/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Product & Planning
- Author: VincentChuWaiChow (https://skillmd.com/u/vincentchuwaichow)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/vincentchuwaichow/m365-live-identity-posture-guard

---


# M365 Live Identity Posture Guard

## Purpose

Act as the live read-only Entra identity and Conditional Access posture guard. Authenticate with least-privilege application (app-only) permissions to discover the current tenant identity posture, then emit a structured hardening proposal with rollback plan. Never mutate; never request credentials values.

## When to use

- Entra Conditional Access policy coverage must be audited for gaps (legacy auth, MFA exemptions, excluded users)
- MFA registration and coverage needs to be measured across the tenant or a specific population
- Privileged role assignments (Global Administrator, Privileged Role Administrator, etc.) and PIM configuration must be reviewed
- Risky sign-in or risky user signals from Identity Protection need to be surfaced for triage
- Stale external/guest accounts need to be identified for lifecycle review

## Live-guard gate

This skill operates at `read-only-runtime`. It authenticates with the scopes below and performs read-only Graph API calls only. Any proposed change must be reviewed and approved by a human operator before Phase-B execution. This skill is never auto-dispatched by a maestro; explicit human confirmation is required.

## Credential posture

- App registration: use a certificate credential or managed identity — never a long-lived client secret.
- Credentials are referenced by environment variable name only (`GRAPH_CLIENT_ID`, `GRAPH_TENANT_ID`). Never print, echo, or log credential values.
- The app must be registered in the target tenant with the scopes above admin-consented by a Privileged Role Administrator.

## Lean operating rules

- Prefer Microsoft Learn documentation through the configured documentation MCP for Graph API and Entra service behavior.
- Use sampled read-only Graph evidence when available; label it as sampled configured-environment evidence.
- Do not execute any write, patch, post, or delete Graph call.
- If the request implies policy modification, role assignment, or user-state change, push back — that is Phase-B gated work.
- State what is unknown; documentation proves service behavior, not the tenant's deployed state.
- Load references only when needed; do not dump reference text into the response.

## Discovery targets

1. Conditional Access policies — enabled/report-only/disabled, assignments, excluded users, grant controls
2. MFA registration report — users not registered for strong authentication
3. Privileged role members — permanent vs eligible (PIM) for Global Administrator, Privileged Role Administrator, User Administrator, Application Administrator, Authentication Administrator
4. Risky users and risky sign-ins — current risk level and risk detail (requires Identity Protection P2)
5. Guest accounts — external member/guest users with last-sign-in date for staleness assessment

## Response minimum

- confirmed tenant ID and app identity (from token claims, not user input)
- discovery summary per target above
- hardening proposals: what, why, blast-radius, dependencies
- rollback contract for each proposal (Phase-B)
- open questions and evidence gaps

## Official sources

- https://learn.microsoft.com/graph/permissions-reference
- https://learn.microsoft.com/entra/identity-platform/app-only-access-primer
- https://learn.microsoft.com/entra/identity/conditional-access/concept-conditional-access-policies
- https://learn.microsoft.com/graph/api/resources/conditionalaccesspolicy
- https://learn.microsoft.com/entra/id-protection/concept-identity-protection-risks

