The whole Entra baseline compressed into a list you can run down in an afternoon. Every action the reasoned articles defended, grouped by the eight control-plane domains and tiered by obligation.
This is the whole Entra baseline compressed into a list you can run down in an afternoon. Every action the reasoned articles defended, with what to set and how to check it, grouped by the eight control-plane domains and tiered by obligation. If you read nothing else in this wave and act on one thing, make it this. Where you want the argument behind a line, the last column points to the article that makes it.
Read the tiers as levels of obligation, not difficulty. C is critical, the controls I will not hand over a tenant without. R is recommended, the professional default you deviate from only deliberately. O is optional, genuine preference. A P1 or P2 marks an item that needs that Entra ID licensing tier. A few verification strings, the guest-access role identifier and one or two portal-only settings, should be confirmed against your own tenant, because Microsoft moves the underlying identifiers occasionally. One more thing about the tiers, because it decides how this list gets used. Not applicable, with a written reason, is a legitimate outcome for any row here. The tiers exist to force the decision into the open, not to force the control into a tenant it does not fit, and a checklist that leaves an admin no honest way to say no gets a control implemented against the operating model or gets the row quietly skipped.
1. Privileged access
Tier
Do this
How to verify
See
C
Provision two or more break-glass accounts, cloud-only on the onmicrosoft.com domain
Accounts exist, not synced, permanent Global Admin
BP 1.1
C
Exclude break-glass from every blocking Conditional Access policy, including managed ones
Excluded via a dedicated group on each enforce policy
BP 1.1
C
Create break-glass before enabling any Conditional Access
Accounts and exclusions exist before the first enforce policy
BP 1.3
C
Credential break-glass with a passkey or certificate, not a stored password
FIDO2 or certificate method registered on each account
BP 1.1
R
Use break-glass accounts only from a privileged access workstation or an equivalent secured admin device
A named workstation, recorded alongside the credential custody procedure
BP 1.1
C P1
Alert on every break-glass sign-in
A sign-in alert fires within minutes on each account
BP 1.1
R
Validate break-glass sign-in at least every 90 days; rotate on use, on suspected exposure, or on personnel change, not on a calendar
A dated sign-in test on each account, and credentials configured not to expire
BP 1.1
C
Keep Global Administrators to two or more and fewer than five, all cloud-only
Role membership count and no synced members
BP 1.1
R
Assign finer-grained roles instead of Global Administrator
Role-assignment audit favors scoped roles
BP 1.1
C P2
Eliminate standing active assignments for privileged roles; make them eligible
No standing active assignments in PIM
BP 1.1
R P2
Require approval to activate Global Administrator
PIM activation approval rule set
BP 1.2
R P2
Require phishing-resistant MFA at PIM activation
PIM activation MFA rule set
BP 1.2
R P2
Alert on privileged assignment and activation
PIM alerts enabled and routed
BP 1.2
R P2
Run recurring access reviews on privileged roles
Quarterly PIM access review configured
BP 1.2
O P1
Protect Tier-0 objects with restricted-management administrative units
Break-glass and admins in a restricted AU
BP 1.2
2. Identity and access
Authentication methods
Tier
Do this
How to verify
See
C
Complete the authentication-methods policy migration
Migration state shows Complete
BP 1.1
C
Enable passkey (FIDO2) as an authentication method
FIDO2 method state enabled
BP 1.1
C
Disable SMS and voice call as authentication methods
Both method states disabled; Microsoft-provided delivery retires 1 February 2027 either way
BP 1.1
C
Decide email one-time passcode deliberately on both of its faces: a self-service reset method for members, and separately a sign-in method for guests
The method cannot report disabled while the external-users email OTP setting is on, so check that setting and not the method state alone
BP 1.1
R
Show application name and location in Microsoft Authenticator
Both feature settings enabled
BP 1.2
R
Keep system-preferred MFA on
System-preferred state enabled
BP 1.2
R
Enable Temporary Access Pass for onboarding and recovery
TAP method enabled
BP 1.2
R
Run a registration campaign toward Authenticator and passkeys
Campaign set to Microsoft-managed or on
BP 1.2
O
Deploy Windows Hello for Business or device-bound passkeys where warranted
Policy enabled for managed Windows
BP 1.2
MFA and the Conditional Access baseline
Tier
Do this
How to verify
See
C P1
Require MFA for all users
An enabled CA policy grants require MFA
BP 1.1
C P1
Require a phishing-resistant authentication strength
CA grant uses the phishing-resistant strength
BP 1.1
C P1
Require phishing-resistant MFA for privileged roles
CA policy scoped to directory roles with that strength
BP 1.1
R P1
Set sign-in frequency and non-persistent browser for admins
CA session controls set
BP 1.2
R
Adopt the Microsoft-managed CA policies deliberately, from report-only to on
Each managed policy state decided
BP 1.1
R P1
Require a compliant or managed device for access
CA grant requires compliant device
BP 1.2
Legacy authentication and protocol lockdown
Tier
Do this
How to verify
See
C
Block legacy authentication
Zero successful legacy sign-ins over 30 days
BP 1.1
C
Block basic authentication
Baseline Security Mode setting on
BP 1.1
R
Block device code flow
Block policy on, not report-only
BP 1.2
R
Retire per-user MFA state in favor of Conditional Access
Per-user MFA shows disabled once CA covers users
BP 1.2
O
Block the authentication transfer flow (preview)
CA authentication-flows transfer blocked
BP 1.2
Password protection and risk
Tier
Do this
How to verify
See
R
Set cloud passwords to never expire
Password validity set to never
BP 1.2
R P1
Enable Entra Password Protection in enforced mode with a custom banned list
Mode enforced, custom list populated
BP 1.2
R P1
Tune smart lockout threshold and duration
Threshold 10, duration 60 seconds or more
BP 1.2
R P1
Enable self-service password reset with strong methods
SSPR on, two or more strong methods
BP 1.2
C P2
Remediate risky users with Require risk remediation: secure password change, or session revocation and forced reauth when passwordless
Remediate risky sign-ins: require phishing-resistant MFA and a fresh sign-in frequency
CA conditions on sign-in risk and grants require-MFA
BP 1.1
R P2
Notify admins of high-risk users and migrate legacy risk policies into CA
Notification on; no standalone risk policy
BP 1.2
3. Application trust
Tier
Do this
How to verify
See
C
Restrict application registration to admins
Users-can-register-apps set to false
BP 1.1
C
Restrict user consent to verified publishers and low-impact permissions, or off
A low-impact consent policy is assigned
BP 1.1
R
Enable the admin consent request workflow
Workflow enabled with reviewers
BP 1.2
R
Restrict group-owner consent
Group-owner consent disabled or verified only
BP 1.2
R
Block adding password credentials (secrets) to applications
App management policy blocks secret addition
BP 1.2
O
Cap application secret and certificate lifetimes
App management policy lifetimes set
BP 1.2
R
Review enterprise-app and service-principal credentials and permissions
Stale and over-privileged SPs removed
BP 1.2
4. External trust
Tier
Do this
How to verify
See
C
Restrict guest access to their own directory objects
Guest access level set to most restrictive
BP 1.1
R
Limit who can invite guests to specific admin roles
Invite setting restricted to Guest Inviter roles
BP 1.2
R
Allow-list permitted external domains for invitations
Collaboration allow-list configured
BP 1.2
R
Default cross-tenant access to block, permit partners deliberately
Default inbound and outbound blocked
BP 1.3
R P2
Run recurring access reviews on guests
Guest access review configured
BP 1.2
O
Trust partner MFA or device claims only where warranted
Per-partner trust set deliberately
BP 1.2
O
Control outbound access with tenant restrictions
Tenant restrictions policy configured
BP 1.2
5. Device trust
Tier
Do this
How to verify
See
R
Scope who can Entra-join devices to an enrolment group rather than to all users
Join setting set to Selected, which with All is the only other state it has; it does not govern hybrid join, Entra joined Azure VMs, or Autopilot self-deploying mode
BP 1.2
R
Decide personal device registration separately from join
Register setting set to Selected or None, which is the setting where None exists
BP 1.2
R P1
Require MFA to register or join via the Conditional Access user action
CA user-action policy set, not the legacy toggle
BP 1.2
R
Remove the joining user’s standing local admin; use Windows LAPS
No standing local admin; LAPS policy on
BP 1.2
O
Set a maximum device count per user
Device setting bounded
BP 1.2
O
Restrict non-admin BitLocker key self-recovery
Device setting restricted
BP 1.2
6. Self-service and groups
Tier
Do this
How to verify
See
R
Prevent users from creating new tenants
Allowed-to-create-tenants set to false
BP 1.2
R
Restrict security-group creation to admins
Allowed-to-create-security-groups set to false
BP 1.2
R
Restrict Microsoft 365 group creation to an approved group
Group.Unified setting off with an allowed group
BP 1.2
R
Restrict the Entra admin center for non-admins
Portal-only setting and not a security control (deep links and Graph still work), so pair it with a CA policy on the Azure management API
BP 1.2
R
Prevent group owners from adding or approving their own members
Self-service group setting restricted
BP 1.2
O
Disable LinkedIn connections and self-service trial sign-up
Both settings off
BP 1.2
O
Set a Microsoft 365 group expiration and naming policy
Expiration and naming configured
BP 1.2
O
Leave “users can read other users” at default unless directory-hiding is required
Default kept (restricting breaks apps)
BP 1.2
7. Monitoring and response
Tier
Do this
How to verify
See
R
Stream Entra sign-in and audit logs to the SIEM
Diagnostic settings send to Sentinel or Log Analytics
BP 1.2
R
Export the key log categories
Sign-in, audit, risky users, service-principal, provisioning on
BP 1.2
R
Set adequate log retention
Retention meets the compliance requirement
BP 1.2
R
Confirm the unified audit log is on
Audit-log ingestion enabled
BP 1.2
R
Alert on high-signal identity events
Analytics on new CA policy, role change, app credential, break-glass
BP 1.2
R
Keep Continuous Access Evaluation on
CAE enabled
BP 1.2
8. Tenant governance
Tier
Do this
How to verify
See
C P1
Choose Conditional Access over Security Defaults once licensed
Security Defaults off with a CA baseline present
BP 1.3
R
If unlicensed for CA, keep Security Defaults on
Security Defaults enabled
BP 1.2
C
Review each Microsoft-managed CA policy before it auto-enables
Each state decided, break-glass excluded
BP 1.1
R
Decide on Baseline Security Mode setting by setting
Each setting adopted or declined
BP 1.2
R
Assign a named owner for identity posture and drift
Documented owner
BP 1.2
R
Run continuous baseline conformance testing
Scheduled Maester run with tracked results
BP 1.4
R
Know exactly what Entra ID Backup and Recovery covers, and cover the rest yourself
P1/P2; one restore point a day held seven days; covers users, groups, applications and service principals, and also Conditional Access policies, named locations and the authentication method and authorization policies; not hard-deletes, synced identities or workload data; Backup Reader and Backup Administrator assigned deliberately
BP 1.2
That is the baseline, end to end. The reasoned articles in this wave defend every line, and the verification loop proves the lines that can be tested stay true. Work down the critical tier first. Everything below it is the difference between a tenant that is adequate and one that is genuinely well kept.