The checks that find the holes
Misconfigurations and identity risk across users, groups, applications and service principals, re-run every six hours.
- Admins without MFA, dormant accounts, guests holding member rights
- Conditional Access gaps, weak password policy, risky OAuth consent





