BLOG

Guides & best practices

Practical articles on auditing and securing your Microsoft environment — connectors, methodology, misconfigurations and compliance.

Methodology

Install and customize EntraGUARD: from setup to white-label

Step-by-step: install EntraGUARD on a workstation (even shared), then make it yours — white-label branding, per-client logos, offline licence, themes.

2026-07-26·7 min
Read article →
MSP

The Microsoft 365 security assessment checklist for MSPs

A repeatable checklist for MSPs running Microsoft 365, Entra ID and Azure security assessments across multiple clients, and how to package it as a service.

2026-07-21·9 min
Read article →
Compliance

HIPAA and Microsoft 365: auditing the technical safeguards

How the HIPAA Security Rule's technical safeguards map to Entra ID, Active Directory and Microsoft 365 configuration, and how to evidence them.

2026-07-07·8 min
Read article →
Compliance

CMMC and NIST SP 800-171: auditing Microsoft identity for defense contractors

How the access control and authentication requirements of NIST SP 800-171 and CMMC map to Entra ID, Active Directory and Azure configuration.

2026-06-30·9 min
Read article →
Compliance

Microsoft 365 security audit for SOC 2 compliance

How a Microsoft 365, Entra ID and Azure security audit produces the technical evidence auditors ask for under SOC 2 Trust Services Criteria CC6 and CC7.

2026-06-16·9 min
Read article →
Compliance

Security audits for NIS2 and ISO 27001 compliance

How a Microsoft 365, Entra ID and Azure security audit supports NIS2 and ISO 27001 compliance with defensible, documented evidence.

2026-04-07·7 min
Read article →
Security

Securing Active Directory: the critical points of an audit

The Active Directory weaknesses that matter most in a security audit: privileged groups, delegation, Kerberos, password policy and stale accounts.

2026-03-31·8 min
Read article →
Security

Top 10 Entra ID misconfigurations to fix first

The ten most common and most dangerous Microsoft Entra ID misconfigurations, why they matter, and how to remediate each one.

2026-03-24·9 min
Read article →
Methodology

Custom baselines: adapting the audit to your context

How to build custom baselines in EntraGUARD: exclude irrelevant controls, adjust criticality, and make the compliance score reflect your real requirements.

2026-03-17·6 min
Read article →
Methodology

Entra ID audit vs Microsoft Secure Score: the differences

Microsoft Secure Score is useful but limited. Here is how a dedicated Entra ID and Microsoft 365 audit goes deeper, with an action plan Secure Score does not give you.

2026-03-10·7 min
Read article →
Methodology

Understanding the weighted compliance score (L1/L2)

Why a weighted compliance score reflects real risk better than a simple pass ratio, and how EntraGUARD weights level 1 and level 2 controls.

2026-03-03·6 min
Read article →
Methodology

The 323 controls explained: CIS, ANSSI, NIST and ISO 27001

How EntraGUARD's 323 automated controls map to CIS, ANSSI, NIST and ISO 27001, and why framework alignment makes an audit defensible.

2026-02-24·9 min
Read article →
Connectors

Setting up the Azure connector: subscriptions, RBAC and Defender for Cloud

Configure the EntraGUARD Azure connector to audit subscriptions, RBAC assignments, network exposure and Defender for Cloud, all read-only.

2026-02-17·7 min
Read article →
Connectors

Configuring the Active Directory connector for on-premises audits

Connect EntraGUARD to on-premises Active Directory: LDAP settings, domain and credentials, least-privilege read access, and how to validate the connection.

2026-02-10·7 min
Read article →
Connectors

How to configure the Entra ID connector: every authentication method explained

Set up the EntraGUARD Entra ID connector step by step: automatic provisioning, certificate vs client secret, and the read-only Graph permissions required.

2026-02-03·8 min
Read article →