Guides & best practices
Practical articles on auditing and securing your Microsoft environment — connectors, methodology, misconfigurations and compliance.
Install and customize EntraGUARD: from setup to white-label
Step-by-step: install EntraGUARD on a workstation (even shared), then make it yours — white-label branding, per-client logos, offline licence, themes.
Read article → MSPThe Microsoft 365 security assessment checklist for MSPs
A repeatable checklist for MSPs running Microsoft 365, Entra ID and Azure security assessments across multiple clients, and how to package it as a service.
Read article → ComplianceHIPAA and Microsoft 365: auditing the technical safeguards
How the HIPAA Security Rule's technical safeguards map to Entra ID, Active Directory and Microsoft 365 configuration, and how to evidence them.
Read article → ComplianceCMMC and NIST SP 800-171: auditing Microsoft identity for defense contractors
How the access control and authentication requirements of NIST SP 800-171 and CMMC map to Entra ID, Active Directory and Azure configuration.
Read article → ComplianceMicrosoft 365 security audit for SOC 2 compliance
How a Microsoft 365, Entra ID and Azure security audit produces the technical evidence auditors ask for under SOC 2 Trust Services Criteria CC6 and CC7.
Read article → ComplianceSecurity audits for NIS2 and ISO 27001 compliance
How a Microsoft 365, Entra ID and Azure security audit supports NIS2 and ISO 27001 compliance with defensible, documented evidence.
Read article → SecuritySecuring Active Directory: the critical points of an audit
The Active Directory weaknesses that matter most in a security audit: privileged groups, delegation, Kerberos, password policy and stale accounts.
Read article → SecurityTop 10 Entra ID misconfigurations to fix first
The ten most common and most dangerous Microsoft Entra ID misconfigurations, why they matter, and how to remediate each one.
Read article → MethodologyCustom baselines: adapting the audit to your context
How to build custom baselines in EntraGUARD: exclude irrelevant controls, adjust criticality, and make the compliance score reflect your real requirements.
Read article → MethodologyEntra ID audit vs Microsoft Secure Score: the differences
Microsoft Secure Score is useful but limited. Here is how a dedicated Entra ID and Microsoft 365 audit goes deeper, with an action plan Secure Score does not give you.
Read article → MethodologyUnderstanding the weighted compliance score (L1/L2)
Why a weighted compliance score reflects real risk better than a simple pass ratio, and how EntraGUARD weights level 1 and level 2 controls.
Read article → MethodologyThe 323 controls explained: CIS, ANSSI, NIST and ISO 27001
How EntraGUARD's 323 automated controls map to CIS, ANSSI, NIST and ISO 27001, and why framework alignment makes an audit defensible.
Read article → ConnectorsSetting up the Azure connector: subscriptions, RBAC and Defender for Cloud
Configure the EntraGUARD Azure connector to audit subscriptions, RBAC assignments, network exposure and Defender for Cloud, all read-only.
Read article → ConnectorsConfiguring the Active Directory connector for on-premises audits
Connect EntraGUARD to on-premises Active Directory: LDAP settings, domain and credentials, least-privilege read access, and how to validate the connection.
Read article → ConnectorsHow to configure the Entra ID connector: every authentication method explained
Set up the EntraGUARD Entra ID connector step by step: automatic provisioning, certificate vs client secret, and the read-only Graph permissions required.
Read article →