How-to guides
Create two cloud-only emergency access accounts in Entra ID, exclude them from Conditional Access, alert on every sign-in, and test them quarterly.
Step-ordered playbook for a compromised Entra admin account: disable, revoke sessions, remove persistence, verify tenant state, keep evidence.
PIM needs Entra ID P2 for each eligible admin and approver. What Business Premium and E3 tenants can do instead, and how Orbitra handles response.
Microsoft says two to four Global Admins. Count yours, including PIM eligible and service principals, remove the extras safely, and stop the creep.
List service principals holding Global Administrator or other privileged Entra roles, check sign-ins and owners, then remove it with a recovery path.
PowerShell and Graph steps to list app registrations with expiring or expired client secrets, find who owns them, and rotate without downtime.
Revoke sessions invalidates refresh tokens; access tokens can live up to an hour. Disable blocks new sign-ins. What each stops and how to verify.
By situation
What cyber insurers and auditors ask about privileged access in Microsoft 365, what a read-only Entra connection shows first, and proof of what changed.
What Entra ID P1 in Business Premium and E3 includes, what P2 or E5 adds (PIM, risk-based Conditional Access, attack disruption), and how Orbitra fits.
Privileged identity response for 1 to 5 person security teams on Business Premium or E3: standing admins, app consents, secrets, insurer evidence.
Find a malicious or over-privileged OAuth consent in Entra ID, revoke the grant or app role assignment, and verify it is gone. A password reset will not.
Field notes
Longer essays on how the security org is changing and what lean teams actually need are on the blog. Definitions of the terms used across these guides are in the glossary.