M365Audit

Benchmark · Entra ID

EIDSCA — Entra ID Security Config Analyzer logo

EIDSCA — Entra ID Security Config Analyzer.
Automated. One report.

EIDSCA is a security configuration baseline for Microsoft Entra ID, derived from common attack scenarios and published as part of the Entra ID Attack and Defense Playbook.

About the baseline

What is EIDSCA?

EIDSCA (Entra ID Security Config Analyzer) takes a different approach to baselines: instead of starting from a checklist, it starts from attacker scenarios. Each control maps to a documented attack technique against Entra ID and describes the configuration that mitigates it. The result is a tenant-configuration baseline focused squarely on identity — the control plane for Microsoft 365.

Maintainer
Cloud Architecture & Security community
Coverage
40+ Entra ID controls
License
MIT

Capabilities

What EIDSCA covers

The baseline's scope — we run these checks against your tenant and report the results.

Attack-driven controls

Every control is tied to a documented attack scenario against Entra ID, so remediation maps back to a concrete threat.

Identity deep-dive

Goes deeper on Entra ID than a general M365 benchmark — Conditional Access design, authentication methods, and privileged role management.

Attack & defense playbook

Maintained alongside the Entra ID Attack and Defense Playbook, a widely used community reference for identity security.

Actionable defaults

Focuses on risky defaults that ship enabled, so a fresh tenant often has meaningful findings on the first audit.

Surface area

Where it looks

Entra IDConditional AccessPrivileged rolesAuthentication

Use cases

When it earns its keep

Identity hardening

When identity is the priority — after a phishing incident, an admin compromise, or before enabling more M365 services — audit Entra ID on its own.

Conditional Access review

Validate that Conditional Access policies actually close the gaps they were meant to close rather than leaving loopholes.

Privileged access governance

Surface standing Global Admin assignments and other privileged-role risks that should be moved to just-in-time access.

Other benchmarks

Add another framework

One credit. One tenant. One report.

Run EIDSCA against a Microsoft 365 tenant and get a severity-ranked PDF. Credits never expire.