Attack-driven controls
Every control is tied to a documented attack scenario against Entra ID, so remediation maps back to a concrete threat.
Benchmark · Entra ID
EIDSCA is a security configuration baseline for Microsoft Entra ID, derived from common attack scenarios and published as part of the Entra ID Attack and Defense Playbook.
About the baseline
EIDSCA (Entra ID Security Config Analyzer) takes a different approach to baselines: instead of starting from a checklist, it starts from attacker scenarios. Each control maps to a documented attack technique against Entra ID and describes the configuration that mitigates it. The result is a tenant-configuration baseline focused squarely on identity — the control plane for Microsoft 365.
Capabilities
The baseline's scope — we run these checks against your tenant and report the results.
Every control is tied to a documented attack scenario against Entra ID, so remediation maps back to a concrete threat.
Goes deeper on Entra ID than a general M365 benchmark — Conditional Access design, authentication methods, and privileged role management.
Maintained alongside the Entra ID Attack and Defense Playbook, a widely used community reference for identity security.
Focuses on risky defaults that ship enabled, so a fresh tenant often has meaningful findings on the first audit.
Surface area
Use cases
When identity is the priority — after a phishing incident, an admin compromise, or before enabling more M365 services — audit Entra ID on its own.
Validate that Conditional Access policies actually close the gaps they were meant to close rather than leaving loopholes.
Surface standing Global Admin assignments and other privileged-role risks that should be moved to just-in-time access.
Other benchmarks
CIS Microsoft 365 Foundations Benchmark v3.1.0 — 60+ tests across Entra ID, Exchange, Teams, and SharePoint.
US CISA Secure Cloud Business Applications baselines — 70+ tests covering identity, access, devices, and apps.
Office 365 Recommended Configuration Analyzer — comprehensive Exchange Online security configuration checks.
Run EIDSCA against a Microsoft 365 tenant and get a severity-ranked PDF. Credits never expire.