Methodology

The method, not just the tool.How a proper audit actually runs.

Home / Guide / Methodology
Methodology

The complete methodology

EntraGUARD·2026-07-30·10 min

Running the controls is the easy part — EntraGUARD executes all 299 of them in seconds. What separates a good audit from a screenshot folder is everything around the run: how you scope it, how you prioritise what it finds, and what happens afterwards. This guide is the method we recommend to every consultant and MSP using the product.

1Prepare
2Connect
3Scope
4Run
5Avoid
6Repeat
7Deliver

Official sources and frameworks

EntraGUARD maps its controls to published frameworks. The primary sources, for your engagement files:

Preparation: agree on the perimeter before you connect anything

An audit that starts in the tooling ends in an argument. Before registering the read-only application, agree in writing with the client on three things: which tenant (production, not a pilot), which services are in scope — Entra ID alone for an identity review, or the full estate with Exchange, Teams, SharePoint, OneDrive, Intune, Defender and Purview — and who receives which report. The executive summary and the remediation plan rarely go to the same inbox.

Read-only means demonstrably read-only. Send the client the list of Graph permissions before the engagement. Every scope is .Read.All; no write permission is ever requested. This single email removes most of the friction of getting an application approved in someone else's tenant.

Connect and verify — don't assume

Configure the Entra connector first: automatic provisioning creates the application, the certificate and the consented permissions in one guided pass. Then use Test connection on every service connector before enabling it. A connector only becomes activatable after its test passes, so a missing licence (Intune on a tenant without Intune, Purview without E5 Compliance) surfaces before the audit, with the exact missing permission named — not halfway through a client call.

Choose the scope: a baseline, not always the whole catalog

Not every engagement should run all 299 controls. A first pass with CIS level 1 gives a defensible, low-noise starting point. A certification file calls for the ISO 27001 A.8 selection; a French public-sector or regulated client for the ANSSI baseline; a financial entity for DORA; an EU essential entity for NIS2 Article 21. Save the selection as a named baseline: the name is stamped on the audit in history and on every report, so six months later you can prove what was in scope.

Run it — and read the failures before the score

The compliance percentage is for the cover page. The work is in the failed controls, and they are not equal. Triage in this order:

PriorityWhat it looks likeTypical examples
Fix this weekDirect account-takeover pathsMFA not enforced for admins, legacy authentication allowed, no break-glass account
Fix this monthPrivilege and exposureStanding Global Admins instead of PIM, anonymous sharing links, unrestricted app consent
Plan itHardening and hygieneRetention policies, device compliance gaps, audit log coverage

Every control in the report cites its source (CIS, NIST, ISO, ANSSI…) and ships with the remediation steps and the PowerShell to verify the fix — use them as the working checklist, not as an appendix.

The classic pitfalls

Auditing the wrong tenant. Verify the tenant name on the connector screen against the engagement letter. Fixing during the audit. Resist it: finish the run, get the baseline picture, then remediate — otherwise the report describes neither the before nor the after. Treating 100% as the goal. Some controls are legitimately not applicable to a given business; document the exception in the baseline instead of chasing the number. One audit, no follow-up. A single snapshot proves nothing about posture; the value is in the trend.

Cadence: the audit is a series, not an event

Quarterly is the sweet spot for most tenants — monthly for regulated or fast-moving environments, and always immediately after a migration, a merger or an incident. Keep every run in history: the comparison view shows regressions first, which is exactly what a steering committee wants to see, and the trend chart turns four audits into a posture narrative.

After the audit: deliver the four reports to the four audiences

The executive report (PDF) goes to management; the remediation plan to the engineers; the framework matrix to the compliance officer; the detailed evidence export stays in the engagement file. Send them under your brand, book the remediation review, and schedule the next run before you leave the call — that is what turns a one-off audit into a recurring engagement.

Short version. Agree the perimeter → provision Entra → test every connector → pick the right baseline → triage failures by exploitability → fix, re-run, compare → deliver per audience → book the next run. The tool executes the controls; this sequence is what makes it an audit.