Security Ninja

Tenant Hardening Dojo

The settings underneath everything else. Not policies, not authentication methods — the defaults your tenant shipped with, that nobody revisits. Who can consent to an app. What a guest can read. Who can register an application, create a tenant, or move a subscription out of your directory. Then the Azure side: who has elevated access, what's logged, what's governed. Most of it is free, and most of it is one toggle.

Recorded progress
0 / 1000
Current Rank
No belt yet
0 done 0 audited 0 in scope

User-recorded progress; not tenant-verified.

Read this first — two systems, one door

Microsoft Entra and Azure are separate permission systems. An Entra role grants you nothing over Azure resources. An Azure role grants you nothing in Entra. People assume otherwise constantly, and the assumption is usually harmless — right up until it isn't.

There is exactly one door between them: Entra ID → Properties → Access management for Azure resources. A Global Administrator sets it to Yes and is assigned User Access Administrator at root scope, which means every subscription and every management group in the tenant. It is self-service, it is per-user, and it does not switch itself back off.

Full guidance: Secure your Microsoft Entra identity infrastructure ↗

Size up your environment

Three questions. The Azure answer matters most — say no and ten controls disappear rather than scoring against subscriptions you don't own. If you've been through another dojo, your licence is already filled in.

Which licences do you hold? Select all that apply.
More products and add-ons

Check assignments for each affected user, cloud and feature. Education and government packages can be recorded as Other with confirmed P1/P2 features.

Microsoft Learn licensing reference ↗

Do you run Azure subscriptions?

"Not sure" counts as yes, deliberately. A subscription you've forgotten about is worse than one you're managing — and this dojo will help you find it.

Do you collaborate with external organisations?

Is paid Defender CSPM enabled for resources in scope?

Walk out with a plan

Your plan reflects recorded answers and progress, including unresolved and deferred controls. Configuration examples require review of permissions, licensing, dependencies and placeholders. PowerShell bundles include an execution stop; read and edit them before deliberately running a selected section.