Independent assessment practice / Microsoft cloud identity

A written record of what your tenant is actually configured to do.

Microsoft 365, Entra, and Intune, examined under fixed scope and read-only access. You receive a written report: what was examined, what was found, the evidence behind each finding, and what to change. Nothing is sold to you afterward — no products, no managed service, no vendor commissions.

Evidence-led Vendor-neutral Principal-delivered

01

Examination

What gets examined

Scope is agreed in writing before any access is granted. Within a Microsoft 365 and Entra assessment, these are the surfaces read and the question asked of each one.

Privileged roles and PIM eligibility

roleManagement/directory/roleAssignmentScheduleInstances

Who holds tenant-wide administrative capability, and whether that access is standing or activated on demand.

Conditional Access policy set

identity/conditionalAccess/policies

Which sign-ins are actually governed, which are excluded, and what the exclusions add up to in practice.

Authentication methods and MFA coverage

reports/authenticationMethods/userRegistrationDetails

What each identity is able to authenticate with, and where weaker methods remain available.

Enterprise apps and service principals

servicePrincipals

Which workloads and integrations hold identities in the tenant, what they can reach, and whether their ownership and purpose are still clear.

Application credential expiry (secrets and certificates)

applications?$select=displayName,passwordCredentials,keyCredentials

Which workload credentials are expired or approaching expiry, and whether secrets and certificates are governed with a deliberate rotation window.

OAuth consent grants and delegated permissions

oauth2PermissionGrants

Which applications have delegated access, at what scopes, and whether each consent remains necessary and proportionate.

Exchange Online transport and mailbox rules

Get-TransportRule / Get-InboxRule
Exchange Online PowerShell

Where mail is forwarded, redirected, or silently moved, and which rules nobody remembers creating.

SharePoint and OneDrive external sharing

Get-SPOTenant / Get-SPOSite
SharePoint Online Management Shell

What may be shared outside the organization, by whom, and what already has been.

Intune compliance and configuration profiles

deviceManagement/deviceCompliancePolicies

What a device must satisfy before it is trusted, and whether the assigned policy set says what it is assumed to say.

Defender and Secure Score posture

security/secureScores

Which controls are reported as in place, and whether the reported state matches the configured state.

Read-only throughout — nothing is changed. A focused engagement may cover a subset; the agreed scope governs. Findings reference the CIS Microsoft 365 Benchmark, CISA SCuBA, and NIST CSF 2.0 where they apply.

02

Practice

Scope of practice

Kino Security provides focused assessments for organizations that need an experienced, independent view of a defined environment.

Scope is agreed in writing before work begins. Assessment access is temporary and read-only. Findings are supported by evidence and written for both the people responsible for remediation and the people responsible for decisions.

Kino does not sell managed security services, resell security products, or receive vendor commissions on remediation recommendations. The client pays for the assessment and the judgment behind it.

Work
Fixed-scope security assessment of an agreed environment, control set, or security question.
Access
Temporary, read-only, and limited to what the assessment requires.
Deliverable
A written assessment report with evidence, impact analysis, and specific remediation guidance.
Outside the model
Ongoing administration, managed security operations, standing access, and product resale.

03

Assessments

Assessment services

Each engagement starts with the environment and the security question that needs an answer. Scope is set before access is granted.

04

Work sample

Illustrative finding

One finding, in the form it is delivered. The report page shows the document it belongs to.

Illustrative finding / synthetic lab data / not client work

Kino Security / illustrative assessment finding

Microsoft Entra ID / IAM-01

Finding IDIAM-01
SeverityHigh
Affected systemMicrosoft Entra ID

Standing Global Administrator assignments increase privileged-access exposure

Condition

Four direct Global Administrator role-assignment schedule instances are active in the illustrative tenant with no end date. The assignments provide standing tenant-wide administrative capability rather than requiring time-bound activation for routine privileged access.

Evidence
Evidence excerpt / Microsoft Graph v1.0 / synthetic lab output
GET /v1.0/roleManagement/directory/roleAssignmentScheduleInstances
    ?$select=principalId,roleDefinitionId,directoryScopeId,
             startDateTime,endDateTime,assignmentType,memberType

HTTP/1.1 200 OK
{
  "value": [
    {
      "principalId": "1f3b••••••••a821",
      "roleDefinitionId": "62e90394-69f5-4237-9190-012177145e10",
      "directoryScopeId": "/",
      "startDateTime": null,
      "endDateTime": null,
      "assignmentType": "Assigned",
      "memberType": "Direct"
    },
    {
      "principalId": "6d92••••••••11be",
      "roleDefinitionId": "62e90394-69f5-4237-9190-012177145e10",
      "directoryScopeId": "/",
      "startDateTime": null,
      "endDateTime": null,
      "assignmentType": "Assigned",
      "memberType": "Direct"
    },
    {
      "principalId": "8a40••••••••c704",
      "roleDefinitionId": "62e90394-69f5-4237-9190-012177145e10",
      "directoryScopeId": "/",
      "startDateTime": null,
      "endDateTime": null,
      "assignmentType": "Assigned",
      "memberType": "Direct"
    },
    {
      "principalId": "c251••••••••9d37",
      "roleDefinitionId": "62e90394-69f5-4237-9190-012177145e10",
      "directoryScopeId": "/",
      "startDateTime": null,
      "endDateTime": null,
      "assignmentType": "Assigned",
      "memberType": "Direct"
    }
  ]
}
Impact

Standing Global Administrator access increases the number of identities capable of making high-impact tenant changes at any given time. Compromise of one of those identities may provide immediate administrative capability without a separate privilege-elevation event.

Remediation

Review each standing assignment and document its operational requirement. For routine administrative identities, prefer eligible, time-bound Privileged Identity Management activation with strong authentication and approval controls where appropriate.

Retain standing Global Administrator access only where a documented exception requires it, such as a deliberately governed emergency-access account, and apply compensating monitoring and access controls.

Assessment note: This specimen uses synthetic lab data formatted to mirror Microsoft Graph role-assignment schedule output. It is illustrative only and is not an anonymized client finding.

05

Conduct

Conduct of an engagement

The process is straightforward: define the question, examine the evidence, document the result, and close the access used for the assessment.

  1. Scope

    Objectives, systems, exclusions, access requirements, and expected delivery are agreed in writing before assessment work begins.

  2. Access

    Temporary read-only access is established for the agreed assessment window and limited to what the scope requires.

  3. Assessment

    Configuration, identity, relevant documentation, and other agreed evidence are reviewed. Potential findings are validated and analyzed for practical impact.

  4. Report

    Findings are documented with evidence, impact analysis, remediation guidance, and an executive summary that identifies the material conclusions.

  5. Delivery & closeout

    The material findings and priorities are reviewed with the client. The report is issued, and assessment access is removed.

Data handling

An assessment produces evidence about weaknesses. How that evidence is held is part of the engagement, not an afterthought.

Agreement
A mutual non-disclosure agreement is executed before scoping details are exchanged.
Access
Provisioned by the client, read-only, scoped to the assessment, and time-boxed to the agreed window.
Evidence
Collected read-only and held encrypted. Used for the assessment and for nothing else.
Identifiers
Principal, tenant, and account identifiers are truncated in the report wherever the full value is not required to act on the finding.
Retention
Working evidence is destroyed at closeout. The client retains the report and the evidence within it.
Closeout
Assessment access is removed at delivery, and the removal is confirmed in writing.
Disclosure
Findings are not published, reused, or referenced as marketing. No client is named without written permission.

06

Practitioner

Practitioner

Kino Security is a principal-led practice. The same practitioner scopes the work, examines the environment, and prepares the final report.

The practice is grounded in more than a decade of systems and security administration in regulated environments, with direct operating responsibility for Microsoft 365, Entra, Intune, and security governance.

That operating context informs how configuration, access, and control failures are evaluated: as conditions someone must understand, prioritize, and remediate—not as scores to collect.

Principal
Robert Jaworski
Background
More than a decade of systems and security administration
Operating context
Microsoft cloud administration and security governance in regulated environments
Technical emphasis
Cloud identity, privileged access, endpoint management, and non-human identities
Credentials
B.S. Cybersecurity & Information Assurance; ISC² SSCP; CompTIA CySA+; CompTIA PenTest+
Accountability
The practitioner who scopes the engagement performs the assessment and signs the report

07

Contact

Contact

Send a short note about the environment, what you would like examined, and any timing constraint.

No system access is needed to start the conversation. If the work fits the practice, Kino will define the scope, fee, access requirements, and expected delivery before assessment work begins.

Assessment inquiries
info@kinosecurity.com
Start an inquiry

Helpful context

Organization or environment, what you want reviewed, approximate scope, and desired timing. A formal statement of work is not needed for the first note.