AD / Microsoft 365 hygiene report

Collected 2026-09-30T12:00:00Z · corp.internal / corp.example

Summary

SeverityFindings
High4
Medium11
Low5
Info0
CheckTitleResult
AD-01Stale users2 finding(s)
AD-02Stale computers1 finding(s)
AD-03Passwords that never expire2 finding(s)
AD-04Privileged group membership2 finding(s)
AD-05Kerberoastable users2 finding(s)
AD-06AS-REP roastable users1 finding(s)
AD-07Unconstrained delegation2 finding(s)
M365-01Users without MFA2 finding(s)
M365-02Unused licenses3 finding(s)
M365-03Global Administrator count1 finding(s)
M365-04Permanent privileged rolesNot evaluated
M365-05Stale guests2 finding(s)

AD-01 · Stale users

Disable accounts that no longer log on, then delete them after your retention period. Reference

SeverityStatusTypeIdentityDetail
MediumFindingUserbob.oldLast activity 140 days before collection.
MediumFindingUsercontractor.neverNever active; created 200 days before collection.

AD-02 · Stale computers

Disable computer accounts that no longer authenticate, then remove them. Reference

SeverityStatusTypeIdentityDetail
LowFindingComputerPC-OLD-17Last activity 180 days before collection.

AD-03 · Passwords that never expire

Remove PasswordNeverExpires; move service accounts to gMSA. Reference

SeverityStatusTypeIdentityDetail
MediumFindingUsersvc-sqlPasswordNeverExpires is set.
MediumFindingUsersvc-backupPasswordNeverExpires is set.

AD-04 · Privileged group membership

Keep privileged groups small; remove disabled and inactive members. Reference

SeverityStatusTypeIdentityDetail
MediumFindingUserformer.adminDisabled account is still a member (Domain Admins > former.admin).
MediumFindingUserbob.oldInactive member (Backup Operators > bob.old). Last activity 140 days before collection.

AD-05 · Kerberoastable users

Move services to gMSA or use long random passwords; remove SPNs that are not needed. Reference

SeverityStatusTypeIdentityDetail
MediumFindingUsersvc-sqlSPN: MSSQLSvc/sql01.corp.internal:1433
HighFindingUsersvc-backupSPN: HTTP/backup01.corp.internal; member of Domain Admins.

AD-06 · AS-REP roastable users

Re-enable Kerberos pre-authentication. Reference

SeverityStatusTypeIdentityDetail
HighFindingUserlegacy.appKerberos pre-authentication is disabled.

AD-07 · Unconstrained delegation

Replace unconstrained delegation with constrained or resource-based constrained delegation. Reference

SeverityStatusTypeIdentityDetail
HighFindingComputerAPP01Trusted for unconstrained delegation.
HighFindingUsersvc-webTrusted for unconstrained delegation.

M365-01 · Users without MFA

Require MFA registration (registration campaign or Conditional Access). Reference

SeverityStatusTypeIdentityDetail
MediumFindingUserbob@corp.exampleNo MFA method registered.
MediumFindingUserdave@corp.exampleNo MFA method registered.

M365-02 · Unused licenses

Reclaim licenses from disabled and inactive users; reduce unassigned seats at renewal. Reference

SeverityStatusTypeIdentityDetail
LowFindingLicenseENTERPRISEPREMIUM6 of 10 seats unassigned.
MediumFindingUsercarol@corp.exampleLicensed but the account is disabled.
LowFindingUserdave@corp.exampleLicensed but inactive. Last activity 120 days before collection.

M365-03 · Global Administrator count

Keep between two and four Global Administrators, including break-glass accounts. Reference

SeverityStatusTypeIdentityDetail
MediumFindingTenantGlobal Administrator1 active Global Administrators; expected 2 to 4.

M365-04 · Permanent privileged roles

Convert standing assignments to PIM-eligible assignments. Reference

SeverityStatusTypeIdentityDetail
InfoNot evaluatedCheckNot evaluated: graph.roleEligibility unavailable: The tenant needs a Microsoft Entra ID P2 license..

M365-05 · Stale guests

Review guests with access reviews; remove inactive guests and expired invitations. Reference

SeverityStatusTypeIdentityDetail
LowFindingGuestpartner_fabrikam.test#EXT#@corp.exampleLast activity 95 days before collection.
LowFindingGuestpending_contoso.test#EXT#@corp.exampleInvitation pending 45 days.