Identity Security Program Checklist for Mid-Market Companies
Retrospective: this article looks back at events from May 2022, written in 2026 with the benefit of hindsight.
Use this checklist to assess an identity security program for a mid-sized organization.
Strategy and ownership
- An identity program owner is named.
- Identity security metrics are reported to leadership.
- A roadmap exists with funded priorities.
Authentication
- MFA required for all users.
- Phishing-resistant MFA for administrators and high-risk roles.
- Legacy authentication blocked.
- Passwordless rollout planned or underway.
Access control
- Conditional Access baseline policies in place.
- Access to sensitive data requires compliant devices.
- SSO for major SaaS applications.
Privileged access
- Fewer than five permanent Global Administrators.
- Just-in-time access for admin roles.
- Separate admin accounts.
- Break-glass accounts tested.
Lifecycle
- Joiners get access automatically based on role.
- Movers lose old access.
- Leavers are disabled within hours.
- Quarterly access reviews for privileged roles and guests.
Non-human identities
- Inventory of apps, service principals and service accounts.
- Owners assigned.
- Secretless authentication where possible.
Monitoring
- Sign-in and audit logs retained and monitored.
- Risk detections reviewed.
- Help desk identity verification procedure enforced.
- Microsoft Entra Launches (May 2022): Identity Becomes Its Own Product Family Platform Changes
- How to Map Entra Products to Your Identity Security Roadmap How-To & Hardening
- CIO Brief: Identity Is the New Perimeter — Now It Has a Brand CIO Briefings