Identity governance is one of those topics that sounds enterprise-only. Privileged Identity Management, access reviews, entitlement management — these feel like concepts that belong in a 10,000-person company with a dedicated IAM team, not a 50-person professional services firm running Microsoft 365 Business Premium.
That perception is wrong, and it costs SMBs. The most damaging breaches in small businesses are not zero-day exploits — they are compromised admin accounts with standing Global Admin access and offboarded employees whose accounts still work three months after they left. Both are identity governance failures, and both are preventable with features that are already included in Entra ID P1 or P2.
Privileged Identity Management (PIM) — whether Global Admin and other privileged roles require just-in-time activation rather than being permanently assigned. Standing admin access is the single biggest identity risk in SMB tenants. If an admin account is compromised, PIM limits the blast radius to the window between activation and session end.
Access Reviews — whether periodic reviews are configured to confirm that users still need the access they have. Without access reviews, permissions accumulate over time. The person who needed SharePoint Owner access for a project two years ago still has it today.
Entitlement Management — whether access packages are configured with approval workflows. This matters most for external collaboration — it replaces ad-hoc guest invitations with a structured, approved, time-limited access model.
Lifecycle Workflows (JML) — whether joiner, mover, and leaver processes are automated. The leaver workflow is the most critical and the most commonly missing. Manual offboarding is unreliable. Automated leaver workflows ensure accounts are disabled, licences are reclaimed, and group memberships are removed on the day someone leaves.
Guest Access Review — whether external guest accounts are periodically reviewed. Most tenants accumulate guest accounts from past projects and vendor relationships that were never cleaned up. Each one is a potential entry point.
Sign-in Risk Policy — whether Identity Protection is configured to block or require MFA step-up when a sign-in shows risk signals (atypical location, leaked credentials, impossible travel).
Emergency Access Accounts — whether break-glass accounts exist for emergency admin access if MFA is unavailable. This is a critical resilience control that most SMBs don't have.
Conditional Access and CA Enforcement vs Report-Only gap — whether CA policies are enforced (not just in report-only mode) and whether there are gaps in coverage.
Authentication Strengths — whether phishing-resistant MFA (FIDO2, Windows Hello) is required for privileged operations rather than just SMS or authenticator app.
Enterprise App Permissions and App Registrations Audit — whether third-party applications have been granted excessive permissions and whether stale app registrations are being cleaned up.
The AI Entra Governance Posture card synthesises all 13 signals into a risk level and narrative. The most common finding in SMB tenants is a combination of: PIM not configured (standing admin access), no leaver lifecycle workflow, and access reviews covering only M365 Groups rather than applications. Together these three gaps mean that an admin account compromise has maximum blast radius, offboarded employees may still have active accounts, and application permissions are never reviewed.
Licence note: PIM, Access Reviews, and Entitlement Management require Entra ID P2 or Microsoft 365 Business Premium (which includes Entra ID P1 — PIM requires P2). Lifecycle Workflows require Entra ID Governance. M365Clarity will indicate which features are not available on your current plan rather than flagging them as red.
If you take nothing else from this post: configure a leaver lifecycle workflow. It does not require Entra ID Governance — a basic version can be implemented with Entra ID P1 and Power Automate. Every day an offboarded employee account remains active is a day of unnecessary risk. The M365Clarity Entra Governance Posture assessment will surface this immediately if it is missing.
Assess your Entra ID governance posture
Scan your tenant and get an AI assessment of your identity governance health.
Run a free scan →