> ## Content Index
> Fetch the complete content index at: https://guardians-of-kings-landing.ghost.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# Guarding the Realm: 10 Entra Admin Tasks You Shouldn't Skip
- URL: https://guardians-of-kings-landing.ghost.io/guarding-the-realm-10-entra-admin-tasks-you-shouldnt-skip/
- Published: 2026-09-08T12:45:02.000Z
- Updated: 2026-09-08T12:45:01.000Z
- Author: Kevin Villarreal
- Tags: Entra

Alright, Guardians….let's dive deeper into our favorite topic…Entra.

If you've spent any time in my world, you know I live at the intersection of Microsoft Security and "things that sound like they belong in a fantasy novel." Entra ID is basically the Wall for your tenant, it's the line between "the realm is safe" and "someone's Golden Vault just got looted by a phished credential." And just like the Night's Watch, most environments I walk into have a Wall that's undermanned, under-configured, and hoping nothing shows up before reinforcements arrive.

Good news: you don't need a full identity transformation project to start raising your defenses. Some of these are five-minute toggles, others are policies worth taking the time to plan and roll out properly, but every one of them meaningfully tightens your identity perimeter. Consider this your patrol checklist.

Here are my top 10.

## 1\. Turn On Security Defaults (or Move to Conditional Access)

If you're a smaller shop and haven't touched Conditional Access yet, Security Defaults is your free, baseline shield, it forces MFA for admins, blocks legacy auth, and requires MFA for risky sign-ins. It's not customizable, but it's infinitely better than nothing. If you're already licensed for Entra P1/P2, please don't stop here, build real Conditional Access policies instead. But for a lot of tenants, this is the fastest "close the obvious gap" move you can make in five minutes.

For more information on moving away from Security Defaults to Conditional Access, give my latest YouTube video a watch (I'd greatly appreciate it 🙂) link: [Conditional Access 101: From Security Defaults to Your First CA Policy](https://www.youtube.com/watch?v=TcMNwXbj85k&ref=guardians-of-kings-landing.ghost.io)

## 2\. Enforce MFA Everywhere | Especially on Admin Accounts

I know, I know, you've heard this a thousand times. But I still walk into tenants where Global Admins are running around with password-only auth like they're wielding a sword with no shield. Your admins are the high-value targets. Treat their accounts like the crown jewels they are: phishing-resistant MFA (FIDO2 keys or Windows Hello for Business) if you can swing it, standard MFA at an absolute minimum.

For more details: ([https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-mfa-strength](https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-mfa-strength?ref=guardians-of-kings-landing.ghost.io))

## 3\. Kill Legacy Authentication

Legacy auth protocols (POP, IMAP, SMTP AUTH, older Exchange ActiveSync) don't support modern MFA, they're the unguarded postern gate around the side of the castle. Attackers know this and they love spraying credentials against it. Block it tenant-wide through Conditional Access or Security Defaults, and watch your sign-in risk logs get noticeably quieter.

For more details: ([https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-legacy-authentication](https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-legacy-authentication?ref=guardians-of-kings-landing.ghost.io))

## 4\. Turn On Identity Protection Risk Policies

**NOTE:** This requires a Microsoft Entra ID Plan 2 subscription. Entra ID Protection is quietly one of the most underused tools in the whole suite. User risk and sign-in risk policies let Entra automatically respond to signs of compromise, impossible travel, leaked credentials, anomalous sign-in patterns, without you having to be the one staring at logs at 2 a.m. Set up a sign-in risk policy requiring MFA, and a user risk policy requiring a secure password change. It's an automated Maester (double entendre here for those who love GoT and also love [Maester](https://maester.dev/?ref=guardians-of-kings-landing.ghost.io) \- shoutout Merill Fernando) watching the ravens so you don't have to.

For more details: ([https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-risk-based-sign-in](https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-risk-based-sign-in?ref=guardians-of-kings-landing.ghost.io))

## 5\. Roll Out Privileged Identity Management (PIM) for Admin Roles

**NOTE:** This requires a Microsoft Entra ID Plan 2 subscription. Standing admin access is a liability. Every permanently-assigned Global Admin is a target that never sleeps. PIM lets you make privileged roles eligible instead of active, admins activate the role only when they need it, for a limited window, often with an approval step or justification requirement attached. It's the difference between handing out a permanent set of keys to the vault versus requiring a formal request every time someone needs to walk in.

For a deeper dive into the benefits of PIM and how to best utilize it, please read: [**PIM Is Not Enough | Here's What Most Orgs Miss**](https://guardians-of-kings-landing.ghost.io/pim-is-not-enough-heres-what-most-orgs-miss/)

## 6\. Audit and Trim Your Global Admin List

While you're in there setting up PIM, take a hard look at who actually holds Global Admin today. In almost every environment I've audited, that list is longer than it needs to be, often padded with old service accounts, former employees who somehow still have access, or people who only ever needed a narrower role like User Administrator or Exchange Administrator. Trim it down to the smallest number of humans who truly need it….and if you're caught up on my blog (self-promo 😂) your emergency access account(s).

## 7\. Enable Self-Service Password Reset (SSPR)

This one's as much about resilience as it is security. SSPR takes password reset requests off your help desk's plate and puts registered authentication methods in the hands of your users. Pair it with Combined Registration so users set up MFA and SSPR methods in one pass, one registration experience instead of two separate nagging prompts.

For more details: ([https://docs.azure.cn/en-us/entra/identity/authentication/concept-sspr-howitworks](https://docs.azure.cn/en-us/entra/identity/authentication/concept-sspr-howitworks?ref=guardians-of-kings-landing.ghost.io))

## 8\. Restrict User Consent to Apps Accessing Company Data

By default, a lot of tenants let any user grant permissions to any third-party app registration that comes knocking, which means all it takes is one convincing phishing page dressed up as a legitimate app, and a user unknowingly hands over access to their mailbox, files, or directory data. Lock this down: allow user consent only for apps from verified publishers (and only for low-risk permissions), and route everything else through an admin consent workflow so someone's actually reviewing what's asking for access before it's granted. It's a policy change that closes off one of the more common paths for data exfiltration and data spillage, and it's one I still find wide open in most tenants I walk into.

If you really want to drop the proverbial hammer, you can lock this down even further, completely disabling a non-admin's ability to consent to apps.

For more details: ([https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent?pivots=portal](https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent?pivots=portal&ref=guardians-of-kings-landing.ghost.io))

## 9\. Set Up Access Reviews for Guests and Privileged Groups

Guest accounts and role-assigned groups have a way of accumulating over time like ice on the Wall, nobody notices until there's a real problem. Access Reviews let you automate a recurring check-in: do these guests still need access? Are these group members still doing the job that earned them that role? Schedule quarterly reviews and let Entra route the approvals to the right owners instead of relying on someone remembering to do it manually.

## 10\. Send Entra Sign-In and Audit Logs to Log Analytics

Last one, and it's close to my heart right now since I'm knee-deep in building videos revolving this. Entra's free tier retention is short, and the built-in log view just isn't built for real investigation. Standing up a Log Analytics workspace and enabling diagnostic settings to export your sign-in and audit logs gives you real query power with KQL, longer retention, and a foundation you can build Sentinel analytics rules on top of later. If you're not capturing this data somewhere durable, you're flying without a raven network, you won't know trouble's coming until it's already at the gate.

If you’re interested in how to setup and configure your Log Analytics Workspace, head on over to: [**Exporting Sign-In Data to a Log Analytics Workspace (tutorial/walkthrough)**](https://www.youtube.com/watch?v=M-zt1sH1d28&ref=guardians-of-kings-landing.ghost.io)

---

None of these are a full identity program on their own, but stack all ten together and you've meaningfully hardened your tenant's front line. Pick a few you haven't tackled yet, work through them this month, and keep building from there.

Thanks for reading! Drop a comment for topics you'd like to see covered or your thoughts on my top 10.

Stay vigilant out there.

— Kevin