Acme Corporation
Demo · read-onlyAcme Corporation (Demo) · acme.example.com · last scan: Scan, 10/06/2026, 22:38:05Microsoft Entra ID P1via Microsoft 365 E3
You have gaps that should be closed quickly.
Almindelige medarbejdere uden MFA og administratorer uden phishing-resistent MFA skaber dobbelt angrebsflade for legitimationstyveristyring og privilege-eskalation. 2 things require a decision from you.
What you need to decide now
2 things cannot be resolved by the system alone — they require a decision from leadership. You don't need to understand the technical details.
Administrator accounts aren't phishing-resistant
Your administrators are not fully protected against phishing. Either they don't have phishing-resistant login set up (security key, Windows Hello or passkey) — or they DO have it set up, but there's no rule that forces them to use it at sign-in. If only one is in place, administrators can still sign in with weaker methods like SMS or push — which can be tricked by a fake login page.
Not all employees use two-step sign-in
Without two-step sign-in, a stolen password is enough for an attacker to access the account and the rest of your Microsoft 365.
Quick metrics from your Microsoft 365
Direct readings — not controls. Shows the current state of your environment, not whether a specific rule is configured. Click a row to see the underlying accounts or log.
Tekniske detaljer for jeres IT-afdelingrå sign-in-data, lande og verdenskort
Åbn kortet for detaljer pr. land, by og fejlede forsøg