Entra ID Access Review fuer kleine Agenturen
Claude Code prueft Leaver, Shared Accounts, Gruppen, App-Zugriff und Logs in Entra ID.
In einer kleinen Agentur bleibt Microsoft 365 Zugriff oft laenger bestehen als das Projekt. Ein Designer ist gegangen, ein Social-Media-Shared-Account ist aktiv, ein Kunde bleibt in Teams und eine alte Admin-Rolle wurde nie geprueft. Der erste sinnvolle Bildschirm ist die Entra ID Benutzerliste zusammen mit Gruppen, Apps, Sign-in logs und Audit logs.
Key Points
- Pruefe Benutzer, Gruppen, Apps, Shared Accounts, Gaeste und Rollen getrennt.
- Access reviews helfen bei wiederkehrender Kontrolle von Gruppen und Apps.
- Audit logs und Sign-in logs zeigen Aenderungen und Nutzung.
- Claude Code erstellt die Review-Tabelle; Menschen genehmigen Aktionen.
- Messe aktive Leaver, Shared Accounts ohne Owner, stale Gruppen und Review-Zeit.
Workflow: Build The Review Table First
Erstelle zuerst eine Tabelle mit Austrittsdatum, accountEnabled, Gruppen, Apps, Rollen, Owner und letzter Anmeldung. Vor Claude Code werden Namen, E-Mails und Kundennamen anonymisiert.
| Source | Review field | Human decision |
|---|---|---|
| Users | leave date, accountEnabled, department | HR status and exceptions |
| Groups | owner, guests, project end | client access and contract |
| Enterprise apps | assignment, shared account, role | business need and license |
| Sign-in logs | last activity, failures | leave, exception, or cleanup |
| Audit logs | who changed what | approval trail |
Primary sources checked: access reviews, create access reviews, audit logs, sign-in logs, Lifecycle workflows, sharing accounts, and security defaults.
What Claude Code Does And What Humans Decide
Claude Code can clean an anonymized CSV, find enabled leavers, ownerless shared accounts, stale assignments, old privileged roles, and missing owners. Humans decide disablement, deletion, license removal, role removal, guest removal, shared-account replacement, and emergency-account policy.
3 Use Cases
Use case 1: Find enabled leavers
- Input: user list, leave date, accountEnabled, groups, app assignments, last sign-in.
- Output: enabled leavers, remaining groups, app assignments, review owner.
- Human review: HR status, contractor continuation, mailbox retention, legal hold, approval.
Use Claude Code to prepare a candidate list. Do not let it delete accounts.
Use case 2: Review shared accounts
- Input: shared account list, app name, owner, MFA, last sign-in, department.
- Output: ownerless shared accounts, weak authentication, high permission, long-lived access.
- Human review: whether to move to app assignment, SSO, or another managed pattern.
The first win is visibility: owner, app, authentication method, and review date.
Use case 3: Run monthly group cleanup
- Input: groups, app assignments, owners, guests, last use, project end date.
- Output: review target, owner message, keep reason, removal candidate, next review date.
- Human review: client contract, project continuation, privileged role, audit needs.
Start with client-share groups, external guests, and admin roles.
Copy-Paste Prompt
Act as a Microsoft Entra ID access review assistant for a small agency.
Prepare a human-review table for leavers, shared accounts, stale groups, guests, and privileged roles.
Check enabled leavers, ownerless shared accounts, weak shared-account authentication, unused assignments, stale privileged accounts, and groups with guests.
Never issue deletion or disable commands.
Use anonymized IDs only.
Return the five rows to inspect today.
Working Check Code
// verify-entra-access-review.mjs
// No dependencies. Run with: node verify-entra-access-review.mjs
const accounts = [
{
userPrincipalName: "[email protected]",
department: "design",
employeeLeaveDate: "2026-06-30",
accountEnabled: true,
lastSignInDaysAgo: 2,
groups: ["client-a-share", "figma-admin"],
roles: [],
mfa: true,
owner: "manager-01"
},
{
userPrincipalName: "[email protected]",
department: "marketing",
employeeLeaveDate: null,
accountEnabled: true,
lastSignInDaysAgo: 1,
groups: ["social-media-tools"],
roles: [],
mfa: false,
owner: ""
},
{
userPrincipalName: "[email protected]",
department: "it",
employeeLeaveDate: null,
accountEnabled: true,
lastSignInDaysAgo: 120,
groups: [],
roles: ["Global Administrator"],
mfa: false,
owner: "it-lead"
}
];
const problems = [];
const today = new Date("2026-07-19T00:00:00Z");
for (const account of accounts) {
if (account.employeeLeaveDate && new Date(account.employeeLeaveDate + "T00:00:00Z") < today && account.accountEnabled) {
problems.push({ account: account.userPrincipalName, item: "leaver still enabled", fix: "disable account or run the approved offboarding workflow" });
}
if (account.userPrincipalName.includes("shared") && !account.owner) {
problems.push({ account: account.userPrincipalName, item: "shared account owner", fix: "assign an accountable owner and review app assignment" });
}
if (account.userPrincipalName.includes("shared") && !account.mfa) {
problems.push({ account: account.userPrincipalName, item: "shared account MFA", fix: "replace direct password sharing with controlled app access or strong authentication" });
}
if (account.roles.length > 0 && account.lastSignInDaysAgo > 90) {
problems.push({ account: account.userPrincipalName, item: "stale privileged account", fix: "review role need, sign-in logs, and break-glass policy" });
}
if (account.groups.length > 0 && account.lastSignInDaysAgo > 30) {
problems.push({ account: account.userPrincipalName, item: "group access review", fix: "ask the group owner to approve, deny, or remove access" });
}
}
if (problems.length > 0) {
console.table(problems);
process.exitCode = 1;
} else {
console.log("Entra ID access review checklist passed.");
}
Pitfall: Common Failure Cases
The first failure is using last sign-in as the only signal. Add leave date, owner, role, exception, and approval. The second failure is leaving shared accounts ownerless. The third failure is reviewing users but missing groups. The fourth failure is letting AI decide deletion. Claude Code prepares candidates; humans approve changes.
FAQ
Q. What should a small team review first?
A. Enabled leavers, ownerless shared accounts, and stale privileged accounts.
Q. Are access reviews only for large companies?
A. No. Start with client-share groups, guests, and privileged roles.
Q. Can shared accounts remain?
A. Sometimes, but owner, app purpose, authentication method, and review date must be visible.
Q. Can Claude Code read real logs?
A. Use anonymized CSV data. Do not include real names, emails, client names, phone numbers, or contracts.
Training And Consultation Signal
Measure enabled leavers, ownerless shared accounts, stale groups, guests, review time, and inquiry rate. If those numbers hurt, Entra ID review operations are a fit for ClaudeCodeLab Training.
What I Verified
I checked Microsoft Learn references for access reviews, audit logs, sign-in logs, Lifecycle workflows, shared accounts, and security defaults. I also checked the CTA, executable JavaScript, internal link, external links, locale coverage, and queue removal.
Ähnliche Artikel
Codex Desktop in Agenturen: Diff-, PR- und Release-Review sicher trennen
Praxisleitfaden für Agenturen: Diff, PR und Staging mit Codex prüfen; die Release-Freigabe bleibt beim Menschen.
Der 3-Minuten-Check vor dem Commit: Prüfen, was Claude Code wirklich angefasst hat
So erkennst du in drei Minuten, welche Dateien Claude Code eigenmächtig geändert hat: Diff, Prüfprotokoll und gezieltes Stagen.
Claude Code First PR Review Rubric: echte Risiken vor Stilfeedback finden
Eine praktische PR-Review-Rubrik für Claude Code mit Severity, Nachweis, Tests und Kommentaren, die Regressionen zuerst finden.
Kostenloses PDF: Claude-Code-Cheatsheet
E-Mail eintragen und eine Seite mit Befehlen, Review-Gewohnheiten und sicheren Workflows herunterladen.
Wir schützen Ihre Daten und senden keinen Spam.
Über den Autor
Masa
Engineer für praktische Claude-Code-Workflows und Team-Einführung.