The tenant-wide settings nobody's watching
Security Defaults, guest invite policy, app consent, default user permissions, these apply to every single user in your tenant, but they live in settings screens an admin typically only ever visits once, during initial setup. A Conditional Access rollout gets Security Defaults switched off and nobody switches it back on. A guest-invite policy gets left wide open because the person who set it up six months ago has moved teams. None of these show up in a day-to-day admin view of the tenant. ID Posture checks 10 of them on every scan, so a setting that quietly drifted stays visible instead of invisible.
Ten findings, checked on every scan
Ask your ID Posture contact to enable Tenant Health for your tenant.
Why it matters
Most tenant-wide settings default to permissive. Security Defaults gets turned off once, during a Conditional Access rollout, and never turned back on. A guest invite policy gets left open because nobody remembers it exists. None of these show up in a normal admin's day-to-day view of the tenant, they're one-time settings with ongoing consequences. ID Posture checks all 10 on every scan, so a setting that quietly drifted six months ago doesn't stay invisible.
Part of ID Posture’s broader Azure resource coverage. See the full product overview, or explore SQL Security and Cosmos DB Security.
It's optional, per tenant, and off by default until you ask for it.