| Scope and inventory | Tenant details, management-group tree, subscriptions, resource inventory, regions, owners, criticality, data classification | Current date, complete scope, reconciled orphan resources, named owner | What exists, where is it, who owns it, and what matters most? |
| Identity | Users, guests, authentication methods, Conditional Access, emergency accounts, risk policies, service principals, managed identities | Coverage measured, exclusions explained, inactive identities reviewed | Who or what can authenticate, and under which conditions? |
| Privilege | Entra roles, Azure RBAC, classic administrators, PIM settings, activations, approvals, access reviews | Role, scope, duration, reason, reviewer, and last use are visible | Who can change high-impact cloud controls? |
| Governance | Policy definitions, initiatives, assignments, exemptions, compliance state, Defender plans, recommendations, standards | Inheritance understood, remediation tracked, exceptions expire | How does the organization prevent and detect configuration drift? |
| Network | Topology, VNets, subnets, NSGs, routes, firewalls, WAF, DDoS, public IPs, private endpoints, DNS, flow data | Effective paths verified from source to destination | Which communication paths are possible, expected, and monitored? |
| Workloads | VMs, extensions, endpoint status, patching, images, registries, AKS, App Service, Functions, vulnerability results | Criticality and exposure enrich findings; fixes are rescanned | Can workloads resist known exploitation and unauthorized change? |
| Data and secrets | Storage and database configuration, identities, private access, encryption, Key Vault RBAC, rotation, deletion protection | Control plane and data plane both reviewed | How are sensitive data and credentials protected throughout their lifecycle? |
| Monitoring | Diagnostic settings, workspaces, retention, data connectors, analytics rules, incidents, playbooks, response tickets | Required sources ingest; test events create actionable incidents | Will the organization know when a material security event occurs? |
| Recovery | Protected items, policies, vault security, Resource Guard, alerts, restore procedures, test results, recovery exceptions | Recovery objectives measured; tests include application validation | Can the organization restore trustworthy operations after destructive activity? |
| Remediation | Findings register, risk rating, owner, due date, change record, rollback, retest, residual risk, closure approval | Original test repeated; evidence linked; overdue risk escalated | Are findings actually reducing risk, or only moving between reports? |