SecureOps Playbooks logosecureops/playbooks

Guides

Read-only Microsoft 365 playbooks for review-first admins.

These are the checks I want in front of me before I start changing a tenant. The goal is not to automate judgment away. The goal is to make the first review clearer.

The playbook ledger

Live entries are starter playbooks written as read-only examples — review the permissions, output, and limitations before using them in any production tenant. Planned entries belong to the same first-pass review workflow and go live through Dispatch.

PB-001Audit MFA Registration in Microsoft 365Review which users have authentication methods registered before assuming MFA coverage is handled.MEDIUMPB-002Find External Mailbox Forwarding in Exchange OnlineFind mailbox forwarding that may send mail outside the organization and prepare it for careful review.HIGHPB-003Review Privileged Role Assignments in Entra IDExport privileged Entra role membership before making security or access policy changes.HIGH
PB-004Find Expiring Entra App CredentialsInventory app secrets and certificates that need owner review.MEDIUM
PB-005Inventory Guest UsersList external identities and review stale or unrecognized guests.MEDIUM
PB-006Export Conditional Access PoliciesCapture policy configuration for review before edits.HIGH
PB-007Tenant Summary Quick-CheckCollect high-level Microsoft 365 tenant posture details.LOW
PB-008Licensed Users ReviewExport licensed user inventory for cleanup planning and reporting.LOW

How to read the labels

Example playbook

A starter workflow you can read, adapt, and test before using in your own environment.

Lab review pending

The content needs more review before it should be treated as tested guidance.

Production validation required

Every tenant is different. Validate scope, permissions, and output before relying on a workflow.

Coming soon

A planned read-only check that belongs in the broader tenant review workflow.