Lesson 33 — Microsoft Entra Recommendations
Microsoft Entra Recommendations provide personalised insights and actionable guidance designed to help keep a tenant secure, healthy and effectively used.
A recommendation is not merely a generic best-practice statement. It can identify a tenant-wide issue or specific affected resources, explain why the condition matters, assign a Microsoft priority and provide guidance for remediation.
This lesson explains how to open and interpret recommendations, validate their scope, distinguish security, health and usage findings, assess business impact, manage recommendation status and implement changes safely without treating every recommendation as an automatic instruction.

What you will learn
This lesson explains how to investigate Microsoft Entra Recommendations, validate affected resources, prioritise findings and manage remediation through a controlled operational workflow.
Learning objectives
After completing this lesson, you should be able to investigate and manage Microsoft Entra Recommendations as part of normal identity operations.
- Explain what Microsoft Entra Recommendations are.
- Distinguish security, health and usage recommendations.
- Interpret priority, impact, affected resources and status.
- Validate whether a recommendation applies to the tenant.
- Assess business and authentication impact before remediation.
- Use completed, dismissed and postponed statuses appropriately.
- Retain evidence for implementation and exceptions.
- Build a repeatable recommendation-review process.
The problem this solves
Identity environments change continuously. Applications become stale, credentials approach expiry, configuration drifts and new Microsoft guidance becomes applicable.
Recommendations turn these conditions into a visible operational backlog instead of leaving administrators to discover them only during incidents or audits.
Recommendation lifecycle
What Microsoft Entra Recommendations are
Microsoft Entra Recommendations provide personalised insights and actionable guidance based on the configuration and activity of the tenant.
They give administrators a holistic view across security, health and usage rather than limiting attention to a single score.
What recommendations are not
A recommendation is not proof of compromise, a mandatory compliance requirement or an instruction to change production immediately.
It is a finding that should be validated against the organisation's architecture, licensing, risk and operational dependencies.
Recommendation categories
| Category | Primary concern | Example investigation question |
|---|---|---|
| Security | Reduce identity attack exposure | Which users, apps or credentials remain exposed? |
| Health | Maintain reliable identity services | Could this condition interrupt authentication or provisioning? |
| Usage | Improve adoption and remove waste | Is the resource unused, underused or incorrectly configured? |
Where to find recommendations
In the Microsoft Entra admin centre, browse to Entra ID > Overview > Recommendations.
Access requires an appropriate read role. Microsoft documentation currently identifies Reports Reader as sufficient to view the recommendations page.
Start with the detail page
Select a recommendation rather than making a decision from the title alone.
The detail should be used to understand the rationale, affected resources, priority, impact and recommended response.
Recommendation anatomy
| Field | Purpose | Investigation use |
|---|---|---|
| Title | Summarises the condition | Use as the starting hypothesis—not the conclusion |
| Description | Explains the finding and security or operational value | Identify the intended risk reduction |
| Priority | Microsoft-assigned ranking | Combine with local business risk |
| Impact | Shows tenant-wide or resource-specific scope | Estimate potential blast radius |
| Affected resources | Lists objects associated with the finding | Validate every object before remediation |
| Status | Tracks operational handling | Record active, completed, dismissed or postponed work |
| Action guidance | Provides remediation direction | Translate into a tested change plan |
Priority is not local risk
Microsoft priority helps organise findings, but it does not know every application dependency, privileged workflow, regulatory obligation or compensating control in your organisation.
Combine Microsoft priority with local risk and impact.
Local prioritisation factors
- Privileged or tenant-wide exposure
- Number and sensitivity of affected resources
- Likelihood of exploitation or service failure
- Existing compensating controls
- Implementation complexity
- Authentication and business disruption risk
Priority decision matrix
| Microsoft priority | Local impact | Recommended handling |
|---|---|---|
| High | High | Open an urgent remediation plan and assign accountable ownership |
| High | Low | Validate quickly and implement where safe |
| Medium | High | Escalate based on local business exposure |
| Medium | Low | Schedule into the normal improvement cycle |
| Low | High | Do not ignore; local risk may override vendor priority |
| Low | Low | Backlog, dismiss or postpone with rationale |
Tenant-wide impact
A tenant-wide recommendation may affect authentication policy, privileged access, directory configuration or the organisation's broad identity posture.
These changes require careful scoping, pilot testing, emergency-access protection and rollback planning.
Resource-specific impact
Resource-specific recommendations identify individual applications, service principals, credentials, users or other objects requiring attention.
Confirm ownership and actual usage before modifying or deleting the resource.
Affected-resource investigation
Common application recommendations
Recommendations may identify unused applications, expiring service principal credentials or configuration that no longer follows current guidance.
Application findings require business-owner confirmation because low visible usage does not automatically mean an object is safe to remove.
Application evidence
- Service principal and application object IDs
- Sign-in and token activity
- Credential expiry and ownership
- Assigned permissions and roles
- User and group assignments
- Change records and application documentation
Common identity recommendations
Identity findings can address stronger authentication, privileged-role protection, legacy exposure, tenant hygiene and other recommended controls.
The exact catalogue evolves as Microsoft updates the service.
Validate authentication changes
Changes involving MFA, Conditional Access, authentication methods or legacy protocols can affect every user or a critical application.
Use report-only or staged deployment where supported and preserve emergency access.
Safe remediation workflow
Recommendation status
Status allows the team to communicate how the recommendation is being handled.
Microsoft's recommendation model supports active work and outcomes such as completed, dismissed and postponed.
Status is not evidence
Changing a recommendation status does not prove that the underlying control is correct.
Keep configuration, testing, approval and ownership evidence outside the recommendation status itself.
Status selection guide
| Status | Use when | Required evidence |
|---|---|---|
| Active | The finding still applies and has not been resolved | Owner, priority and next action |
| Completed | The control or corrective action has been implemented and verified | Configuration and validation results |
| Dismissed | The recommendation is incorrect, not applicable or intentionally rejected | Technical rationale and risk approval |
| Postponed | More review, dependency removal or scheduled work is required | Reason, owner and future review date |
When to postpone
Postpone when the recommendation is valid but cannot yet be implemented safely.
Typical reasons include application remediation, pilot preparation, licensing, change freezes or dependency on another security project.
When to dismiss
Dismiss only after establishing that the finding is incorrect, not applicable or intentionally accepted.
A dismissal should have a durable explanation because future reviewers may not know the original context.
Exception workflow
Completion validation
After implementing a recommendation, verify the tenant configuration directly and confirm the affected resources behave as expected.
Allow for service reassessment before assuming that a delayed status update means the remediation failed.
Validation sources
- Microsoft Entra Audit Logs
- Sign-in Logs
- Provisioning Logs
- Application activity
- Policy configuration and report-only results
- Recommendation status and affected-resource refresh
Implementation evidence package
| Evidence | Why retain it |
|---|---|
| Recommendation details | Preserves the original finding, priority and affected scope |
| Resource inventory | Records object IDs, owners and dependencies |
| Pre-change state | Supports risk review and rollback |
| Test plan and results | Demonstrates safe behaviour before rollout |
| Post-change state | Proves implementation |
| Operational monitoring | Shows authentication and service health remained stable |
| Status decision | Explains completed, postponed or dismissed handling |
Email notifications
Microsoft Entra can send recommendation email notifications, helping administrators identify new findings without relying only on manual portal reviews.
Notifications should route to an actively monitored security or identity operations process.
Notifications need ownership
An email alert is useful only when a person or team is responsible for reviewing it, creating a work item and tracking the outcome.
Do not direct important recommendations to an unattended administrator mailbox.
Operational review cadence
| Frequency | Activity | Outcome |
|---|---|---|
| On notification | Triage new high-priority recommendations | Immediate owner and initial risk decision |
| Weekly | Review new and changing affected resources | Updated work queue |
| Monthly | Review all active, postponed and dismissed findings | Governance report and overdue actions |
| Quarterly | Revalidate exceptions and business owners | Renewed approval or remediation |
| After major change | Review recommendations and affected resources | Detection of new posture or health issues |
Agent Foskett investigation: “The recommendation looked critical…”
Security indicators
- New high-priority security recommendations.
- Privileged identities or applications in affected resources.
- Expiring application credentials.
- Stale applications retaining powerful permissions.
- Recommendations reopening after configuration regression.
- Dismissals without risk ownership or evidence.
Operational indicators
- Recommendations remain active without owners.
- Postponed findings have no review date.
- Affected resources have unknown business owners.
- Completed status is used before validation.
- Email notifications go to an unattended mailbox.
- Recommendations are reviewed only during audits.
Recommendation review checklist
| Review area | Question | Evidence |
|---|---|---|
| Rationale | What security, health or usage problem is being identified? | Recommendation detail |
| Scope | Is the impact tenant-wide or resource-specific? | Affected-resource list |
| Ownership | Who owns each affected object and remediation decision? | Application and service register |
| Priority | How does Microsoft priority compare with local risk? | Risk assessment |
| Change safety | Could remediation disrupt authentication or production access? | Pilot and rollback plan |
| Status | Is completed, dismissed or postponed supported by evidence? | Approval and validation record |
Common mistakes
- Acting from the recommendation title alone.
- Assuming Microsoft priority equals local business risk.
- Deleting an apparently unused application without owner review.
- Applying tenant-wide authentication changes without a pilot.
- Marking work completed before reassessment and validation.
- Dismissing findings without a durable rationale.
- Leaving postponed recommendations without a target date.
Best practices
- Review the full recommendation detail.
- Validate every affected resource.
- Combine Microsoft priority with local risk.
- Test authentication and application changes in stages.
- Use recommendation status consistently.
- Retain implementation and exception evidence.
- Review recommendations as a normal operational process.
Key takeaways
- Microsoft Entra Recommendations provide personalised security, health and usage guidance.
- A recommendation can have tenant-wide or resource-specific impact.
- Microsoft priority should be combined with local risk, ownership and business impact.
- The affected-resource list is essential investigation evidence.
- Recommendations should initiate controlled investigation—not automatic production change.
- Active, completed, dismissed and postponed statuses support operational management.
- Status does not replace configuration and testing evidence.
- Application recommendations require ownership, usage and dependency validation.
- Authentication recommendations should use pilots, monitoring and rollback.
- A mature identity team reviews recommendations continuously rather than waiting for an audit.
Related Agent Foskett resources
Continue learning
Microsoft Entra Recommendations
Microsoft Entra Recommendations provide personalised insights and actionable guidance across tenant security, health and usage. Administrators can review priority, impact, affected resources and status before implementing or deferring remediation.
Microsoft Entra Academy Lesson 33 — Microsoft Entra Recommendations
This Agent Foskett lesson explains how to investigate Microsoft Entra Recommendations, validate affected resources, assess local risk, manage completed, dismissed and postponed status, and safely remediate identity findings.
