Agent Foskett Academy • Microsoft Entra • Module 3 • Lesson 33

Lesson 33 — Microsoft Entra Recommendations

Microsoft Entra Recommendations provide personalised insights and actionable guidance designed to help keep a tenant secure, healthy and effectively used.

A recommendation is not merely a generic best-practice statement. It can identify a tenant-wide issue or specific affected resources, explain why the condition matters, assign a Microsoft priority and provide guidance for remediation.

This lesson explains how to open and interpret recommendations, validate their scope, distinguish security, health and usage findings, assess business impact, manage recommendation status and implement changes safely without treating every recommendation as an automatic instruction.

Recommendations should begin an investigation. Confirm the affected resources, technical prerequisites and business impact before changing production identity controls.
Agent Foskett Microsoft Entra Recommendations lesson
What you will learn

This lesson explains how to investigate Microsoft Entra Recommendations, validate affected resources, prioritise findings and manage remediation through a controlled operational workflow.

Recommendation anatomy
Scope and impact
Status and remediation
Review and governance

Learning objectives

After completing this lesson, you should be able to investigate and manage Microsoft Entra Recommendations as part of normal identity operations.

  • Explain what Microsoft Entra Recommendations are.
  • Distinguish security, health and usage recommendations.
  • Interpret priority, impact, affected resources and status.
  • Validate whether a recommendation applies to the tenant.
  • Assess business and authentication impact before remediation.
  • Use completed, dismissed and postponed statuses appropriately.
  • Retain evidence for implementation and exceptions.
  • Build a repeatable recommendation-review process.

The problem this solves

Identity environments change continuously. Applications become stale, credentials approach expiry, configuration drifts and new Microsoft guidance becomes applicable.

Recommendations turn these conditions into a visible operational backlog instead of leaving administrators to discover them only during incidents or audits.

Recommendation lifecycle

Tenant data evaluated ↓ Condition detected ↓ Recommendation generated ↓ Priority and impact assigned ↓ Affected resources identified ↓ Administrator validates finding ↓ Remediate, postpone or dismiss ↓ Evidence retained ↓ Tenant reassessed ↓ Recommendation completed or reopened

What Microsoft Entra Recommendations are

Microsoft Entra Recommendations provide personalised insights and actionable guidance based on the configuration and activity of the tenant.

They give administrators a holistic view across security, health and usage rather than limiting attention to a single score.

What recommendations are not

A recommendation is not proof of compromise, a mandatory compliance requirement or an instruction to change production immediately.

It is a finding that should be validated against the organisation's architecture, licensing, risk and operational dependencies.

Recommendation categories

CategoryPrimary concernExample investigation question
SecurityReduce identity attack exposureWhich users, apps or credentials remain exposed?
HealthMaintain reliable identity servicesCould this condition interrupt authentication or provisioning?
UsageImprove adoption and remove wasteIs the resource unused, underused or incorrectly configured?

Where to find recommendations

In the Microsoft Entra admin centre, browse to Entra ID > Overview > Recommendations.

Access requires an appropriate read role. Microsoft documentation currently identifies Reports Reader as sufficient to view the recommendations page.

Start with the detail page

Select a recommendation rather than making a decision from the title alone.

The detail should be used to understand the rationale, affected resources, priority, impact and recommended response.

Recommendation anatomy

FieldPurposeInvestigation use
TitleSummarises the conditionUse as the starting hypothesis—not the conclusion
DescriptionExplains the finding and security or operational valueIdentify the intended risk reduction
PriorityMicrosoft-assigned rankingCombine with local business risk
ImpactShows tenant-wide or resource-specific scopeEstimate potential blast radius
Affected resourcesLists objects associated with the findingValidate every object before remediation
StatusTracks operational handlingRecord active, completed, dismissed or postponed work
Action guidanceProvides remediation directionTranslate into a tested change plan

Priority is not local risk

Microsoft priority helps organise findings, but it does not know every application dependency, privileged workflow, regulatory obligation or compensating control in your organisation.

Combine Microsoft priority with local risk and impact.

Local prioritisation factors

  • Privileged or tenant-wide exposure
  • Number and sensitivity of affected resources
  • Likelihood of exploitation or service failure
  • Existing compensating controls
  • Implementation complexity
  • Authentication and business disruption risk

Priority decision matrix

Microsoft priorityLocal impactRecommended handling
HighHighOpen an urgent remediation plan and assign accountable ownership
HighLowValidate quickly and implement where safe
MediumHighEscalate based on local business exposure
MediumLowSchedule into the normal improvement cycle
LowHighDo not ignore; local risk may override vendor priority
LowLowBacklog, dismiss or postpone with rationale

Tenant-wide impact

A tenant-wide recommendation may affect authentication policy, privileged access, directory configuration or the organisation's broad identity posture.

These changes require careful scoping, pilot testing, emergency-access protection and rollback planning.

Resource-specific impact

Resource-specific recommendations identify individual applications, service principals, credentials, users or other objects requiring attention.

Confirm ownership and actual usage before modifying or deleting the resource.

Affected-resource investigation

Open affected-resource list ↓ Record object ID and display name ↓ Identify business and technical owner ↓ Check sign-in, audit and usage evidence ↓ Confirm production dependency ↓ Review credentials, permissions and assignments ↓ Is the resource genuinely affected? ┌────────────┴────────────┐ ↓ ↓ Yes No or unclear ↓ ↓ Plan remediation Postpone or dismiss and validation with evidence

Common application recommendations

Recommendations may identify unused applications, expiring service principal credentials or configuration that no longer follows current guidance.

Application findings require business-owner confirmation because low visible usage does not automatically mean an object is safe to remove.

Application evidence

  • Service principal and application object IDs
  • Sign-in and token activity
  • Credential expiry and ownership
  • Assigned permissions and roles
  • User and group assignments
  • Change records and application documentation

Common identity recommendations

Identity findings can address stronger authentication, privileged-role protection, legacy exposure, tenant hygiene and other recommended controls.

The exact catalogue evolves as Microsoft updates the service.

Validate authentication changes

Changes involving MFA, Conditional Access, authentication methods or legacy protocols can affect every user or a critical application.

Use report-only or staged deployment where supported and preserve emergency access.

Safe remediation workflow

Recommendation accepted ↓ Define intended risk reduction ↓ Identify owners and affected resources ↓ Confirm prerequisites and licensing ↓ Capture current configuration ↓ Design pilot and success criteria ↓ Test representative users and apps ↓ Approve production rollout ↓ Monitor sign-ins, audit and service health ↓ Verify recommendation status

Recommendation status

Status allows the team to communicate how the recommendation is being handled.

Microsoft's recommendation model supports active work and outcomes such as completed, dismissed and postponed.

Status is not evidence

Changing a recommendation status does not prove that the underlying control is correct.

Keep configuration, testing, approval and ownership evidence outside the recommendation status itself.

Status selection guide

StatusUse whenRequired evidence
ActiveThe finding still applies and has not been resolvedOwner, priority and next action
CompletedThe control or corrective action has been implemented and verifiedConfiguration and validation results
DismissedThe recommendation is incorrect, not applicable or intentionally rejectedTechnical rationale and risk approval
PostponedMore review, dependency removal or scheduled work is requiredReason, owner and future review date

When to postpone

Postpone when the recommendation is valid but cannot yet be implemented safely.

Typical reasons include application remediation, pilot preparation, licensing, change freezes or dependency on another security project.

When to dismiss

Dismiss only after establishing that the finding is incorrect, not applicable or intentionally accepted.

A dismissal should have a durable explanation because future reviewers may not know the original context.

Exception workflow

Recommendation cannot be implemented ↓ Confirm recommendation is technically valid ↓ Document blocker or non-applicability ↓ Identify residual risk ↓ Apply compensating controls ↓ Obtain accountable approval ↓ Choose postponed or dismissed ↓ Record review or expiry date ↓ Reassess when conditions change

Completion validation

After implementing a recommendation, verify the tenant configuration directly and confirm the affected resources behave as expected.

Allow for service reassessment before assuming that a delayed status update means the remediation failed.

Validation sources

  • Microsoft Entra Audit Logs
  • Sign-in Logs
  • Provisioning Logs
  • Application activity
  • Policy configuration and report-only results
  • Recommendation status and affected-resource refresh

Implementation evidence package

EvidenceWhy retain it
Recommendation detailsPreserves the original finding, priority and affected scope
Resource inventoryRecords object IDs, owners and dependencies
Pre-change stateSupports risk review and rollback
Test plan and resultsDemonstrates safe behaviour before rollout
Post-change stateProves implementation
Operational monitoringShows authentication and service health remained stable
Status decisionExplains completed, postponed or dismissed handling

Email notifications

Microsoft Entra can send recommendation email notifications, helping administrators identify new findings without relying only on manual portal reviews.

Notifications should route to an actively monitored security or identity operations process.

Notifications need ownership

An email alert is useful only when a person or team is responsible for reviewing it, creating a work item and tracking the outcome.

Do not direct important recommendations to an unattended administrator mailbox.

Operational review cadence

FrequencyActivityOutcome
On notificationTriage new high-priority recommendationsImmediate owner and initial risk decision
WeeklyReview new and changing affected resourcesUpdated work queue
MonthlyReview all active, postponed and dismissed findingsGovernance report and overdue actions
QuarterlyRevalidate exceptions and business ownersRenewed approval or remediation
After major changeReview recommendations and affected resourcesDetection of new posture or health issues

Agent Foskett investigation: “The recommendation looked critical…”

1. A high-priority recommendation appears ↓ 2. An administrator prepares an immediate tenant-wide change ↓ 3. Agent Foskett opens the recommendation detail ↓ 4. The affected-resource list contains only a legacy pilot group ↓ 5. Sign-in and policy evidence show a compensating control ↓ 6. One production application still depends on the legacy path ↓ 7. Immediate enforcement would interrupt business access ↓ 8. The recommendation is valid—but the first remediation plan is unsafe ↓ 9. A pilot, application fix and staged rollout are approved ↓ 10. The recommendation is postponed with evidence and a target date ↓ 11. After successful testing, the control is implemented and verified
The recommendation was important. The dangerous part was treating its title as permission to skip scope validation, application testing and change control.

Security indicators

  • New high-priority security recommendations.
  • Privileged identities or applications in affected resources.
  • Expiring application credentials.
  • Stale applications retaining powerful permissions.
  • Recommendations reopening after configuration regression.
  • Dismissals without risk ownership or evidence.

Operational indicators

  • Recommendations remain active without owners.
  • Postponed findings have no review date.
  • Affected resources have unknown business owners.
  • Completed status is used before validation.
  • Email notifications go to an unattended mailbox.
  • Recommendations are reviewed only during audits.

Recommendation review checklist

Review areaQuestionEvidence
RationaleWhat security, health or usage problem is being identified?Recommendation detail
ScopeIs the impact tenant-wide or resource-specific?Affected-resource list
OwnershipWho owns each affected object and remediation decision?Application and service register
PriorityHow does Microsoft priority compare with local risk?Risk assessment
Change safetyCould remediation disrupt authentication or production access?Pilot and rollback plan
StatusIs completed, dismissed or postponed supported by evidence?Approval and validation record

Common mistakes

  • Acting from the recommendation title alone.
  • Assuming Microsoft priority equals local business risk.
  • Deleting an apparently unused application without owner review.
  • Applying tenant-wide authentication changes without a pilot.
  • Marking work completed before reassessment and validation.
  • Dismissing findings without a durable rationale.
  • Leaving postponed recommendations without a target date.

Best practices

  • Review the full recommendation detail.
  • Validate every affected resource.
  • Combine Microsoft priority with local risk.
  • Test authentication and application changes in stages.
  • Use recommendation status consistently.
  • Retain implementation and exception evidence.
  • Review recommendations as a normal operational process.

Key takeaways

  • Microsoft Entra Recommendations provide personalised security, health and usage guidance.
  • A recommendation can have tenant-wide or resource-specific impact.
  • Microsoft priority should be combined with local risk, ownership and business impact.
  • The affected-resource list is essential investigation evidence.
  • Recommendations should initiate controlled investigation—not automatic production change.
  • Active, completed, dismissed and postponed statuses support operational management.
  • Status does not replace configuration and testing evidence.
  • Application recommendations require ownership, usage and dependency validation.
  • Authentication recommendations should use pilots, monitoring and rollback.
  • A mature identity team reviews recommendations continuously rather than waiting for an audit.

Continue learning

Continue through Microsoft Entra posture and governance, or return to the academy roadmap.
⬅ Previous lesson
Lesson 32 — Microsoft Entra Identity Secure ScoreMeasure identity security posture, prioritise improvements and investigate score changes.
🏠 Academy home
Microsoft Entra AcademyReview the roadmap and continue through the identity security learning path.
📘 Next lesson
Lesson 34 — Microsoft Entra Security DefaultsUnderstand the baseline identity protections provided by Security Defaults and when Conditional Access becomes the appropriate next step.

Microsoft Entra Recommendations

Microsoft Entra Recommendations provide personalised insights and actionable guidance across tenant security, health and usage. Administrators can review priority, impact, affected resources and status before implementing or deferring remediation.

Microsoft Entra Academy Lesson 33 — Microsoft Entra Recommendations

This Agent Foskett lesson explains how to investigate Microsoft Entra Recommendations, validate affected resources, assess local risk, manage completed, dismissed and postponed status, and safely remediate identity findings.