Microsoft Entra ID

Microsoft Entra ID

Identity, MFA and access review evidence
Connect
Connect
More Popular integrations
DATEV
Accounting and payroll software
DocuSign
Electronic signatures
Salesforce
CRM platform

Teddy connects to Microsoft Entra ID with its own read-only service account and collects identity evidence on a schedule.

What Teddy collects

  • MFA status for every account
  • User and group lists for access reviews
  • Joiner, mover and leaver changes

Frameworks and controls

  • ISO 27001:2022: A.5.15 Access control, A.5.16 Identity management, A.5.18 Access rights, A.8.5 Secure authentication
  • SOC 2: CC6.1, CC6.2 and CC6.3 on logical access
  • NIS2: Article 21(2)(i) access control and 21(2)(j) multi-factor authentication
  • TISAX®: identity and access management requirements of the ISA

How it works

  1. You approve the permission list and connect Entra ID with a dedicated service account.
  2. Teddy collects MFA status, users and groups on a schedule, daily or weekly.
  3. Each report is linked to every control it satisfies. Accounts without MFA or former employees with access become tasks.

Access

Read-only by default. Teddy never uses a personal account, and every sync is recorded in the action log.

Does Teddy change anything in Entra ID?

No. The connection is read-only. Teddy flags accounts that need attention, and your team decides what to change.