Skip to main content

← Back to the article

The package contains the five-topic article, two editable diagrams, thirteen lab screenshots, reusable read-only audit scripts, sanitized findings, and verified cleanup evidence. It accompanies the published article.

Start with the article, then compare the findings below with the screenshot gallery.

Screenshots have identifying account, subscription, tenant, workspace, and object labels masked. Displayed settings and test observations are unchanged; source originals remain private. The portable package uses relative links and contains no local-user paths. Evidence diagrams and screenshots retain the established cat-head and nineliveszerotrust.com footer. The social cover has one cat beside the main wordmark and keeps the site address in its footer. The current social cover is conceptual AI-generated artwork; evidence images retain their original provenance.

What the lab established

TopicEvidence obtainedLimit to preserve
Security Administrator and response rolesThree separately authenticated operators; same client and delegated scopes; 28 recorded observations; 85 corroborating audit recordsDirect Graph v1.0 tests against an ordinary user and one Global Reader target; not every portal or administrator role
Sentinel AI playbook generatorTwo onboarded workspaces inspected; classic creation menus only; no custom unified-RBAC roles, assignments, or scopes; no active Sentinel workspaces in that permission modelNo editor, generation or execution validated. The missing menu’s cause remains unresolved. Microsoft’s no-SCU documentation is not contradicted by this observation
Legacy risk-policy retirementBoth legacy pages showed the October 1 read-only/retirement notice and Disabled; CA v1.0/beta each returned the same existing disabled policyNo migration, replacement coverage or risk-remediation outcome tested
Foundational CSPM opt-inExisting subscription showed Free and On; October 27 notice visible; explicit pricing object and assessment data obtainedExisting subscription evidence cannot establish the future new-subscription default
memberOf retirementTen assigned-membership groups, zero administrative units and zero access-package assignment policies; no matching configuration foundComplete inventory of listed surfaces; no replacement-rule or November enforcement test

Strongest original finding

The role comparison separates actual state changes from accepted requests. All three operators disabled and re-enabled the ordinary target. Revocation and password-reset requests were accepted and corroborated, but live-session rejection and sign-in with a replacement password were outside the test.

An already-enabled account returned HTTP 204 for enable requests. A proper disabled-to-enabled test exposed a more useful distinction: Security Administrator and Security Operator received 403 against the Global Reader target, while SOC Identity Responder returned 204 without an observed change during eleven reads over about 21.5 seconds. The administrator restored the target afterward. This remains effect unverified, not a bypass claim.

See the role-results record and sanitized JSON.

Diagrams

Both figures include companion alt text and interpretation notes in the assets folder. The PNGs were rendered from their vector sources and visually checked.

Audits and source material

  • Reusable scripts and usage: 14 offline checks passed, followed by a live run with 8/8 listed Graph collections and 5/5 principal checks completed.
  • Readiness summary: later directory-role eligibility coverage returned zero instances. Group PIM eligibility remains outside scope.
  • CSPM findings: current plan and assessment evidence with interpretation limits.
  • Sentinel preflight: documented prerequisites and the unresolved tenant availability/authorization question.
  • Source ledger: claim-by-claim official references and date distinctions.

The audit used GET requests only. Its administrator credential also retained earlier bootstrap scopes, so the claim is read-only execution, not a token limited exclusively to read permissions. Operator action-test scopes were unchanged.

Cleanup

Cleanup was verified at 2026-09-12 00:14:30 UTC (September 11 in America/Chicago): five test users, four temporary role assignments, four delegated grants, one application and its service principal were removed. The test users were disabled and had sessions revoked before soft deletion. No permanent purge was performed.

The original five directory-role assignments and ten groups remained. The existing manual Conditional Access policy stayed disabled, the TAP configuration matched its baseline, Security Defaults remained enabled, and Security Copilot capacity remained zero. Sixteen temporary credential/authorization files were removed locally.

See the sanitized cleanup receipt. Raw operational evidence remains outside this review package.

Editorial boundaries

  1. Sentinel: the article presents the documented capability with an explicit preflight limitation. It does not portray the generator as tested.
  2. SOC enable response: the measured result and its short observation window are kept as an evidence lesson, not a vulnerability claim.
  3. Image density: the article uses two diagrams and three selected screenshots. The gallery holds the additional captures.
  4. Readiness versus enforcement: the distinction is kept for all three future deadlines. The tenant checks demonstrate current state and coverage of the audit, not future rollout behavior.

Screenshot dates and file hashes are recorded in the companion screenshot manifest. The original experiment and cleanup span September 11–12 UTC (September 11 in America/Chicago). The later audit-log follow-up occurred on September 12 and is recorded separately in the role results.