The live run timestamp is 2026-09-12 00:07:46 UTC. The public audit script completed 8/8 collection scans and 5/5 principal checks. This run occurred on September 11 in America/Chicago.
| Graph inventory | Count | Coverage |
|---|---|---|
| Role definitions | 145 | Complete |
| Active directory-role assignments | 9 | Complete |
| Directory-role eligibility instances | 0 | Complete |
| Conditional Access policies (v1.0) | 1 | Complete |
| Conditional Access policies (beta) | 1 | Complete |
| Groups | 10 | Complete |
| Administrative units (beta) | 0 | Complete |
| Access-package assignment policies | 0 | Complete |
All five scoped principals had completed transitive active-role, group-membership, user-state, and directory-role eligibility checks. The earlier directory-eligibility permission failure was resolved by this later read-only run, which returned zero directory-role eligibility instances. PIM eligibility for group membership or ownership remains outside the audit.
The ten groups included zero dynamic groups. No memberOf-rule candidates were found in the completely scanned groups, administrative units, or access-package assignment policies. This is an inventory finding, not a tested migration or proof that replacement rules are equivalent.
The v1.0 and beta Conditional Access inventories each returned the same single policy, which was disabled. Neither inventory contained a risk-policy candidate. This alone cannot establish the state of the older ID Protection policy pages.
Separate manual UI review found the legacy user-risk policy Disabled and sign-in-risk policy Disabled. Screenshots 06-legacy-user-risk-retirement.png and 07-legacy-signin-risk-retirement.png preserve the October 1, 2026 retirement banner. The public script correctly retains ManualReviewRequired for these UI-only checks; it does not infer their state from the CA inventory.
Counts describe the tenant with the isolated lab fixtures still present. This audit changed no cloud settings, ran no remediation, and does not establish license compliance or complete PIM coverage. Additional audit read permissions were limited to the administrative reader; operator action-test scopes were unchanged.
The audit implemented only Graph GET requests. The administrative token retained earlier TAP and authentication-policy write scopes, so this is evidence of read-only execution, not a token restricted exclusively to reads.
The companion JSON exports counts, labels, statuses, and provenance checksums without directory identifiers or credentials.
