← What we check

Review recent privileged changes

IdentityMedium severity

Lists the privileged changes made in your tenant recently — apps granted access, new app secrets, and accounts given admin roles. These are the first things an attacker does after getting in, because each one survives a password reset. They are also normal administration, so the point is to confirm each one was you.

A scan reports where your tenant stands on this check — pass, fail with a step-by-step fix, or not applicable if your licensing doesn’t include the feature. When Tenant Strike can’t read a setting with read-only access, it says unverified and gives you a one-command way to confirm it yourself — it never guesses.

Check your own tenant

Is your tenant covered on "review recent privileged changes"?

One read-only scan answers it — this check and every other one in the catalog, each with a plain-English fix. 7-day Pro trial, no credit card.