A cybersecurity analyst reviews a digital dashboard showing identity controls, access settings, security ratings, and configuration alerts.
CoreView has opened a new research arm, Intelligence Labs, and aimed it at a familiar IT problem: teams that think their Microsoft 365 tenant is in good shape and haven't checked. The launch makes for a useful reality check on tenant security. It is a vendor initiative, though. It is not a Microsoft advisory, and nothing in Microsoft 365 itself has changed.

What CoreView launched​

IT Brief UK is not the source for the next line. The lab's own pages describe it as a home for practical Microsoft 365 security and administration content. The stated topics include identity and access risk, configuration drift, SharePoint permissions, Conditional Access, audit gaps, AI readiness, tenant recovery and the limits of Microsoft-native tooling in complex tenants. CoreView says each article is written by a named practitioner and technically reviewed. It also says it doesn't use AI to draft or edit the content. Those are CoreView's claims about its own process, and I haven't independently verified them.

IT Brief UK reports that the lab is led by Kasper Lindgaard, CoreView's Vice President of Security Strategy. He previously led Secunia Research and has served as a CISO in regulated services. IT Brief also says the lab will analyse newly disclosed attacks. The lab pages I reviewed don't show a specific attack analysis as part of the launch, so treat that as a stated intention.

At launch, the article list leans heavily on Entra ID:

  • Applications and non-human identities in Entra (August 17)
  • Best practices for enabling and enforcing passkeys (August 27)
  • What Microsoft's passkey rollout means for admins (September 3)
  • How enterprise applications authenticate in Entra ID (September 4)
  • A practical guide to authentication methods (September 7)
  • App registration permissions, delegated versus application (September 28)

The headline number, and what it actually means​

The figures that drove the launch coverage are easy to misread. CoreView's 2026 State of Microsoft 365 Security research says 62% of surveyed leaders rated their security posture "Established" or "Advanced." Of that confident group, 54% were missing at least one of three controls:

  • MFA enforced on administrator accounts
  • A privileged access management solution
  • A defined way to detect configuration tampering

The 54% applies to the confident 62%, not to every respondent. That is a narrower claim than "more than half of all organisations lack basic controls."

CoreView also reports these related survey findings:

  • Full MFA enforcement was 62% for standard users and 55% for administrator accounts.
  • 73% had some form of privileged access management, up from 50% a year earlier.
  • 38% detect configuration tampering through manual review, and 17% have no defined method.
  • 83% run multiple tenants, and 63% say access reviews take too much time.
  • Respondents cited administrative overhead (40%) and the difficulty of creating custom Entra roles (38%) as obstacles to least privilege.

How far to trust the survey​

Treat this as vendor research, not a census.

  • Sample: 279 IT, security, infrastructure and compliance leaders, all at organisations with more than 1,000 employees.
  • Geography: About 86% were in the United States and 7% in Canada.
  • Missing detail: The material I reviewed gives no field dates, recruitment method, response rate or weighting.
  • Incentive: CoreView sells tools that fill exactly the gaps the survey highlights. That doesn't make the numbers wrong, but it is a reason to read them as directional.

The finding itself matches ordinary admin experience. A "maturity" self-rating is a feeling. Admin MFA coverage and tamper detection are checkable facts. Where the two disagree, the checkable facts should win.

The Microsoft change behind the passkey articles​

The lab's passkey coverage ties into a real Microsoft change, and other outlets corroborate it. Several write-ups of Microsoft Message Center post MC1426371 say passkeys became the default authentication experience in Entra on September 1, 2026. Users enabled for Microsoft-provided SMS or voice are auto-enrolled for passkeys, and the Registration Campaign switches to Microsoft-managed, nudging them to register a passkey at their next MFA sign-in.

The retirement dates are where sources differ, so check your own Message Center:

  • Entra.News Daily's summary of the post lists February 1, 2027 for the retirement of Microsoft-provided SMS and voice, and July 1, 2027 for Global Admins and external users.
  • ChangePilot reports that Microsoft revised the timeline on September 15, 2026, and that the overall deadline moved from February 28 to July 30, 2027. That date does not match the other summaries, so I wouldn't plan around it without confirming in your tenant.
  • LoginTC says a tenant-level opt-out is available from September 1, 2026 until February 1, 2027, set through Microsoft Graph with optOutSettings.passkeyDynamicMigration. It excludes the tenant from automatic passkey enablement and the registration campaign only during that window.
  • Entra.News Daily says customers who still need SMS or voice will be able to choose a telecom provider through the Microsoft Security Store from October 30, 2026.

The lab's passkey page gives only the September 1, 2026 and February 1, 2027 dates. If you rely on a single summary, you can miss the later dates for Global Admins and external users. That is the kind of detail a tenant owner needs to confirm in Message Center.

A practical checklist​

You don't need to read any of CoreView's articles to test the survey's three gaps against your own tenant.

  1. Admin MFA. Confirm every administrator account is covered by an enforced MFA or Conditional Access policy. "Most admins" is not a result.
  2. Privileged access. Check whether privileged roles are time-bound and approved through a PAM tool such as Entra Privileged Identity Management, or a third-party equivalent, rather than permanently assigned.
  3. Tamper detection. Decide how you would learn that a security setting, Conditional Access policy or role assignment changed. If the answer is "someone would notice," that is a manual review at best.
  4. Phone-based MFA. List users and admins whose only method is SMS or voice, and decide whether to move them to passkeys or another phishing-resistant method before the retirement dates.
  5. App identities. Review app registrations and enterprise applications, including whether permissions are delegated or application-level, since non-human identities sit outside most MFA conversations.

Check any operational advice, from CoreView or anyone else, against current Microsoft documentation and your own licensing. Some of these controls depend on specific Entra licences.

Bottom line​

Intelligence Labs is a new, vendor-run source of Entra and Microsoft 365 guidance, with a practitioner-written, Entra-heavy backlog already published. Its main claim is that confidence and control coverage don't line up, and that is plausible but rests on one vendor's survey. The part with a hard deadline is Microsoft's passkey and SMS retirement. Verify your tenant's exact dates in Message Center and test the three controls above.

 

References

  1. CoreView launches Microsoft 365 security research lab - IT Brief UK IT Brief UK 2026-10-06T09:15:00+00:00
  2. CoreView Intelligence Labs | Microsoft 365 Insights coreview.com
  3. CoreView Intelligence Labs – About Our Research Team coreview.com