App registration secrets and certificates
A secret or certificate has an end date. When it passes, every integration that signs in with it stops, usually without a warning from Microsoft.
When it breaks: sign-ins and API calls through the application stop.
Enterprise application credentials
Single sign-on to a third-party application relies on a signing certificate with an end date. When it passes, staff can no longer sign in to that application.
When it breaks: SAML sign-in to the application stops.
Applications without an owner
Microsoft warns the owners of an application before its credentials expire. An application with no owner warns nobody.
When it breaks: nobody is warned before its credentials expire.
Unused applications
An application nobody has used in a long time still holds working credentials. If one leaks, nobody notices. Confirm it is still needed or remove it.
When it breaks: a credential nobody uses stays an open door.
Domains and mail records
DNS records do not expire, but they break. A domain move, a new mail service or a rebuilt website can delete or overwrite them, and nobody notices until mail bounces or lands in spam. Remind reads the MX, SPF, DKIM and DMARC records as the Internet sees them and compares them with what Microsoft 365 expects, so a change shows here before it shows as lost mail.
When it breaks: mail from the domain bounces or lands in spam.
Intune certificates and tokens
Apple and Google require a certificate or token that Microsoft cannot renew for you. When one expires, phones and laptops stop enrolling and can fall out of management.
When it breaks: device enrollment and management stop.
Entra Connect and cloud sync
Directory synchronization copies on-premises accounts and password changes to Microsoft 365. When it stalls, new staff cannot sign in and password changes do not take effect in the cloud.
When it breaks: password changes and new users stop reaching the cloud.
Conditional Access references
A sign-in policy that still names a deleted user, group or application no longer applies to what it was meant for. Microsoft does not flag this.
When it breaks: the policy no longer applies to what it was meant for.