Network boundaries matter less each year; identity has absorbed their role. The practical consequence is that the attack surface includes every credential, token, key and grant that can authenticate.
What to enumerate
Accounts. Human, service, break-glass, legacy, and those belonging to people who left. Count the ones with privileged roles, and the ones that have never been used.
Authentication methods. Which accounts can sign in with a password alone, where legacy protocols bypass multi-factor, and which conditional access policies have exclusions — exclusions are where the real risk lives.
Keys and tokens. Long-lived API keys, personal access tokens, service account keys and their age. A ten-year-old key with broad scope is a perimeter nobody is watching.
Consents and grants. OAuth applications granted access to mail and files, and who approved them. Malicious consent is a quiet, effective route into a tenant.
Federation and trust. Trusts between directories, external collaboration settings and anything that lets another organisation's identity assert itself in yours.
Reducing it
Short-lived credentials wherever possible, privileged access that is requested rather than held, strong factors everywhere with the exclusions reviewed monthly, and a joiner-mover-leaver process that actually removes access on the leaving date.
Then test it: given a single compromised standard account, map every path to privilege. That map is your real attack surface, and it is usually shorter than anybody expects.