Read-only audit of authentication backends on MikroTik RouterOS: RADIUS secret handling and exposure, Message-Authenticator requirement, CoA/incoming without source restriction, single RADIUS without a pair, AAA default group, RADIUS over untrusted networks, accounting, PPP secrets and profiles, PPP authentication methods, User Manager exposure. This skill should be used when assessing how a RouterOS device authenticates administrators and subscribers, without changing configuration.