
Tests authored
- CIS.M365.5.1.4.6Ensure users are restricted from recovering BitLocker keys
- MT.1049Conditional Access policies for User Risk and Sign-in Risk should be configured separately.
- MT.1052At least one Conditional Access policy is targeting the Device Code authentication flow.
- MT.1183Temporary bypass for onPremisesObjectIdentifier updates should be disabled
- MT.1184Conditional Access policy without any target resources configured
- MT.1185Block legacy MSOnline (MSOL) PowerShell module
- MT.1186High-privilege first-party Entra Apps should only have explicitly assigned users instead of All Users.
Also contributed to
- MT.1002App management restrictions on applications and service principals is configured and enabled.
- MT.1007At least one Conditional Access policy is configured to require MFA for all users.
- MT.1011At least one Conditional Access policy is configured to secure security info registration only from a trusted location.
- MT.1013At least one Conditional Access policy is configured to require new password when user risk is high.
- MT.1016At least one Conditional Access policy is configured to require MFA for guest access.
- MT.1021Security Defaults are enabled.
- MT.1033MT.1033.$($RegularUsers.IndexOf($_)): User should be blocked from using legacy authentication ($($_.userPrincipalName))
- MT.1038Conditional Access policies should not include or exclude deleted groups.
