
Tests authored
- MT.1002App management restrictions on applications and service principals is configured and enabled.
- MT.1005All Conditional Access policies are configured to exclude at least one emergency/break glass account or group.
- MT.1006At least one Conditional Access policy is configured to require MFA for admins.
- MT.1007At least one Conditional Access policy is configured to require MFA for all users.
- MT.1008At least one Conditional Access policy is configured to require MFA for Azure management.
- MT.1009At least one Conditional Access policy is configured to block other legacy authentication.
- MT.1010At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync.
- MT.1011At least one Conditional Access policy is configured to secure security info registration only from a trusted location.
- MT.1012At least one Conditional Access policy is configured to require MFA for risky sign-ins.
- MT.1013At least one Conditional Access policy is configured to require new password when user risk is high.
- MT.1014At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for admins.
- MT.1015At least one Conditional Access policy is configured to block access for unknown or unsupported device platforms.
- MT.1016At least one Conditional Access policy is configured to require MFA for guest access.
- MT.1017At least one Conditional Access policy is configured to enforce non persistent browser session for non-corporate devices.
- MT.1018At least one Conditional Access policy is configured to enforce sign-in frequency for non-corporate devices.
- MT.1019At least one Conditional Access policy is configured to enable application enforced restrictions.
- MT.1020All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope them.
- MT.1022All users utilizing a P1 license should be licensed.
- MT.1023All users utilizing a P2 license should be licensed.
- MT.1024MT.1024.$($RecommendationId -replace
- MT.1033MT.1033.$($RegularUsers.IndexOf($_)): User should be blocked from using legacy authentication ($($_.userPrincipalName))
- MT.1147Do not sync krbtgt_AzureAD to Entra ID
Also contributed to
- CISA.MS.AAD.4.1Security logs SHALL be sent to the agency's security operations center for monitoring.
- CISA.MS.AAD.7.6Activation of the Global Administrator role SHALL require approval.
- CISA.MS.EXO.7.1External sender warnings SHALL be implemented.
- EIDSCA.AF01Authentication Method - FIDO2 security key - State.
- EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set up.
- EIDSCA.AF03Authentication Method - FIDO2 security key - Enforce attestation.
- EIDSCA.AF04Authentication Method - FIDO2 security key - Enforce key restrictions.
- EIDSCA.AF05Authentication Method - FIDO2 security key - Restricted.
- EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keys.
- EIDSCA.AG01Authentication Method - General Settings - Manage migration.
- EIDSCA.AG02Authentication Method - General Settings - Report suspicious activity - State.
- EIDSCA.AG03Authentication Method - General Settings - Report suspicious activity - Included users/groups.
- EIDSCA.AM01Authentication Method - Microsoft Authenticator - State.
- EIDSCA.AM02Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP.
- EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notifications.
- EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications.
- EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications.
- EIDSCA.AM07Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications.
- EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications.
- EIDSCA.AM10Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications.
- EIDSCA.AP01Default Authorization Settings - Enabled Self service password reset for administrators.
- EIDSCA.AP04Default Authorization Settings - Guest invite restrictions.
- EIDSCA.AP05Default Authorization Settings - Sign-up for email based subscription.
- EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validation.
- EIDSCA.AP07Default Authorization Settings - Guest user access.
- EIDSCA.AP08Default Authorization Settings - User consent policy assigned for applications.
- EIDSCA.AP09Default Authorization Settings - Allow user consent on risk-based apps.
- EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create Apps.
- EIDSCA.AP14Default Authorization Settings - Default User Role Permissions - Allowed to read other users.
- EIDSCA.AT01Authentication Method - Temporary Access Pass - State.
- EIDSCA.AT02Authentication Method - Temporary Access Pass - One-time.
- EIDSCA.AV01Authentication Method - Voice call - State.
- EIDSCA.CP01Default Settings - Consent Policy Settings - Group owner consent for apps accessing data.
- EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky apps.
- EIDSCA.CP04Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to.
- EIDSCA.CR01Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature.
- EIDSCA.CR02Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests.
- EIDSCA.CR03Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire.
- EIDSCA.CR04Consent Framework - Admin Consent Request - Consent request duration (days).
- EIDSCA.PR01Default Settings - Password Rule Settings - Password Protection - Mode.
- EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory.
- EIDSCA.PR03Default Settings - Password Rule Settings - Enforce custom list.
- EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds.
- EIDSCA.PR06Default Settings - Password Rule Settings - Smart Lockout - Lockout threshold.
- EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner.
- EIDSCA.ST09Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content.
- MT.1001At least one Conditional Access policy is configured with device compliance.
- MT.1003At least one Conditional Access policy is configured with All Apps.
- MT.1004At least one Conditional Access policy is configured with All Apps and All Users.
- MT.1021Security Defaults are enabled.
- MT.1025No external user with permanent role assignment on Control Plane.
- MT.1026No hybrid user with permanent role assignment on Control Plane.
- MT.1027No Service Principal with Client Secret and permanent role assignment on Control Plane.
- MT.1028No user with mailbox and permanent role assignment on Control Plane.
- MT.1029Stale accounts are not assigned to privileged roles.
- MT.1030Eligible role assignments on Control Plane are in use by administrators.
- MT.1031Privileged role on Control Plane are managed by PIM only.
- MT.1032Limited number of Global Admins are assigned.
- MT.1034MT.1034.$($EmergencyAccessUsers.IndexOf($_)): Emergency access users should not be blocked ($($_.userPrincipalName))
- MT.1042Restrict dial-in users from bypassing a meeting lobby
- MT.1045Only invited users should be automatically admitted to Teams meetings
- MT.1046Restrict anonymous users from joining meetings
- MT.1047Restrict anonymous users from starting Teams meetings
- MT.1048Limit external participants from having control in a Teams meeting
- MT.1084Seamless Single SignOn should be disabled for all domains in EntraID Connect servers.
- MT.1085Pending approvals for Critical Asset Management should not be present
