
Tests authored
- CIS.M365.8.1.1(L2) Ensure external file sharing in Teams is enabled for only approved cloud storage services
- CIS.M365.8.2.2(L1) Ensure communication with unmanaged Teams users is disabled
- CIS.M365.8.4.1(L1) Ensure all or a majority of third-party and custom apps are blocked
- CIS.M365.8.5.3(L1) Ensure only people in my org can bypass the lobby
- CIS.M365.8.6.1(L1) Ensure users can report security concerns in Teams to internal destination
- MT.1050Apps with high-risk permissions having a direct path to Global Admin
- MT.1051Apps with high-risk permissions having an indirect path to Global Admin
- MT.1053Ensure intune device clean-up rule is configured
- MT.1054Ensure built-in Device Compliance Policy marks devices with no compliance policy assigned as 'Not compliant'
- MT.1071At least one Conditional Access policy explicitly includes Azure DevOps.
- MT.1072Conditional access policies should not use the deprecated Approved Client App grant.
- MT.1073Soft- and hard-matching of synchronized objects should be blocked.
- MT.1074Mailboxes should not send outbound mails using the .onmicrosoft.com domain.
Also contributed to
- CIS.M365.1.2.2(L1) Ensure sign-in to shared mailboxes is blocked
- CIS.M365.1.3.1(L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
- CISA.MS.AAD.3.5The authentication methods SMS, Voice Call, and Email One-Time Passcode (OTP) SHALL be disabled.
- MT.1017At least one Conditional Access policy is configured to enforce non persistent browser session for non-corporate devices.
- MT.1021Security Defaults are enabled.