
Also contributed to
- CIS.M365.1.1.1(L1) Ensure Administrative accounts are cloud-only
- CIS.M365.1.1.3(L1) Ensure that between two and four global admins are designated
- CIS.M365.3.1.1(L1) Ensure Microsoft 365 audit log search is Enabled
- CIS.M365.5.1.4.6Ensure users are restricted from recovering BitLocker keys
- CIS.M365.5.1.5.2Ensure the admin consent workflow is enabled
- CISA.MS.AAD.2.1Users detected as high risk SHALL be blocked.
- CISA.MS.AAD.2.2A notification SHOULD be sent to the administrator when high-risk users are detected.
- CISA.MS.AAD.2.3Sign-ins detected as high risk SHALL be blocked.
- CISA.MS.AAD.7.2Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.
- CISA.MS.AAD.7.4Permanent active role assignments SHALL NOT be allowed for highly privileged roles.
- CISA.MS.AAD.7.5Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system.
- CISA.MS.AAD.7.6Activation of the Global Administrator role SHALL require approval.
- CISA.MS.AAD.7.8User activation of the Global Administrator role SHALL trigger an alert.
- CISA.MS.AAD.7.9User activation of other highly privileged roles SHOULD trigger an alert.
- EIDSCA.AG02Authentication Method - General Settings - Report suspicious activity - State.
- MT.1006At least one Conditional Access policy is configured to require MFA for admins.
- MT.1014At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for admins.
- MT.1025No external user with permanent role assignment on Control Plane.
- MT.1026No hybrid user with permanent role assignment on Control Plane.
- MT.1027No Service Principal with Client Secret and permanent role assignment on Control Plane.
- MT.1028No user with mailbox and permanent role assignment on Control Plane.
- MT.1035All security groups assigned to Conditional Access Policies should be protected by RMAU.
- MT.1050Apps with high-risk permissions having a direct path to Global Administrator
- MT.1051Apps with high-risk permissions having an indirect path to Global Administrator
- MT.1056Ensure that no person has permanent access to all Azure subscriptions at the root scope
- MT.1068Restrict non-admin users from creating tenants
- MT.1085Pending approvals for Critical Asset Management should not be present
- MT.1090Global Administrator role should not be added as local administrator on the device during Microsoft Entra join
- MT.1187The Microsoft 365 traffic forwarding profile in Global Secure Access should be enabled
- MT.1188Entra Private Access applications should be covered by a Conditional Access policy that requires a managed device
- MT.1191Break-glass accounts should be excluded from the Compliant Network Conditional Access policy
- MT.1195The Quick Access app should not be subject to a sign-in frequency Conditional Access control