
Also contributed to
- CIS.M365.1.3.3(L2) Ensure 'External sharing' of calendars is not available
- CISA.MS.AAD.1.1Legacy authentication SHALL be blocked.
- CISA.MS.AAD.2.1Users detected as high risk SHALL be blocked.
- CISA.MS.AAD.2.2A notification SHOULD be sent to the administrator when high-risk users are detected.
- CISA.MS.AAD.2.3Sign-ins detected as high risk SHALL be blocked.
- CISA.MS.AAD.3.1Phishing-resistant MFA SHALL be enforced for all users.
- CISA.MS.AAD.3.2If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.
- CISA.MS.AAD.3.3If Microsoft Authenticator is enabled, it SHALL be configured to show login context information.
- CISA.MS.AAD.3.4The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.
- CISA.MS.AAD.3.5The authentication methods SMS, Voice Call, and Email One-Time Passcode (OTP) SHALL be disabled.
- CISA.MS.AAD.3.6Phishing-resistant MFA SHALL be required for highly privileged roles.
- CISA.MS.AAD.3.7Managed devices SHOULD be required for authentication.
- CISA.MS.AAD.3.8Managed Devices SHOULD be required to register MFA.
- CISA.MS.AAD.4.1Security logs SHALL be sent to the agency's security operations center for monitoring.
- CISA.MS.AAD.5.1Only administrators SHALL be allowed to register applications.
- CISA.MS.AAD.5.2Only administrators SHALL be allowed to consent to applications.
- CISA.MS.AAD.5.3An admin consent workflow SHALL be configured for applications.
- CISA.MS.AAD.5.4Group owners SHALL NOT be allowed to consent to applications.
- CISA.MS.AAD.6.1User passwords SHALL NOT expire.
- CISA.MS.AAD.7.1A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role.
- CISA.MS.AAD.7.2Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.
- CISA.MS.AAD.7.3Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers.
- CISA.MS.AAD.7.4Permanent active role assignments SHALL NOT be allowed for highly privileged roles.
- CISA.MS.AAD.7.5Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system.
- CISA.MS.AAD.7.6Activation of the Global Administrator role SHALL require approval.
- CISA.MS.AAD.7.7Eligible and Active highly privileged role assignments SHALL trigger an alert.
- CISA.MS.AAD.7.8User activation of the Global Administrator role SHALL trigger an alert.
- CISA.MS.AAD.7.9User activation of other highly privileged roles SHOULD trigger an alert.
- CISA.MS.AAD.8.1Guest users SHOULD have limited or restricted access to Azure AD directory objects.
- CISA.MS.AAD.8.2Only users with the Guest Inviter role SHOULD be able to invite guest users.
- CISA.MS.AAD.8.3Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes.
- CISA.MS.EXO.1.1Automatic forwarding to external domains SHALL be disabled.
- CISA.MS.EXO.2.1A list of approved IP addresses for sending mail SHALL be maintained.
- CISA.MS.EXO.2.2An SPF policy SHALL be published for each domain, designating only these addresses as approved senders.
- CISA.MS.EXO.3.1DKIM SHOULD be enabled for all domains.
- CISA.MS.EXO.4.1A DMARC policy SHALL be published for every second-level domain.
- CISA.MS.EXO.4.2The DMARC message rejection option SHALL be p=reject.
- CISA.MS.EXO.4.3The DMARC point of contact for aggregate reports SHALL include [email protected].
- CISA.MS.EXO.5.1SMTP AUTH SHALL be disabled.
- CISA.MS.EXO.6.1Contact folders SHALL NOT be shared with all domains.
- CISA.MS.EXO.7.1External sender warnings SHALL be implemented.
- CISA.MS.EXO.8.1A DLP solution SHALL be used.
- CISA.MS.EXO.12.1IP allow lists SHOULD NOT be created.
- CISA.MS.EXO.12.2Safe lists SHOULD NOT be enabled.
- CISA.MS.EXO.13.1Mailbox auditing SHALL be enabled.
- MT.1001At least one Conditional Access policy is configured with device compliance.
- MT.1002App management restrictions on applications and service principals is configured and enabled.
- MT.1003At least one Conditional Access policy is configured with All Apps.
- MT.1004At least one Conditional Access policy is configured with All Apps and All Users.
- MT.1005All Conditional Access policies are configured to exclude at least one emergency/break glass account or group.
- MT.1006At least one Conditional Access policy is configured to require MFA for admins.
- MT.1007At least one Conditional Access policy is configured to require MFA for all users.
- MT.1008At least one Conditional Access policy is configured to require MFA for Azure management.
- MT.1009At least one Conditional Access policy is configured to block other legacy authentication.
- MT.1010At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync.
- MT.1011At least one Conditional Access policy is configured to secure security info registration only from a trusted location.
- MT.1012At least one Conditional Access policy is configured to require MFA for risky sign-ins.
- MT.1013At least one Conditional Access policy is configured to require new password when user risk is high.
- MT.1014At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for admins.
- MT.1015At least one Conditional Access policy is configured to block access for unknown or unsupported device platforms.
- MT.1016At least one Conditional Access policy is configured to require MFA for guest access.
- MT.1017At least one Conditional Access policy is configured to enforce non persistent browser session for non-corporate devices.
- MT.1018At least one Conditional Access policy is configured to enforce sign-in frequency for non-corporate devices.
- MT.1019At least one Conditional Access policy is configured to enable application enforced restrictions.
- MT.1020All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope them.
- MT.1022All users utilizing a P1 license should be licensed.
- MT.1023All users utilizing a P2 license should be licensed.
- MT.1025No external user with permanent role assignment on Control Plane.
- MT.1026No hybrid user with permanent role assignment on Control Plane.
- MT.1027No Service Principal with Client Secret and permanent role assignment on Control Plane.
- MT.1028No user with mailbox and permanent role assignment on Control Plane.
- MT.1029Stale accounts are not assigned to privileged roles.
- MT.1030Eligible role assignments on Control Plane are in use by administrators.
- MT.1031Privileged role on Control Plane are managed by PIM only.
- MT.1032Limited number of Global Admins are assigned.
- MT.1033MT.1033.$($RegularUsers.IndexOf($_)): User should be blocked from using legacy authentication ($($_.userPrincipalName))
- MT.1034MT.1034.$($EmergencyAccessUsers.IndexOf($_)): Emergency access users should not be blocked ($($_.userPrincipalName))
- MT.1042Restrict dial-in users from bypassing a meeting lobby
- MT.1045Only invited users should be automatically admitted to Teams meetings
- MT.1046Restrict anonymous users from joining meetings
- MT.1047Restrict anonymous users from starting Teams meetings
- MT.1048Limit external participants from having control in a Teams meeting