Tests Overview
This section is generated from the Maester test source. Each page includes the test ID, severity, tags, PowerShell command, overview, remediation details, and related references when available.
Every test is researched, written, and refined by security experts from the Maester community — meet the contributors.
Test Suites
| Suite | Tests | Description |
|---|---|---|
| Maester | 190 | Maester security tests for Microsoft 365 and Microsoft Entra configurations. |
| Entra ID SCA | 44 | Entra ID Security Config Analyzer tests mapped to Microsoft Entra security configuration checks. |
| CISA | 79 | CISA SCuBA baseline tests for Microsoft 365 security configurations. |
| CIS | 49 | CIS Benchmark controls implemented as Maester tests. |
| ORCA | 67 | ORCA Exchange Online security configuration tests included in Maester. |
| Active Directory | 270 | Active Directory inventory and security configuration tests for on-premises domains. |
All Tests
| Test ID | Title | Suite | Severity | Category |
|---|---|---|---|---|
| AD-CFG-01 | Tombstone lifetime configuration should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-02 | dSHeuristics count should be retrievable | Active Directory | High | AD.Config |
| AD-CFG-03 | SPN mappings should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-04 | Optional features count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-05 | Recycle bin enabled paths should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-06 | LDAP query policy count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-07 | Default query policy should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-08 | AuthN policy container count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-09 | AD activation objects count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-10 | Well-known security principals count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-11 | Registered DHCP servers count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-12 | Enterprise CA count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-13 | Certificate templates count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-14 | Enrollment templates count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-15 | Enrollment CA certificate details should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-16 | Trusted root CA count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-17 | Trusted root CA details should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-18 | Intermediate CA count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-19 | Intermediate CA details should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-20 | CRL distribution points count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-21 | NTAuth certificates count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-22 | KDS root keys count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-23 | SMTP site links count should be retrievable | Active Directory | Info | AD.Config |
| AD-CFG-24 | IP site links count should be retrievable | Active Directory | Info | AD.Config |
| AD-COMP-01 | Computer disabled count should be retrievable | Active Directory | Info | AD.Computer |
| AD-COMP-02 | Computer dormant count should be retrievable | Active Directory | Info | AD.Computer |
| AD-COMP-03 | Computer CreatorSid count should be retrievable | Active Directory | Info | AD.Computer |
| AD-COMP-04 | Computer non-standard primary group count should be retrievable | Active Directory | Info | AD.Computer |
| AD-COMP-05 | Computer SID History count should be retrievable | Active Directory | Medium | AD.Computer |
| AD-COMP-06 | Computer default container count should be retrievable | Active Directory | Info | AD.Computer |
| AD-COMP-07 | Computer OU count should be retrievable | Active Directory | Info | AD.Computer |
| AD-COMP-08 | Computer per OU average should be retrievable | Active Directory | Info | AD.Computer |
| AD-COMP-09 | Computer delegation count should be retrievable | Active Directory | Info | AD.Computer |
| AD-COMP-10 | Computer delegation details should be retrievable | Active Directory | Info | AD.Computer |
| AD-DACL-01 | Distinct DACL object count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-02 | OU DACL entry count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-03 | Conflict object count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-04 | Conflict object details should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-05 | Deny ACE count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-06 | Deny ACE details should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-07 | Distinct DACL identity count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-08 | DACL ACE distribution per identity should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-09 | Privileged allow ACE count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-10 | Privileged allow ACE details should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-11 | Privileged extended right count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-12 | Privileged extended right details should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-13 | Privileged extended right identities should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-14 | Non-inherited ACE count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-15 | Unresolved SID count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-16 | Unresolved SID details should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-17 | Inherited object type count should be retrievable | Active Directory | Info | AD.DACL |
| AD-DACL-18 | Inherited object type details should be retrievable | Active Directory | Info | AD.DACL |
| AD-DC-01 | DC site coverage count should be retrievable | Active Directory | Info | AD.DomainController |
| AD-DC-02 | SMBv1 should be disabled on all domain controllers | Active Directory | Unknown | AD.DomainController |
| AD-DC-03 | SMBv3.1.1 enabled count should be retrievable | Active Directory | Info | AD.DomainController |
| AD-DC-04 | SMB signing should be enabled on all domain controllers | Active Directory | Unknown | AD.DomainController |
| AD-DC-05 | DCs with all FSMO roles count should be retrievable | Active Directory | Info | AD.DomainController |
| AD-DC-06 | FSMO role holder details should be retrievable | Active Directory | Info | AD.DomainController |
| AD-DC-07 | DC operating system count should be retrievable | Active Directory | High | AD.DomainController |
| AD-DC-08 | DC operating system details should be retrievable | Active Directory | High | AD.DomainController |
| AD-DCD-01 | DC non-standard LDAP port count should be retrievable | Active Directory | Info | AD.DomainController |
| AD-DCD-02 | DC non-standard LDAPS port count should be retrievable | Active Directory | Info | AD.DomainController |
| AD-DCD-03 | Read-only domain controller count should be retrievable | Active Directory | Info | AD.DomainController |
| AD-DCD-04 | Non-Global Catalog DC count should be retrievable | Active Directory | Info | AD.DomainController |
| AD-DCOMP-01 | Computers with unconstrained delegation count should be retrievable | Active Directory | Critical | AD.Security |
| AD-DCOMP-02 | Non-DC computers should not have unconstrained delegation | Active Directory | Critical | AD.Security |
| AD-DCOMP-03 | Non-DC computers with constrained delegation count should be retrievable | Active Directory | High | AD.Security |
| AD-DCOMP-04 | Computer operating system count should be retrievable | Active Directory | Info | AD.Security |
| AD-DCOMP-05 | Computer operating system details should be retrievable | Active Directory | Info | AD.Security |
| AD-DCOMP-06 | Stale enabled computer count should be retrievable | Active Directory | Medium | AD.Security |
| AD-DCOMP-07 | Computer DNS host name count should be retrievable | Active Directory | Info | AD.Security |
| AD-DCOMP-08 | Computer DNS zone count should be retrievable | Active Directory | Info | AD.Security |
| AD-DCOMP-09 | Computer DNS zone details should be retrievable | Active Directory | Info | AD.Security |
| AD-DFSR-01 | DFS-R subscription count should be retrievable | Active Directory | Info | AD.Replication |
| AD-DNS-01 | DNS zone count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-02 | Zones with only SOA/NS records should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-03 | Root servers with incorrect IPs should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-04 | Root server incorrect IP details should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-05 | Dynamic DNS record count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-06 | Zones with non-default records should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-07 | Zone record count details should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-08 | Zone delegation count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-09 | Zone delegation details should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-10 | SOA record details should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-11 | AD DS SRV record count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-12 | AD DS SRV record details should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-13 | DNSSEC record count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-14 | Empty zone count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-15 | Duplicate zone count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-16 | Reverse lookup zone count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-17 | Non-standard zone count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-18 | Reverse zone network count should be retrievable | Active Directory | Info | AD.DNS |
| AD-DNS-19 | Reverse zone network details should be retrievable | Active Directory | Info | AD.DNS |
| AD-DOM-01 | Domain functional level should be retrievable | Active Directory | Medium | AD.Domain |
| AD-DOM-02 | Machine account quota should be retrievable | Active Directory | Low | AD.Domain |
| AD-DOM-03 | Domain controller count should be retrievable | Active Directory | Info | AD.Domain |
| AD-DOM-04 | RIDs remaining should be retrievable | Active Directory | Info | AD.Domain |
| AD-DOM-05 | Domain name standard compliance should be retrievable | Active Directory | Info | AD.Domain |
| AD-DOM-06 | Domain name non-standard details should be retrievable | Active Directory | Info | AD.Domain |
| AD-DOM-07 | NetBIOS name standard compliance should be retrievable | Active Directory | Info | AD.Domain |
| AD-DOM-08 | NetBIOS name non-standard details should be retrievable | Active Directory | Info | AD.Domain |
| AD-DOMS-01 | Allowed DNS suffixes count should be retrievable | Active Directory | Info | AD.Domain |
| AD-FEAT-01 | Optional feature count should be retrievable | Active Directory | Info | AD.Replication |
| AD-FEAT-02 | Optional feature enabled details should be retrievable | Active Directory | Info | AD.Replication |
| AD-FGPP-01 | Fine-grained password policy count should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-FGPP-02 | Fine-grained password policy value count should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-FGPP-03 | Fine-grained password policy setting counts should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-FGPP-04 | Fine-grained password policy application targets should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-FOR-01 | Forest functional level should be retrievable | Active Directory | Medium | AD.Forest |
| AD-FOR-02 | Forest domain count should be retrievable | Active Directory | Info | AD.Forest |
| AD-FOR-03 | Tombstone lifetime should be retrievable | Active Directory | Info | AD.Forest |
| AD-FOR-04 | Recycle Bin status should be retrievable | Active Directory | Info | AD.Forest |
| AD-FORS-01 | UPN suffixes count should be retrievable | Active Directory | Info | AD.Forest |
| AD-FORS-02 | UPN suffixes details should be retrievable | Active Directory | Info | AD.Forest |
| AD-FORS-03 | SPN suffixes count should be retrievable | Active Directory | Info | AD.Forest |
| AD-FORS-04 | Cross-forest references count should be retrievable | Active Directory | Info | AD.Forest |
| AD-GCHG-01 | Average group membership changes per year should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-01 | Distinct groups with members count should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-02 | Distinct account types of members count should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-03 | Member account types breakdown should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-04 | Trust members count should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-05 | Trust members details by group should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-06 | Foreign SID principals count should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-07 | Foreign SID details by domain should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-08 | Empty non-privileged group count should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-09 | Empty non-privileged group details should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-10 | Privileged groups with members count should be retrievable | Active Directory | Info | AD.Group |
| AD-GMC-11 | Privileged groups with members details should be retrievable | Active Directory | Info | AD.Group |
| AD-GPO-01 | GPO total count should be retrievable | Active Directory | Info | AD.GPO |
| AD-GPO-02 | GPO created before 2020 count should be retrievable | Active Directory | Info | AD.GPO |
| AD-GPO-03 | GPO stale-before-2020 count should be retrievable | Active Directory | Info | AD.GPO |
| AD-GPO-04 | Unlinked GPO count should be compliant | Active Directory | Unknown | AD.GPO |
| AD-GPO-05 | GPO unlinked details should be compliant | Active Directory | Unknown | AD.GPO |
| AD-GPOL-01 | GPO linked count should be retrievable | Active Directory | Info | AD.GPO |
| AD-GPOL-02 | Disabled GPO link count should be retrievable | Active Directory | Info | AD.GPO |
| AD-GPOL-03 | GPO unlinked target count should be compliant | Active Directory | Unknown | AD.GPO |
| AD-GPOL-04 | Enforced GPO link count should be retrievable | Active Directory | Unknown | AD.GPO |
| AD-GPOL-05 | GPO blocked inheritance count should be compliant | Active Directory | Unknown | AD.GPO |
| AD-GPOL-06 | GPO linked OU count should be retrievable | Active Directory | Info | AD.GPO |
| AD-GPOREP-01 | GPOs without permissions count should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-02 | GPOs without permissions details should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-03 | GPOs without authenticated users count should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-04 | GPOs without authenticated users details should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-05 | GPOs without enterprise domain controllers count should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-06 | GPOs without domain computers count should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-07 | GPOs with deny ACE count should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-08 | GPOs with deny ACE details should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-09 | GPO inherited permissions count should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-10 | GPO no-apply Group Policy ACE count should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOREP-11 | GPO no-apply Group Policy ACE details should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOREP-12 | GPO disabled link count should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOREP-13 | GPO disabled link details should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOREP-14 | GPO enforcement count should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOREP-15 | GPO version mismatch count should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOREP-16 | GPO version mismatch details should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOREP-17 | GPO Cpassword found count should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-18 | GPO Cpassword found details should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-19 | GPO default password found count should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOREP-20 | GPO default password found details should be retrievable | Active Directory | Unknown | AD.GPOState |
| AD-GPOS-01 | GPO state total count should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOS-02 | WMI filter count should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOS-03 | WMI filter details should be compliant | Active Directory | Info | AD.GPOState |
| AD-GPOS-04 | Disabled GPO settings count should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOS-05 | Computer disabled GPO settings details should be compliant | Active Directory | Info | AD.GPOState |
| AD-GPOS-06 | User disabled GPO settings details should be compliant | Active Directory | Info | AD.GPOState |
| AD-GPOS-07 | All disabled GPO settings details should be compliant | Active Directory | Info | AD.GPOState |
| AD-GPOS-08 | GPO owner distinct count should be retrievable | Active Directory | Info | AD.GPOState |
| AD-GPOS-09 | GPO owner details should be accessible | Active Directory | Info | AD.GPOState |
| AD-GRP-01 | Group AdminCount should be retrievable | Active Directory | Info | AD.Group |
| AD-GRP-02 | Groups in container objects count should be retrievable | Active Directory | Info | AD.Group |
| AD-GRP-03 | Stale groups count should be retrievable | Active Directory | Info | AD.Group |
| AD-GRP-04 | Groups with manager count should be retrievable | Active Directory | Info | AD.Group |
| AD-GRP-05 | Group SID History count should be retrievable | Active Directory | Medium | AD.Group |
| AD-GRP-06 | Distribution group count should be retrievable | Active Directory | Info | AD.Group |
| AD-GRP-07 | Security group count should be retrievable | Active Directory | Info | AD.Group |
| AD-GRP-08 | Domain local group count should be retrievable | Active Directory | Info | AD.Group |
| AD-GRP-09 | Global group count should be retrievable | Active Directory | Info | AD.Group |
| AD-GRP-10 | Universal group count should be retrievable | Active Directory | Info | AD.Group |
| AD-KRBTGT-01 | KRBTGT password last set should be retrievable | Active Directory | High | AD.Security |
| AD-KRBTGT-02 | KRBTGT last logon should be retrievable | Active Directory | Info | AD.Security |
| AD-KRBTGT-03 | KRBTGT should have standard UAC settings (disabled account) | Active Directory | Unknown | AD.Security |
| AD-MSA-01 | Managed service account count should be retrievable | Active Directory | Info | AD.Security |
| AD-OU-01 | OU overlapping name count should be retrievable | Active Directory | Info | AD.OU |
| AD-OU-02 | OU at domain root count should be retrievable | Active Directory | Info | AD.OU |
| AD-OU-03 | OU stale count should be retrievable | Active Directory | Info | AD.OU |
| AD-OU-04 | OU empty count should be retrievable | Active Directory | Info | AD.OU |
| AD-OU-05 | OU empty details should be retrievable | Active Directory | Info | AD.OU |
| AD-PRINT-01 | Printer total count should be retrievable | Active Directory | Info | AD.Printer |
| AD-PWDPOL-01 | Password history count should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-PWDPOL-02 | Password maximum age should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-PWDPOL-03 | Password minimum length should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-PWDPOL-04 | Password complexity requirement should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-PWDPOL-05 | Password reversible encryption status should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-PWDPOL-06 | Account lockout duration should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-PWDPOL-07 | Account lockout threshold should be retrievable | Active Directory | Info | AD.PasswordPolicy |
| AD-REPL-01 | Disabled replication connection count should be retrievable | Active Directory | Info | AD.Replication |
| AD-REPL-02 | Non-auto replication connection count should be retrievable | Active Directory | Info | AD.Replication |
| AD-ROOTDSE-01 | Supported SASL mechanism count should be retrievable | Active Directory | Info | AD.Replication |
| AD-ROOTDSE-02 | Supported SASL mechanism details should be retrievable | Active Directory | Info | AD.Replication |
| AD-ROOTDSE-03 | Root DSE synchronized status should be retrievable | Active Directory | Unknown | AD.Replication |
| AD-SCH-01 | Schema modification year count should be retrievable | Active Directory | Info | AD.Schema |
| AD-SCH-02 | Schema modification year details should be retrievable | Active Directory | Info | AD.Schema |
| AD-SCH-03 | Schema version entry count should be retrievable | Active Directory | Info | AD.Schema |
| AD-SCH-04 | Schema version details should be retrievable | Active Directory | Info | AD.Schema |
| AD-SCH-05 | LAPS installation status should be retrievable | Active Directory | Unknown | AD.Schema |
| AD-SITE-01 | Site total count should be retrievable | Active Directory | Info | AD.Site |
| AD-SITE-02 | Sites without domain controllers count should be retrievable | Active Directory | Info | AD.Site |
| AD-SITE-03 | Sites without domain controllers details should be retrievable | Active Directory | Info | AD.Site |
| AD-SITE-04 | Sites without subnet associations count should be retrievable | Active Directory | Info | AD.Site |
| AD-SITE-05 | Sites without subnet associations details should be retrievable | Active Directory | Info | AD.Site |
| AD-SPN-01 | Computer SPN service class count should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-02 | Computer SPN service class usage should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-03 | Computer SPN unknown service class count should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-04 | Computer SPN unknown service class details should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-05 | Computer SPN non-FQDN hosts should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-06 | User SPN total count should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-07 | User SPN service class count should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-08 | User SPN service class usage should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-09 | User SPN unknown service class count should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-10 | User SPN unknown service class details should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-11 | User SPN non-FQDN hosts should be retrievable | Active Directory | Info | AD.SPN |
| AD-SPN-12 | User SPN domain admin count should be retrievable | Active Directory | Critical | AD.SPN |
| AD-SPN-13 | User SPN domain admin details should be retrievable | Active Directory | Critical | AD.SPN |
| AD-SUB-01 | Subnet total count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-02 | Sites with subnet associations count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-03 | Catch-all subnets count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-04 | IPv6 subnets count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-05 | IPv6 catch-all subnets count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-06 | Non-RFC1918 (public IP) subnets count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-07 | Non-RFC1918 (public IP) subnets details should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-08 | Distinct first octets count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-09 | Distinct first two octets (/16 networks) count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-10 | Distinct first three octets (/24 networks) count should be retrievable | Active Directory | Info | AD.Site |
| AD-SUB-11 | Subnets without site associations count should be retrievable | Active Directory | Info | AD.Site |
| AD-TRUST-01 | Trust total count should be retrievable | Active Directory | Info | AD.Trust |
| AD-TRUST-02 | Trust inter-forest count should be retrievable | Active Directory | Info | AD.Trust |
| AD-TRUST-03 | Trust quarantined count should be retrievable | Active Directory | High | AD.Trust |
| AD-TRUST-04 | Trust non-quarantined details should be retrievable | Active Directory | High | AD.Trust |
| AD-TRUST-05 | Trust configuration details should be retrievable | Active Directory | Info | AD.Trust |
| AD-TRUST-06 | Trust stale count should be retrievable | Active Directory | Info | AD.Trust |
| AD-TRUST-07 | Trust stale details should be retrievable | Active Directory | Info | AD.Trust |
| AD-USER-01 | Disabled user count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-02 | Dormant enabled user count should be retrievable | Active Directory | High | AD.User |
| AD-USER-03 | Non-expiring password user count should be retrievable | Active Directory | High | AD.User |
| AD-USER-04 | Reversible encryption user count should be retrievable | Active Directory | Medium | AD.User |
| AD-USER-05 | Delegation-enabled user count should be retrievable | Active Directory | High | AD.User |
| AD-USER-06 | DES-only Kerberos user count should be retrievable | Active Directory | High | AD.User |
| AD-USER-07 | No pre-authentication user count should be retrievable | Active Directory | High | AD.User |
| AD-USER-08 | Never-logged-in enabled user count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-09 | Password-not-required user count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-10 | Workstation-restricted user count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-11 | User AdminCount count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-12 | User non-standard primary group count should be retrievable | Active Directory | Medium | AD.User |
| AD-USER-13 | User SID History count should be retrievable | Active Directory | Medium | AD.User |
| AD-USER-14 | User SPN count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-15 | User manager count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-16 | User home directory count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-17 | User profile path count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-18 | User script path count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-19 | User in container count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-20 | Known service account count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-21 | Known service account details should be retrievable | Active Directory | Info | AD.User |
| AD-USER-22 | Built-in administrator account count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-23 | Enabled built-in administrator details should be retrievable | Active Directory | Info | AD.User |
| AD-USER-24 | Built-in administrator last logon details should be retrievable | Active Directory | Info | AD.User |
| AD-USER-25 | Built-in administrator password age details should be retrievable | Active Directory | Info | AD.User |
| AD-USER-26 | Honey pot user count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-27 | Honey pot user details should be retrievable | Active Directory | Info | AD.User |
| AD-USER-28 | User delegation configured count should be retrievable | Active Directory | Info | AD.User |
| AD-USER-29 | User delegation details should be retrievable | Active Directory | Info | AD.User |
| CIS.GH.1.2.2 | (L1) Ensure repository creation is limited to specific members | CIS | Medium | CIS GH Level 1 |
| CIS.GH.1.2.3 | (L1) Ensure repository deletion is limited to specific users | CIS | High | CIS GH Level 1 |
| CIS.GH.1.2.4 | (L1) Ensure issue deletion is limited to specific users | CIS | Medium | CIS GH Level 1 |
| CIS.GH.1.3.2 | (L1) Ensure team creation is limited to specific members | CIS | Medium | CIS GH Level 1 |
| CIS.GH.1.3.8 | (L1) Ensure strict base permissions are set for repositories | CIS | High | CIS GH Level 1 |
| CIS.M365.1.1.1 | (L1) Ensure Administrative accounts are cloud-only | CIS | High | CIS E3 Level 1 |
| CIS.M365.1.1.3 | (L1) Ensure that between two and four global admins are designated | CIS | High | CIS E3 Level 1 |
| CIS.M365.1.2.1 | (L2) Ensure that only organizationally managed/approved public groups exist | CIS | Medium | CIS E3 Level 2 |
| CIS.M365.1.2.2 | (L1) Ensure sign-in to shared mailboxes is blocked | CIS | High | CIS E3 Level 1 |
| CIS.M365.1.3.1 | (L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | CIS | High | CIS E3 Level 1 |
| CIS.M365.1.3.3 | (L2) Ensure 'External sharing' of calendars is not available | CIS | Medium | CIS E3 Level 2 |
| CIS.M365.1.3.4 | (L1) Ensure 'User owned apps and services' is restricted | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.1.3.5 | (L1) Ensure internal phishing protection for Forms is enabled | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.1.3.6 | (L2) Ensure the customer lockbox feature is enabled | CIS | High | CIS E5 Level 2 |
| CIS.M365.1.3.7 | (L2) Ensure 'third-party storage services' are restricted in 'Microsoft 365 on the web' | CIS | Unknown | CIS E3 Level 2 |
| CIS.M365.2.1.1 | (L2) Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy) | CIS | Medium | CIS E5 Level 2 |
| CIS.M365.2.1.11 | (L2) Ensure comprehensive attachment filtering is applied | CIS | High | CIS E3 Level 2 |
| CIS.M365.2.1.12 | (L1) Ensure the connection filter IP allow list is not used (Only Checks Default Policy) | CIS | Medium | CIS E3 Level 1 |
| CIS.M365.2.1.13 | (L1) Ensure the connection filter safe list is off (Only Checks Default Policy) | CIS | Medium | CIS E3 Level 1 |
| CIS.M365.2.1.2 | (L1) Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy) | CIS | Medium | CIS E3 Level 1 |
| CIS.M365.2.1.3 | (L1) Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy) | CIS | Medium | CIS E3 Level 1 |
| CIS.M365.2.1.4 | (L2) Ensure Safe Attachments policy is enabled (Only Checks Default Policy) | CIS | High | CIS E5 Level 2 |
| CIS.M365.2.1.5 | (L2) Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled | CIS | High | CIS E5 Level 2 |
| CIS.M365.2.1.6 | (L1) Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy) | CIS | Medium | CIS E3 Level 1 |
| CIS.M365.2.1.7 | (L1) Ensure that an anti-phishing policy has been created (Only Checks Default Policy) | CIS | Medium | CIS E5 Level 1 |
| CIS.M365.2.1.9 | (L1) Ensure that DKIM is enabled for all Exchange Online Domains | CIS | High | CIS E3 Level 1 |
| CIS.M365.2.4.4 | (L1) Ensure Zero-hour auto purge for Microsoft Teams is on (Only Checks ZAP is enabled) | CIS | Medium | CIS E5 Level 1 |
| CIS.M365.3.1.1 | (L1) Ensure Microsoft 365 audit log search is Enabled | CIS | High | CIS E3 Level 1 |
| CIS.M365.4.1 | (L1) Ensure devices without a compliance policy are marked 'not compliant' | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.5.1.2.2 | (L1) Ensure users cannot register applications | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.5.1.2.3 | (L1) Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes' | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.5.1.4.6 | (L2) Ensure users are restricted from recovering BitLocker keys | CIS | Unknown | CIS E3 Level 2 |
| CIS.M365.5.1.5.1 | (L2) Ensure user consent to apps accessing company data on their behalf is not allowed | CIS | Unknown | CIS E3 Level 2 |
| CIS.M365.5.1.5.2 | (L1) Ensure the admin consent workflow is enabled | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.5.1.6.2 | (L1) Ensure that guest user access is restricted | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.5.2.3.5 | (L1) Ensure weak authentication methods are disabled | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.6.5.3 | (L2) Ensure additional storage providers are restricted in Outlook on the web | CIS | Unknown | CIS E3 Level 2 |
| CIS.M365.7.2.11 | (L1) Ensure the SharePoint default sharing link permission is set | CIS | Unknown | SharePoint Online |
| CIS.M365.7.2.2 | (L1) Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | CIS | Unknown | SharePoint Online |
| CIS.M365.7.2.5 | (L2) Ensure that SharePoint guest users cannot share items they don't own | CIS | Unknown | SharePoint Online |
| CIS.M365.7.2.7 | (L1) Ensure link sharing is restricted in SharePoint and OneDrive | CIS | Unknown | SharePoint Online |
| CIS.M365.7.2.9 | (L1) Ensure guest access to a site or OneDrive will expire automatically | CIS | Unknown | SharePoint Online |
| CIS.M365.7.3.1 | (L2) Ensure Office 365 SharePoint infected files are disallowed for download | CIS | Unknown | SharePoint Online |
| CIS.M365.8.1.1 | (L2) Ensure external file sharing in Teams is enabled for only approved cloud storage services | CIS | Medium | CIS E3 Level 2 |
| CIS.M365.8.2.2 | (L1) Ensure communication with unmanaged Teams users is disabled | CIS | Medium | CIS E3 Level 1 |
| CIS.M365.8.2.3 | (L1) Ensure external Teams users cannot initiate conversations | CIS | Unknown | CIS E3 Level 1 |
| CIS.M365.8.4.1 | (L1) Ensure app permission policies are configured | CIS | High | CIS E3 Level 1 |
| CIS.M365.8.5.3 | (L1) Ensure only people in my org can bypass the lobby | CIS | Medium | CIS E3 Level 1 |
| CIS.M365.8.6.1 | (L1) Ensure users can report security concerns in Teams | CIS | Medium | CIS E5 Level 1 |
| CISA.MS.AAD.1.1 | Legacy authentication SHALL be blocked. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.2.1 | Users detected as high risk SHALL be blocked. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.2.2 | A notification SHOULD be sent to the administrator when high-risk users are detected. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.2.3 | Sign-ins detected as high risk SHALL be blocked. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.3.1 | Phishing-resistant MFA SHALL be enforced for all users. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.3.2 | If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.3.3 | If Microsoft Authenticator is enabled, it SHALL be configured to show login context information. | CISA | Medium | Entra ID P1 |
| CISA.MS.AAD.3.4 | The Authentication Methods Manage Migration feature SHALL be set to Migration Complete. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.3.5 | The authentication methods SMS, Voice Call, and Email One-Time Passcode (OTP) SHALL be disabled. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.3.6 | Phishing-resistant MFA SHALL be required for highly privileged roles. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.3.7 | Managed devices SHOULD be required for authentication. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.3.8 | Managed Devices SHOULD be required to register MFA. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.4.1 | Security logs SHALL be sent to the agency's security operations center for monitoring. | CISA | High | Entra ID P1 |
| CISA.MS.AAD.5.1 | Only administrators SHALL be allowed to register applications. | CISA | High | Entra ID Free |
| CISA.MS.AAD.5.2 | Only administrators SHALL be allowed to consent to applications. | CISA | High | Entra ID Free |
| CISA.MS.AAD.5.3 | An admin consent workflow SHALL be configured for applications. | CISA | High | Entra ID Free |
| CISA.MS.AAD.5.4 | Group owners SHALL NOT be allowed to consent to applications. | CISA | High | Entra ID Free |
| CISA.MS.AAD.6.1 | User passwords SHALL NOT expire. | CISA | High | Entra ID Free |
| CISA.MS.AAD.7.1 | A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role. | CISA | High | Entra ID Free |
| CISA.MS.AAD.7.2 | Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator. | CISA | High | Entra ID Free |
| CISA.MS.AAD.7.3 | Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers. | CISA | High | Entra ID Free |
| CISA.MS.AAD.7.4 | Permanent active role assignments SHALL NOT be allowed for highly privileged roles. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.7.5 | Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.7.6 | Activation of the Global Administrator role SHALL require approval. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.7.7 | Eligible and Active highly privileged role assignments SHALL trigger an alert. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.7.8 | User activation of the Global Administrator role SHALL trigger an alert. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.7.9 | User activation of other highly privileged roles SHOULD trigger an alert. | CISA | High | Entra ID P2 |
| CISA.MS.AAD.8.1 | Guest users SHOULD have limited or restricted access to Azure AD directory objects. | CISA | Medium | Entra ID Free |
| CISA.MS.AAD.8.2 | Only users with the Guest Inviter role SHOULD be able to invite guest users. | CISA | High | Entra ID Free |
| CISA.MS.AAD.8.3 | Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes. | CISA | Medium | Entra ID Free |
| CISA.MS.EXO.1.1 | Automatic forwarding to external domains SHALL be disabled. | CISA | High | exchange |
| CISA.MS.EXO.10.1 | Emails SHALL be scanned for malware. | CISA | High | exchange |
| CISA.MS.EXO.10.2 | Emails identified as containing malware SHALL be quarantined or dropped. | CISA | High | exchange |
| CISA.MS.EXO.10.3 | Email scanning SHALL be capable of reviewing emails after delivery. | CISA | High | exchange |
| CISA.MS.EXO.11.1 | Impersonation protection checks SHOULD be used. | CISA | High | exchange |
| CISA.MS.EXO.11.2 | User warnings, comparable to the user safety tips included with EOP, SHOULD be displayed. | CISA | Medium | exchange |
| CISA.MS.EXO.11.3 | The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence. | CISA | Medium | exchange |
| CISA.MS.EXO.12.1 | IP allow lists SHOULD NOT be created. | CISA | Medium | exchange |
| CISA.MS.EXO.12.2 | Safe lists SHOULD NOT be enabled. | CISA | Medium | exchange |
| CISA.MS.EXO.13.1 | Mailbox auditing SHALL be enabled. | CISA | High | exchange |
| CISA.MS.EXO.14.1 | A spam filter SHALL be enabled. | CISA | High | exchange |
| CISA.MS.EXO.14.2 | Spam and high confidence spam SHALL be moved to either the junk email folder or the quarantine folder. | CISA | Medium | exchange |
| CISA.MS.EXO.14.3 | Allowed domains SHALL NOT be added to inbound anti-spam protection policies. | CISA | Medium | exchange |
| CISA.MS.EXO.14.4 | If a third-party party filtering solution is used, the solution SHOULD offer services comparable to the native spam filtering offered by Microsoft. | CISA | Medium | exchange |
| CISA.MS.EXO.15.1 | URL comparison with a block-list SHOULD be enabled. | CISA | Medium | exchange |
| CISA.MS.EXO.15.2 | Direct download links SHOULD be scanned for malware. | CISA | High | exchange |
| CISA.MS.EXO.15.3 | User click tracking SHOULD be enabled. | CISA | Medium | exchange |
| CISA.MS.EXO.16.1 | Alerts SHALL be enabled. | CISA | High | exchange |
| CISA.MS.EXO.16.2 | Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system. | CISA | Medium | exchange |
| CISA.MS.EXO.17.1 | Microsoft Purview Audit (Standard) logging SHALL be enabled. | CISA | High | exchange |
| CISA.MS.EXO.17.2 | Microsoft Purview Audit (Premium) logging SHALL be enabled. | CISA | Medium | Deprecated |
| CISA.MS.EXO.17.3 | Audit logs SHALL be maintained for at least the minimum duration dictated by OMB M-21-31 (Appendix C). | CISA | Medium | exchange |
| CISA.MS.EXO.2.1 | A list of approved IP addresses for sending mail SHALL be maintained. | CISA | Medium | Deprecated |
| CISA.MS.EXO.2.2 | An SPF policy SHALL be published for each domain, designating only these addresses as approved senders. | CISA | Medium | exchange |
| CISA.MS.EXO.3.1 | DKIM SHOULD be enabled for all domains. | CISA | Medium | exchange |
| CISA.MS.EXO.4.1 | A DMARC policy SHALL be published for every second-level domain. | CISA | Medium | exchange |
| CISA.MS.EXO.4.2 | The DMARC message rejection option SHALL be p=reject. | CISA | High | exchange |
| CISA.MS.EXO.4.3 | The DMARC point of contact for aggregate reports SHALL include [email protected]. | CISA | Medium | exchange |
| CISA.MS.EXO.5.1 | SMTP AUTH SHALL be disabled. | CISA | High | exchange |
| CISA.MS.EXO.6.1 | Contact folders SHALL NOT be shared with all domains. | CISA | Medium | exchange |
| CISA.MS.EXO.6.2 | Calendar details SHALL NOT be shared with all domains. | CISA | Medium | exchange |
| CISA.MS.EXO.7.1 | External sender warnings SHALL be implemented. | CISA | Medium | exchange |
| CISA.MS.EXO.8.1 | A DLP solution SHALL be used. | CISA | High | exchange |
| CISA.MS.EXO.8.2 | The DLP solution SHALL protect personally identifiable information (PII) and sensitive information, as defined by the agency. | CISA | Medium | exchange |
| CISA.MS.EXO.8.3 | The selected DLP solution SHOULD offer services comparable to the native DLP solution offered by Microsoft. | CISA | Medium | exchange |
| CISA.MS.EXO.8.4 | At a minimum, the DLP solution SHALL restrict sharing credit card numbers, U.S. Individual Taxpayer Identification Numbers (ITIN), and U.S. Social Security numbers (SSN) via email. | CISA | High | exchange |
| CISA.MS.EXO.9.1 | Emails SHALL be filtered by attachment file types. | CISA | Medium | exchange |
| CISA.MS.EXO.9.2 | The attachment filter SHOULD attempt to determine the true file type and assess the file extension. | CISA | Medium | exchange |
| CISA.MS.EXO.9.3 | Disallowed file types SHALL be determined and enforced. | CISA | High | exchange |
| CISA.MS.EXO.9.4 | Alternatively chosen filtering solutions SHOULD offer services comparable to Microsoft Defender's Common Attachment Filter. | CISA | Medium | exchange |
| CISA.MS.EXO.9.5 | At a minimum, click-to-run files SHOULD be blocked (e.g., .exe, .cmd, and .vbe). | CISA | High | exchange |
| CISA.MS.SHAREPOINT.1.1 | External sharing for SharePoint SHALL be limited to Existing guests or Only People in your organization. | CISA | Medium | spo |
| CISA.MS.SHAREPOINT.1.2 | External sharing for OneDrive SHALL be limited to Existing guests or Only People in your organization. | CISA | Unknown | spo |
| CISA.MS.SHAREPOINT.1.3 | External sharing SHALL be restricted to approved external domains and/or users in approved security groups per interagency collaboration needs. | CISA | High | spo |
| CISA.MS.SHAREPOINT.2.1 | File and folder default sharing scope SHALL be set to Specific People. | CISA | Unknown | spo |
| CISA.MS.SHAREPOINT.2.2 | File and folder default sharing permissions SHALL be set to View only. | CISA | Unknown | spo |
| CISA.MS.SHAREPOINT.3.1 | Expiration days for Anyone links SHALL be set to 30 days or less. | CISA | Unknown | spo |
| CISA.MS.SHAREPOINT.3.2 | Allowable file and folder permissions for Anyone links SHALL be set to View only. | CISA | Unknown | spo |
| CISA.MS.SHAREPOINT.3.3 | Reauthentication days for people who use a verification code SHALL be set to 30 days or less. | CISA | Unknown | spo |
| EIDSCA.AF01 | Authentication Method - FIDO2 security key - State. | Entra ID SCA | High | General |
| EIDSCA.AF02 | Authentication Method - FIDO2 security key - Allow self-service set up. | Entra ID SCA | Medium | General |
| EIDSCA.AF03 | Authentication Method - FIDO2 security key - Enforce attestation. | Entra ID SCA | High | General |
| EIDSCA.AF04 | Authentication Method - FIDO2 security key - Enforce key restrictions. | Entra ID SCA | High | General |
| EIDSCA.AF05 | Authentication Method - FIDO2 security key - Restricted. | Entra ID SCA | High | General |
| EIDSCA.AF06 | Authentication Method - FIDO2 security key - Restrict specific keys. | Entra ID SCA | Medium | General |
| EIDSCA.AG01 | Authentication Method - General Settings - Manage migration. | Entra ID SCA | High | General |
| EIDSCA.AG02 | Authentication Method - General Settings - Report suspicious activity - State. | Entra ID SCA | Medium | General |
| EIDSCA.AG03 | Authentication Method - General Settings - Report suspicious activity - Included users/groups. | Entra ID SCA | Medium | General |
| EIDSCA.AM01 | Authentication Method - Microsoft Authenticator - State. | Entra ID SCA | High | General |
| EIDSCA.AM02 | Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP. | Entra ID SCA | Medium | General |
| EIDSCA.AM03 | Authentication Method - Microsoft Authenticator - Require number matching for push notifications. | Entra ID SCA | Medium | General |
| EIDSCA.AM04 | Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications. | Entra ID SCA | Medium | General |
| EIDSCA.AM06 | Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications. | Entra ID SCA | Medium | General |
| EIDSCA.AM07 | Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications. | Entra ID SCA | Medium | General |
| EIDSCA.AM09 | Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications. | Entra ID SCA | Medium | General |
| EIDSCA.AM10 | Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications. | Entra ID SCA | Medium | General |
| EIDSCA.AP01 | Default Authorization Settings - Enabled Self service password reset for administrators. | Entra ID SCA | High | General |
| EIDSCA.AP04 | Default Authorization Settings - Guest invite restrictions. | Entra ID SCA | Medium | General |
| EIDSCA.AP05 | Default Authorization Settings - Sign-up for email based subscription. | Entra ID SCA | Medium | General |
| EIDSCA.AP06 | Default Authorization Settings - User can join the tenant by email validation. | Entra ID SCA | Medium | General |
| EIDSCA.AP07 | Default Authorization Settings - Guest user access. | Entra ID SCA | High | General |
| EIDSCA.AP08 | Default Authorization Settings - User consent policy assigned for applications. | Entra ID SCA | Medium | General |
| EIDSCA.AP09 | Default Authorization Settings - Allow user consent on risk-based apps. | Entra ID SCA | Medium | General |
| EIDSCA.AP10 | Default Authorization Settings - Default User Role Permissions - Allowed to create Apps. | Entra ID SCA | High | General |
| EIDSCA.AP14 | Default Authorization Settings - Default User Role Permissions - Allowed to read other users. | Entra ID SCA | High | General |
| EIDSCA.AS04 | Authentication Method - SMS - Use for sign-in. | Entra ID SCA | High | General |
| EIDSCA.AT01 | Authentication Method - Temporary Access Pass - State. | Entra ID SCA | High | General |
| EIDSCA.AT02 | Authentication Method - Temporary Access Pass - One-time. | Entra ID SCA | High | General |
| EIDSCA.AV01 | Authentication Method - Voice call - State. | Entra ID SCA | High | General |
| EIDSCA.CP01 | Default Settings - Consent Policy Settings - Group owner consent for apps accessing data. | Entra ID SCA | High | General |
| EIDSCA.CP03 | Default Settings - Consent Policy Settings - Block user consent for risky apps. | Entra ID SCA | High | General |
| EIDSCA.CP04 | Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to. | Entra ID SCA | Medium | General |
| EIDSCA.CR01 | Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature. | Entra ID SCA | High | General |
| EIDSCA.CR02 | Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests. | Entra ID SCA | Medium | General |
| EIDSCA.CR03 | Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire. | Entra ID SCA | Medium | General |
| EIDSCA.CR04 | Consent Framework - Admin Consent Request - Consent request duration (days). | Entra ID SCA | High | General |
| EIDSCA.PR01 | Default Settings - Password Rule Settings - Password Protection - Mode. | Entra ID SCA | High | General |
| EIDSCA.PR02 | Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory. | Entra ID SCA | High | General |
| EIDSCA.PR03 | Default Settings - Password Rule Settings - Enforce custom list. | Entra ID SCA | Medium | General |
| EIDSCA.PR05 | Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds. | Entra ID SCA | Medium | General |
| EIDSCA.PR06 | Default Settings - Password Rule Settings - Smart Lockout - Lockout threshold. | Entra ID SCA | Medium | General |
| EIDSCA.ST08 | Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner. | Entra ID SCA | Medium | General |
| EIDSCA.ST09 | Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content. | Entra ID SCA | Medium | General |
| MT.1001 | At least one Conditional Access policy is configured with device compliance. | Maester | Medium | CA |
| MT.1002 | App management restrictions on applications and service principals is configured and enabled. | Maester | High | App |
| MT.1003 | At least one Conditional Access policy is configured with All Apps. | Maester | High | CA |
| MT.1004 | At least one Conditional Access policy is configured with All Apps and All Users. | Maester | High | CA |
| MT.1005 | All Conditional Access policies are configured to exclude at least one emergency/break glass account or group. | Maester | High | CA |
| MT.1006 | At least one Conditional Access policy is configured to require MFA for admins. | Maester | High | CA |
| MT.1007 | At least one Conditional Access policy is configured to require MFA for all users. | Maester | High | CA |
| MT.1008 | At least one Conditional Access policy is configured to require MFA for Azure management. | Maester | High | CA |
| MT.1009 | At least one Conditional Access policy is configured to block other legacy authentication. | Maester | High | CA |
| MT.1010 | At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync. | Maester | High | CA |
| MT.1011 | At least one Conditional Access policy is configured to secure security info registration only from a trusted location. | Maester | High | CA |
| MT.1012 | At least one Conditional Access policy is configured to require MFA for risky sign-ins. | Maester | High | CA |
| MT.1013 | At least one Conditional Access policy is configured to require new password when user risk is high. | Maester | High | CA |
| MT.1014 | At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for admins. | Maester | High | CA |
| MT.1015 | At least one Conditional Access policy is configured to block access for unknown or unsupported device platforms. | Maester | Medium | CA |
| MT.1016 | At least one Conditional Access policy is configured to require MFA for guest access. | Maester | High | CA |
| MT.1017 | At least one Conditional Access policy is configured to enforce non persistent browser session for non-corporate devices. | Maester | High | CA |
| MT.1018 | At least one Conditional Access policy is configured to enforce sign-in frequency for non-corporate devices. | Maester | Medium | CA |
| MT.1019 | At least one Conditional Access policy is configured to enable application enforced restrictions. | Maester | Medium | CA |
| MT.1020 | All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope them. | Maester | High | CA |
| MT.1021 | Security Defaults are enabled. | Maester | High | CA |
| MT.1022 | All users utilizing a P1 license should be licensed. | Maester | Medium | CA |
| MT.1023 | All users utilizing a P2 license should be licensed. | Maester | Medium | CA |
| MT.1024 | MT.1024.$($RecommendationId -replace '^[^]+', ''): $($_.displayName) | Maester | Unknown | Entra |
| MT.1025 | No external user with permanent role assignment on Control Plane. | Maester | High | Privileged |
| MT.1026 | No hybrid user with permanent role assignment on Control Plane. | Maester | High | Privileged |
| MT.1027 | No Service Principal with Client Secret and permanent role assignment on Control Plane. | Maester | High | Privileged |
| MT.1028 | No user with mailbox and permanent role assignment on Control Plane. | Maester | High | Privileged |
| MT.1029 | Stale accounts are not assigned to privileged roles. | Maester | High | Privileged |
| MT.1030 | Eligible role assignments on Control Plane are in use by administrators. | Maester | High | Privileged |
| MT.1031 | Privileged role on Control Plane are managed by PIM only. | Maester | High | Privileged |
| MT.1032 | Limited number of Global Admins are assigned. | Maester | High | Privileged |
| MT.1033 | MT.1033.$($RegularUsers.IndexOf($)): User should be blocked from using legacy authentication ($($.userPrincipalName)) | Maester | Unknown | CA |
| MT.1034 | MT.1034.$($EmergencyAccessUsers.IndexOf($)): Emergency access users should not be blocked ($($.userPrincipalName)) | Maester | Unknown | CA |
| MT.1035 | All security groups assigned to Conditional Access Policies should be protected by RMAU. | Maester | High | CA |
| MT.1036 | All excluded objects should have a fallback include in another policy. | Maester | Medium | CA |
| MT.1037 | Only users with Presenter role are allowed to present in Teams meetings | Maester | High | Teams |
| MT.1038 | Conditional Access policies should not include or exclude deleted groups. | Maester | Medium | CA |
| MT.1039 | Ensure MailTips are enabled for end users | Maester | Low | Exchange |
| MT.1041 | Ensure users installing Outlook add-ins is not allowed | Maester | High | Exchange |
| MT.1042 | Restrict dial-in users from bypassing a meeting lobby | Maester | Medium | Teams |
| MT.1043 | Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domains | Maester | Medium | Exchange |
| MT.1044 | Ensure modern authentication for Exchange Online is enabled | Maester | High | Exchange |
| MT.1045 | Only invited users should be automatically admitted to Teams meetings | Maester | Medium | Teams |
| MT.1046 | Restrict anonymous users from joining meetings | Maester | Medium | Teams |
| MT.1047 | Restrict anonymous users from starting Teams meetings | Maester | Medium | Teams |
| MT.1048 | Limit external participants from having control in a Teams meeting | Maester | Medium | Teams |
| MT.1049 | Conditional Access policies for User Risk and Sign-in Risk should be configured separately. | Maester | High | CA |
| MT.1050 | Apps with high-risk permissions having a direct path to Global Administrator | Maester | High | App |
| MT.1051 | Apps with high-risk permissions having an indirect path to Global Administrator | Maester | High | App |
| MT.1052 | At least one Conditional Access policy is targeting the Device Code authentication flow. | Maester | High | CA |
| MT.1053 | Ensure intune device clean-up rule is configured | Maester | Medium | Intune |
| MT.1054 | Ensure built-in Device Compliance Policy marks devices with no compliance policy assigned as 'Not compliant' | Maester | Medium | Intune |
| MT.1055 | Microsoft 365 Group (and Team) creation should be restricted to approved users. | Maester | Medium | Group |
| MT.1056 | Ensure that no person has permanent access to all Azure subscriptions at the root scope | Maester | High | Privileged |
| MT.1057 | Ensure Microsoft 365 Group (and Team) expiration is configured to notify users. | Maester | Medium | App |
| MT.1058 | Ensure Microsoft 365 Group (and Team) expiration is configured to auto-expire groups. | Maester | Medium | App |
| MT.1059 | Microsoft Defender for Identity health issues should be resolved | Maester | Medium | Defender |
| MT.1061 | Device registration MFA control conflicts with Conditional Access policies | Maester | Medium | CA |
| MT.1062 | Ensure Direct Send is set to be rejected | Maester | Medium | Exchange |
| MT.1063 | All app registration owners should have MFA registered | Maester | High | App |
| MT.1064 | Management group creation should be limited to users with explicit write access | Maester | High | Azure |
| MT.1065 | Soft Delete should be enabled on all Recovery Services Vaults | Maester | High | Backup |
| MT.1066 | Conditional Access policies should not include or exclude deleted users, groups, or roles. | Maester | Medium | CA |
| MT.1067 | Authentication methods policies should not reference deleted groups. | Maester | Medium | Authentication |
| MT.1068 | Restrict non-admin users from creating tenants | Maester | Medium | Entra |
| MT.1069 | Restrict non-admin users from creating security groups. | Maester | Low | Entra |
| MT.1070 | Restrict device join to selected users/groups or none. | Maester | Medium | Entra |
| MT.1071 | At least one Conditional Access policy explicitly includes Azure DevOps. | Maester | Medium | CA |
| MT.1072 | Conditional Access policies should not use the deprecated Approved Client App grant. | Maester | High | CA |
| MT.1073 | Soft- and hard-matching of synchronized objects should be blocked. | Maester | Medium | Entra |
| MT.1074 | Mailboxes should not send outbound mails using the .onmicrosoft.com domain. | Maester | Medium | Exchange |
| MT.1075 | Third Party Entra Apps should only have explicitly assigned users instead of All Users. | Maester | Medium | App |
| MT.1076 | MOERA SHOULD NOT be used for sent mail. | Maester | High | Exchange |
| MT.1077 | App registrations with privileged API permissions should not have owners | Maester | Medium | Privileged |
| MT.1078 | App registrations with highly privileged directory roles should not have owners | Maester | Medium | Privileged |
| MT.1079 | Privileged API permissions on service principals should not remain unused | Maester | Medium | Privileged |
| MT.1080 | Credentials, tokens, or cookies from highly privileged users should not be exposed on vulnerable endpoints | Maester | Medium | Privileged |
| MT.1081 | Hybrid users should not be assigned Entra ID role assignments | Maester | Medium | Privileged |
| MT.1083 | Ensure Delicensing Resiliency is enabled | Maester | Low | Exchange |
| MT.1084 | Seamless Single SignOn should be disabled for all domains in EntraID Connect servers. | Maester | High | Entra |
| MT.1085 | Pending approvals for Critical Asset Management should not be present | Maester | Medium | Entra |
| MT.1086 | Devices should not share both critical and non-critical user credentials. | Maester | Low | XSPM |
| MT.1087 | Devices should not be publicly exposed with remotely exploitable, highly likely to be exploited, high or critical severity CVE's. | Maester | High | XSPM |
| MT.1088 | Devices with critical credentials should be protected by TPM. | Maester | Medium | XSPM |
| MT.1089 | Devices with critical credentials should be protected by Credential Guard. | Maester | Medium | XSPM |
| MT.1090 | Global Administrator role should not be added as local administrator on the device during Microsoft Entra join | Maester | Medium | Entra |
| MT.1091 | Registering user should not be added as local administrator on the device during Microsoft Entra join | Maester | Medium | Entra |
| MT.1092 | Intune APNS certificate should be valid for more than 30 days | Maester | High | Intune |
| MT.1093 | Apple Automated Device Enrollment Tokens should be valid for more than 30 days | Maester | High | Intune |
| MT.1094 | Apple Volume Purchase Program Tokens should be valid for more than 30 days | Maester | High | Intune |
| MT.1095 | Android Enterprise Account Connection should be healthy | Maester | High | Intune |
| MT.1096 | Intune Multi Admin approval should be configured | Maester | Medium | Intune |
| MT.1097 | Certificate Connectors should be healthy and running supported versions | Maester | High | Intune |
| MT.1098 | Mobile Threat Defense Connectors should be healthy | Maester | Critical | Intune |
| MT.1099 | Windows Diagnostic Data Processing should be enabled | Maester | Low | Intune |
| MT.1100 | Intune Audit Logs should be retained | Maester | High | Intune |
| MT.1101 | Default Branding Profile should be customized | Maester | Low | Intune |
| MT.1102 | Windows Feature Update Policy Settings should not reference end of support builds | Maester | High | Intune |
| MT.1103 | Intune RBAC groups should be protected by Restricted Management Administrative Units or Role Assignable groups | Maester | High | Intune |
| MT.1105 | MDM Authority should be set to Microsoft Intune | Maester | Low | Intune |
| MT.1106 | Catalog resources must have valid roles (no stale app roles or deleted SPNs) | Maester | Medium | Governance |
| MT.1107 | Access packages and catalogs should not reference deleted groups | Maester | Medium | Governance |
| MT.1108 | Access packages should not have inactive or orphaned assignment policies | Maester | Medium | Governance |
| MT.1109 | Access package approval workflows must have valid approvers | Maester | Medium | Governance |
| MT.1110 | No catalog should contain resources without any associated access packages | Maester | Medium | Governance |
| MT.1111 | High privileged user should be linked to an identity | Maester | Low | Privileged |
| MT.1112 | Privileged user accounts should not remain enabled when the linked primary account is disabled | Maester | Medium | Privileged |
| MT.1113 | AI agents should not be shared with broad access control policies | Maester | High | AIAgent |
| MT.1114 | AI agents should require user authentication | Maester | High | AIAgent |
| MT.1115 | AI agents should not have risky HTTP configurations | Maester | Medium | AIAgent |
| MT.1116 | AI agents should not send email with AI-controlled inputs | Maester | High | AIAgent |
| MT.1117 | Published AI agents should not be dormant | Maester | Low | AIAgent |
| MT.1118 | AI agents should avoid using author (maker) authentication for tools | Maester | Medium | AIAgent |
| MT.1119 | AI agents should not have hard-coded credentials in topics | Maester | High | AIAgent |
| MT.1120 | AI agents should not use MCP server tools without review | Maester | Medium | AIAgent |
| MT.1121 | AI agents with generative orchestration should have custom instructions | Maester | Medium | AIAgent |
| MT.1122 | AI agents should not have orphaned ownership | Maester | Medium | AIAgent |
| MT.1123 | Ensure BitLocker full disk encryption is configured via Intune | Maester | High | Intune |
| MT.1147 | Do not sync krbtgt_AzureAD to Entra ID | Maester | High | Entra |
| MT.1148 | Archive Scanning should be enabled | Maester | High | Defender |
| MT.1149 | Behavior Monitoring should be enabled | Maester | High | Defender |
| MT.1150 | Cloud Protection should be enabled | Maester | High | Defender |
| MT.1151 | Email Scanning should be enabled | Maester | High | Defender |
| MT.1152 | Script Scanning should be enabled | Maester | High | Defender |
| MT.1153 | Real-time Monitoring should be enabled | Maester | High | Defender |
| MT.1154 | Full Scan Removable Drives should be enabled | Maester | High | Defender |
| MT.1155 | Full Scan Mapped Drives should be disabled for performance | Maester | High | Defender |
| MT.1156 | Scanning Network Files should be enabled | Maester | High | Defender |
| MT.1157 | CPU Load Factor should be optimized (20-30%) | Maester | High | Defender |
| MT.1158 | Scan should be scheduled | Maester | High | Defender |
| MT.1159 | Quick Scan Time configuration is not required | Maester | High | Defender |
| MT.1160 | Signatures should be checked before scan | Maester | High | Defender |
| MT.1161 | Cloud Block Level should be High or higher | Maester | High | Defender |
| MT.1162 | Cloud Extended Timeout should be 30-50 seconds | Maester | High | Defender |
| MT.1163 | Signature Update Interval should be 1-4 hours | Maester | High | Defender |
| MT.1164 | PUA Protection should be enabled | Maester | High | Defender |
| MT.1165 | Network Protection should be enabled | Maester | High | Defender |
| MT.1166 | Local Admin Merge should be disabled | Maester | High | Defender |
| MT.1167 | Real-Time Scan Direction should cover both directions | Maester | High | Defender |
| MT.1168 | Cleaned Malware should be retained for at least 30 days | Maester | High | Defender |
| MT.1169 | Catch-up Full Scan should be disabled | Maester | High | Defender |
| MT.1170 | Catch-up Quick Scan should be disabled | Maester | High | Defender |
| MT.1171 | Sample Submission should send safe samples automatically | Maester | High | Defender |
| MT.1172 | Unified audit log ingestion is enabled | Maester | High | Purview |
| MT.1173 | Sensitivity labels are published for files used by Microsoft 365 Copilot | Maester | Medium | Purview |
| MT.1174 | Insider Risk Management policy for Risky AI usage is enabled | Maester | Medium | Purview |
| MT.1175 | DLP policy is configured for the Microsoft 365 Copilot location | Maester | High | Purview |
| MT.1176 | Retention policy is configured for the Microsoft Copilot location | Maester | Medium | Purview |
| MT.1177 | Ensure LAPS Configuration Policy is properly set | Maester | Unknown | Intune |
| MT.1178 | Ensure ASR Rules are configured correctly | Maester | High | Intune |
| MT.1179 | Ensure App Control for Business is enabled | Maester | High | Intune |
| MT.1180 | Ensure Managed Installer Rules are configured correctly | Maester | Medium | Intune |
| MT.1181 | Conditional Access policy is present that blocks high agent risk signins | Maester | High | CA |
| MT.1182 | Entra managed and verified domains should have mature DMARC policy (p=reject, pct=100). | Maester | Unknown | Entra |
| MT.1183 | Temporary bypass for onPremisesObjectIdentifier updates should be disabled | Maester | Medium | Entra |
| MT.1184 | Conditional Access policy without any target resources configured | Maester | Medium | CA |
| MT.1185 | Block legacy MSOnline (MSOL) PowerShell module | Maester | High | Entra |
| MT.1186 | High-privilege first-party Entra Apps should only have explicitly assigned users instead of All Users. | Maester | High | Entra |
| MT.1187 | The Microsoft 365 traffic forwarding profile in Global Secure Access should be enabled | Maester | Unknown | Entra |
| MT.1188 | Entra Private Access applications should be covered by a Conditional Access policy that requires a managed device | Maester | Unknown | Entra |
| MT.1189 | Groups assigned to Global Secure Access traffic forwarding profiles should not be nested | Maester | Unknown | Entra |
| MT.1190 | Entra Private Access applications should not use the Default connector group | Maester | Unknown | Entra |
| MT.1191 | Break-glass accounts should be excluded from the Compliant Network Conditional Access policy | Maester | Unknown | Entra |
| MT.1192 | Groups assigned to Entra Private Access applications should not be nested | Maester | Unknown | Entra |
| MT.1193 | Entra Private Access application segments should avoid broad or risky destinations | Maester | Unknown | Entra |
| MT.1194 | The baseline Global Secure Access security profile should enforce a threat-intelligence floor | Maester | Unknown | Entra |
| MT.1195 | The Quick Access app should not be subject to a sign-in frequency Conditional Access control | Maester | Unknown | Entra |
| MT.1196 | Review who can change attributes used by dynamic group rules | Maester | Medium | Entra |
| MT.1197 | Dynamic groups should not use the retiring memberOf rule operator | Maester | High | Entra |
| MT.1198 | App registration certificates should not have excessive validity periods. | Maester | Medium | App |
| MT.1199 | App registration credentials should not be expired or expiring soon. | Maester | Medium | App |
| MT.1200 | Agent Identities should have an active Agent Identity Blueprint Principal (Preview) | Maester | Medium | Entra |
| MT.1201 | Agent Users should have an existing parent Agent Identity (Preview) | Maester | Medium | Entra |
| MT.1203 | Agent Identity Blueprint Principals should have an existing Blueprint (Preview) | Maester | Medium | Entra |
| MT.1204 | Agent Identities, Blueprint Principals, and Blueprints should have active, enabled owners (Preview) | Maester | Medium | Entra |
| MT.1205 | Agent Identity Blueprints and Blueprint Principals should have assigned sponsors (Preview) | Maester | Medium | Entra |
| MT.1206 | Enabled Agent Identities should have active sign-in activity within the last 180 days (Preview) | Maester | Medium | Entra |
| MT.1207 | Foreign or multi-tenant Agent Blueprint Principals and Agent Identities should not hold privileged directory roles (Preview) | Maester | High | Entra |
| MT.1208 | Agent Identity Blueprints should not have expired, excessive, or long-lived client credentials (Preview) | Maester | High | Entra |
| MT.1209 | Agent Identities and Blueprint Principals should not be assigned privileged Entra directory roles (Preview) | Maester | High | Entra |
| MT.1210 | Agent Users should not have privileged directory roles or membership in role-assignable groups (Preview) | Maester | High | Entra |
| MT.1211 | Agent Identity Blueprints should not use the allAllowed inheritance pattern for delegated scopes or application roles (Preview) | Maester | High | Entra |
| MT.1212 | Agent Identity Blueprint Principals should require assignment for the application roles they expose (Preview) | Maester | Medium | Entra |
| MT.1213 | Agent Identity Blueprints should not use wildcard or plain-http redirect URIs (Preview) | Maester | High | Entra |
| MT.1214 | Ensure macOS compliance policy requires System Integrity Protection | Maester | Medium | Intune |
| MT.1215 | Ensure Gatekeeper restricts macOS app download locations | Maester | Medium | Intune |
| MT.1216 | Ensure macOS compliance policy requires a Defender machine risk score level | Maester | Medium | Intune |
| MT.1217 | Ensure macOS LAPS is configured on Automated Device Enrollment profiles | Maester | High | Intune |
| MT.1223 | Agent Identities should not have high-risk Microsoft Graph permissions (Preview) | Maester | High | Entra |
| ORCA.100 | Bulk Complaint Level threshold is between 4 and 6. | ORCA | Medium | EXO |
| ORCA.101 | Bulk is marked as spam. | ORCA | Medium | EXO |
| ORCA.102 | Advanced Spam filter options are turned off. | ORCA | Medium | EXO |
| ORCA.103 | Outbound spam filter policy settings configured. | ORCA | Medium | EXO |
| ORCA.104 | High Confidence Phish action set to Quarantine message. | ORCA | High | EXO |
| ORCA.105 | Safe Links Synchronous URL detonation is enabled. | ORCA | Medium | EXO |
| ORCA.106 | Quarantine retention period is 30 days. | ORCA | Medium | EXO |
| ORCA.107 | End-user spam notification is enabled. | ORCA | Low | EXO |
| ORCA.108 | DKIM signing is set up for all your custom domains. | ORCA | Medium | EXO |
| ORCA.108.1 | DNS Records have been set up to support DKIM. | ORCA | Medium | EXO |
| ORCA.109 | Senders are not being allow listed in an unsafe manner. | ORCA | Medium | EXO |
| ORCA.110 | Internal Sender notifications are disabled. | ORCA | Medium | EXO |
| ORCA.111 | Anti-phishing policy exists and EnableUnauthenticatedSender is true. | ORCA | High | EXO |
| ORCA.112 | Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy. | ORCA | Medium | EXO |
| ORCA.113 | AllowClickThrough is disabled in Safe Links policies. | ORCA | Medium | EXO |
| ORCA.114 | No IP Allow Lists have been configured. | ORCA | High | EXO |
| ORCA.115 | Mailbox intelligence based impersonation protection is enabled in anti-phishing policies. | ORCA | Medium | EXO |
| ORCA.116 | Mailbox intelligence based impersonation protection action set to move message to junk mail folder. | ORCA | Medium | EXO |
| ORCA.118.1 | Domains are not being allow listed in an unsafe manner in Anti-Spam Policies. | ORCA | High | EXO |
| ORCA.118.2 | Domains are not being allow listed in an unsafe manner in Transport Rules. | ORCA | High | EXO |
| ORCA.118.3 | Your own domains are not being allow listed in an unsafe manner in Anti-Spam Policies. | ORCA | Medium | EXO |
| ORCA.118.4 | Your own domains are not being allow listed in an unsafe manner in Transport Rules. | ORCA | Medium | EXO |
| ORCA.119 | Similar Domains Safety Tips is enabled. | ORCA | Info | EXO |
| ORCA.120.1 | Zero Hour Autopurge Enabled for Phish. | ORCA | Medium | EXO |
| ORCA.120.2 | Zero Hour Autopurge Enabled for Malware. | ORCA | Medium | EXO |
| ORCA.120.3 | Zero Hour Autopurge Enabled for Spam. | ORCA | Medium | EXO |
| ORCA.121 | Supported filter policy action used. | ORCA | Low | EXO |
| ORCA.123 | Unusual Characters Safety Tips is enabled. | ORCA | Info | EXO |
| ORCA.124 | Safe attachments unknown malware response set to block messages. | ORCA | High | EXO |
| ORCA.139 | Spam action set to move message to junk mail folder or quarantine. | ORCA | Low | EXO |
| ORCA.140 | High Confidence Spam action set to Quarantine message. | ORCA | High | EXO |
| ORCA.141 | Bulk action set to Move message to Junk Email Folder. | ORCA | Medium | EXO |
| ORCA.142 | Phish action set to Quarantine message. | ORCA | Medium | EXO |
| ORCA.143 | Safety Tips are enabled. | ORCA | Info | EXO |
| ORCA.156 | Safe Links Policies are tracking when user clicks on safe links. | ORCA | Medium | EXO |
| ORCA.158 | Safe Attachments is enabled for SharePoint and Teams. | ORCA | Medium | EXO |
| ORCA.179 | Safe Links is enabled intra-organization. | ORCA | Medium | EXO |
| ORCA.180 | Anti-phishing policy exists and EnableSpoofIntelligence is true. | ORCA | Medium | EXO |
| ORCA.189 | Safe Attachments is not bypassed. | ORCA | Medium | EXO |
| ORCA.189.2 | Safe Links is not bypassed. | ORCA | High | EXO |
| ORCA.205 | Common attachment type filter is enabled. | ORCA | Medium | EXO |
| ORCA.220 | Advanced Phish filter Threshold level is adequate. | ORCA | Medium | EXO |
| ORCA.221 | Mailbox intelligence is enabled in anti-phishing policies. | ORCA | Medium | EXO |
| ORCA.222 | Domain Impersonation action is set to move to Quarantine. | ORCA | Medium | EXO |
| ORCA.223 | User impersonation action is set to move to Quarantine. | ORCA | High | EXO |
| ORCA.224 | Similar Users Safety Tips is enabled. | ORCA | Info | EXO |
| ORCA.225 | Safe Documents is enabled for Office clients. | ORCA | Medium | EXO |
| ORCA.226 | Each domain has a Safe Link policy applied to it. | ORCA | Medium | EXO |
| ORCA.227 | Each domain has a Safe Attachments policy applied to it. | ORCA | Medium | EXO |
| ORCA.228 | No trusted senders in Anti-phishing policy. | ORCA | High | EXO |
| ORCA.229 | No trusted domains in Anti-phishing policy. | ORCA | Medium | EXO |
| ORCA.230 | Each domain has a Anti-phishing policy applied to it, or the default policy is being used. | ORCA | Medium | EXO |
| ORCA.231 | Each domain has a anti-spam policy applied to it, or the default policy is being used. | ORCA | Medium | EXO |
| ORCA.232 | Each domain has a malware filter policy applied to it, or the default policy is being used. | ORCA | High | EXO |
| ORCA.233 | Domains are pointed directly at EOP or enhanced filtering is used. | ORCA | Medium | EXO |
| ORCA.233.1 | Domains are pointed directly at EOP or enhanced filtering is configured on all default connectors. | ORCA | Medium | EXO |
| ORCA.234 | Click through is disabled for Safe Documents. | ORCA | Medium | EXO |
| ORCA.235 | SPF records is set up for all your custom domains. | ORCA | Medium | EXO |
| ORCA.236 | Safe Links is enabled for emails. | ORCA | Medium | EXO |
| ORCA.237 | Safe Links is enabled for teams messages. | ORCA | Medium | EXO |
| ORCA.238 | Safe Links is enabled for office documents. | ORCA | Medium | EXO |
| ORCA.239 | No exclusions for the built-in protection policies. | ORCA | High | EXO |
| ORCA.240 | Outlook is configured to display external tags for external emails. | ORCA | Medium | EXO |
| ORCA.241 | Anti-phishing policy exists and EnableFirstContactSafetyTips is true. | ORCA | Medium | EXO |
| ORCA.242 | Important protection alerts responsible for AIR activities are enabled. | ORCA | High | EXO |
| ORCA.243 | Authenticated Receive Chain is set up for domains not pointing to EOP/MDO, or all domains point to EOP/MDO. | ORCA | Medium | EXO |
| ORCA.244 | Policies are configured to honor sending domains DMARC. | ORCA | Medium | EXO |