Skip to main content

πŸ“ Microsoft Entra ID

  • Contextual name: πŸ“ Microsoft Entra ID
  • ID: /ce/ca/azure/microsoft-entra-id
  • Located in: πŸ“ Azure

Policies (33)​

PolicyLogic CountFlags
πŸ“ Account Lockout Duration is not set 60 seconds or more 🟒🟒 x3
πŸ“ Account Lockout Threshold is not set to 10 or less 🟒🟒 x3
πŸ“ Allow Users To Remember MFA On Devices They Trust is enabled 🟒🟒 x3
πŸ“ Conditional Access By Location is not defined 🟒🟒 x3
πŸ“ Custom Banned Password List is not enforced 🟒🟒 x3
πŸ“ Device Code Authentication Flow is not restricted 🟒🟒 x3
πŸ“ Global Administrator Role assigned to more than 4 users 🟒🟒 x3
πŸ“ Guest Invite Settings is not set to Only Users Assigned To Specific Admin Roles Can Invite Guest Users 🟒1🟒 x6
πŸ“ Guest Users are not reviewed on a regular basis 🟒🟒 x3
πŸ“ Guest Users restricted to their own directory objects 🟒1🟒 x6
πŸ“ MFA For Administrators is not required 🟒🟒 x3
πŸ“ MFA For All Users is not required 🟒🟒 x3
πŸ“ MFA For Risky Sign-Ins is not required 🟒🟒 x3
πŸ“ MFA For Windows Azure Service Management API is not required 🟒🟒 x3
πŸ“ MFA To Access Microsoft Admin Portals is not required 🟒🟒 x3
πŸ“ Named Locations are not defined 🟒🟒 x3
πŸ“ Non-Privileged Users Multi-Factor Auth Status is not enabled 🟒🟒 x3
πŸ“ Notify All Admins When Other Admins Reset Their Password is set No 🟒🟒 x3
πŸ“ Notify Users On Password Resets is set to No 🟒🟒 x3
πŸ“ Owners Can Manage Group Membership Requests In The Access Panel is set to Yes 🟒🟒 x3
πŸ“ Privileged Users Multi-Factor Auth Status is not enabled 🟒🟒 x3
πŸ“ Reconfirm Authentication Information is set to 0 🟒🟒 x3
πŸ“ Require MFA to register or join devices with Microsoft Entra ID is set to No 🟒🟒 x3
πŸ“ Restrict Access To Microsoft Entra Admin Center is set to No 🟒🟒 x3
πŸ“ Restrict User Ability To Access Groups Features In The Access Pane is set to No 🟒🟒 x3
πŸ“ Security Defaults are not enabled 🟒🟒 x3
πŸ“ Self-Service Password Reset does not require 2 authentication methods 🟒🟒 x3
πŸ“ Tenant Creation is set to Yes 🟒1🟒 x6
πŸ“ User Consent For Applications is not set to Allow From Verified Publishers 🟒🟒 x3
πŸ“ User Consent For Applications is not set to Do Not Allow User Consent 🟒🟒 x3
πŸ“ Users Can Create Microsoft 365 Groups In Azure Portals, API Or PowerShell is set to Yes 🟒🟒 x3
πŸ“ Users Can Create Security Groups In Azure Portals, API Or PowerShell is set to Yes 🟒🟒 x3
πŸ“ Users Can Register Applications is set to Yes 🟒1🟒 x6