๐ผ 6.1 Security Defaults (Per-User MFA) | 3 | | | |
ย ย ย ย ๐ผ 6.1.1 Ensure that 'security defaults' is enabled in Microsoft Entra ID (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.1.2 Ensure that 'multifactor authentication' is 'enabled' for all users (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.1.3 Ensure that 'Allow users to remember multifactor authentication on devices they trust' is disabled (Manual) | | | 1 | |
๐ผ 6.2 Conditional Access | 7 | | | |
ย ย ย ย ๐ผ 6.2.1 Ensure that 'trusted locations' are defined (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.2.2 Ensure that an exclusionary geographic Conditional Access policy is considered (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.2.3 Ensure that an exclusionary device code flow policy is considered (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.2.4 Ensure that a multifactor authentication policy exists for all users (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.2.5 Ensure that multifactor authentication is required for risky sign-ins (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.2.6 Ensure that multifactor authentication is required for Windows Azure Service Management API (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.2.7 Ensure that multifactor authentication is required to access Microsoft Admin Portals (Manual) | | | 1 | |
๐ผ 6.3 Periodic Identity Reviews | 4 | | | |
ย ย ย ย ๐ผ 6.3.1 Ensure that Azure admin accounts are not used for daily operations (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.3.2 Ensure that guest users are reviewed on a regular basis (Manual) | | | 1 | |
ย ย ย ย ๐ผ 6.3.3 Ensure that use of the 'User Access Administrator' role is restricted (Automated) | | | 1 | |
ย ย ย ย ๐ผ 6.3.4 Ensure that all 'privileged' role assignments are periodically reviewed (Manual) | | | 1 | |
๐ผ 6.4 Ensure that 'Restrict non-admin users from creating tenants' is set to 'Yes' (Automated) | | | 1 | |
๐ผ 6.5 Ensure that 'Number of methods required to reset' is set to '2' (Manual) | | | 1 | |
๐ผ 6.6 Ensure that account 'Lockout threshold' is less than or equal to '10' (Manual) | | | 1 | |
๐ผ 6.7 Ensure that account 'Lockout duration in seconds' is greater than or equal to '60' (Manual) | | | 1 | |
๐ผ 6.8 Ensure that a 'Custom banned password list' is set to 'Enforce' (Manual) | | | 1 | |
๐ผ 6.9 Ensure that 'Number of days before users are asked to re-confirm their authentication information' is not set to '0' (Manual) | | | 1 | |
๐ผ 6.10 Ensure that 'Notify users on password resets?' is set to 'Yes' (Manual) | | | 1 | |
๐ผ 6.11 Ensure that 'Notify all admins when other admins reset their password?' is set to 'Yes' (Manual) | | | 1 | |
๐ผ 6.12 Ensure that 'User consent for applications' is set to 'Do not allow user consent' (Manual) | | | 1 | |
๐ผ 6.13 Ensure that 'User consent for applications' is set to 'Allow user consent for apps from verified publishers, for selected permissions' (Manual) | | | 1 | |
๐ผ 6.14 Ensure that 'Users can register applications' is set to 'No' (Automated) | | | 1 | |
๐ผ 6.15 Ensure that 'Guest users access restrictions' is set to 'Guest user access is restricted to properties and memberships of their own directory objects' (Automated) | | | 1 | |
๐ผ 6.16 Ensure that 'Guest invite restrictions' is set to 'Only users assigned to specific admin roles can invite guest users' (Automated) | | | 1 | |
๐ผ 6.17 Ensure that 'Restrict access to Microsoft Entra admin center' is set to 'Yes' (Manual) | | | 1 | |
๐ผ 6.18 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes' (Manual) | | | 1 | |
๐ผ 6.19 Ensure that 'Users can create security groups in Azure portals, API or PowerShell' is set to 'No' (Manual) | | | 1 | |
๐ผ 6.20 Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No' (Manual) | | | 1 | |
๐ผ 6.21 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No' (Manual) | | | 1 | |
๐ผ 6.22 Ensure that 'Require Multifactor Authentication to register or join devices with Microsoft Entra' is set to 'Yes' (Manual) | | | 1 | |
๐ผ 6.23 Ensure that no custom subscription administrator roles exist (Automated) | | | 1 | |
๐ผ 6.24 Ensure that a custom role is assigned permissions for administering resource locks (Manual) | | | 1 | |
๐ผ 6.25 Ensure that 'Subscription leaving Microsoft Entra tenant' and 'Subscription entering Microsoft Entra tenant' is set to 'Permit no one' (Manual) | | | 1 | |
๐ผ 6.26 Ensure fewer than 5 users have global administrator assignment (Manual) | | | 1 | |