Skip to main content

💼 5 Identity Services

  • ID: /frameworks/cis-azure-v5.0.0/05

Description​

This section covers security best practice recommendations for products in the Azure Identity services category.

Similar​

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 5.1 Security Defaults (Per-User MFA)33no data
 💼 5.1.1 Ensure that 'security defaults' is enabled in Microsoft Entra ID (Automated)1no data
 💼 5.1.2 Ensure that 'multifactor authentication' is 'enabled' for all users (Automated)1no data
 💼 5.1.3 Ensure that 'Allow users to remember multifactor authentication on devices they trust' is disabled (Manual)1no data
💼 5.2 Conditional Access88no data
 💼 5.2.1 Ensure that 'trusted locations' are defined (Manual)1no data
 💼 5.2.2 Ensure that an exclusionary geographic Conditional Access policy is considered (Manual)1no data
 💼 5.2.3 Ensure that an exclusionary device code flow policy is considered (Manual)1no data
 💼 5.2.4 Ensure that a multifactor authentication policy exists for all users (Manual)1no data
 💼 5.2.5 Ensure that multifactor authentication is required for risky sign-ins (Manual)1no data
 💼 5.2.6 Ensure that multifactor authentication is required for Windows Azure Service Management API (Manual)1no data
 💼 5.2.7 Ensure that multifactor authentication is required to access Microsoft Admin Portals (Manual)1no data
 💼 5.2.8 Ensure a Token Protection Conditional Access policy is considered (Manual)1no data
💼 5.3 Periodic Identity Reviews77no data
 💼 5.3.1 Ensure that Azure admin accounts are not used for daily operations (Manual)1no data
 💼 5.3.2 Ensure that guest users are reviewed on a regular basis (Manual)1no data
 💼 5.3.3 Ensure that use of the 'User Access Administrator' role is restricted (Automated)1no data
 💼 5.3.4 Ensure that all 'privileged' role assignments are periodically reviewed (Manual)1no data
 💼 5.3.5 Ensure disabled user accounts do not have read, write, or owner permissions (Manual)1no data
 💼 5.3.6 Ensure 'Tenant Creator' role assignments are periodically reviewed (Manual)1no data
 💼 5.3.7 Ensure all non-privileged role assignments are periodically reviewed (Manual)1no data
💼 5.4 Ensure that 'Restrict non-admin users from creating tenants' is set to 'Yes' (Automated)1no data
💼 5.5 Ensure that 'Number of methods required to reset' is set to '2' (Manual)1no data
💼 5.6 Ensure that account 'Lockout threshold' is less than or equal to '10' (Manual)1no data
💼 5.7 Ensure that account 'Lockout duration in seconds' is greater than or equal to '60' (Manual)1no data
💼 5.8 Ensure that a 'Custom banned password list' is set to 'Enforce' (Manual)1no data
💼 5.9 Ensure that 'Number of days before users are asked to re-confirm their authentication information' is not set to '0' (Manual)1no data
💼 5.10 Ensure that 'Notify users on password resets?' is set to 'Yes' (Manual)1no data
💼 5.11 Ensure that 'Notify all admins when other admins reset their password?' is set to 'Yes' (Manual)1no data
💼 5.12 Ensure that 'User consent for applications' is set to 'Do not allow user consent' (Manual)1no data
💼 5.13 Ensure that 'User consent for applications' is set to 'Allow user consent for apps from verified publishers, for selected permissions' (Manual)1no data
💼 5.14 Ensure that 'Users can register applications' is set to 'No' (Automated)1no data
💼 5.15 Ensure that 'Guest users access restrictions' is set to 'Guest user access is restricted to properties and memberships of their own directory objects' (Automated)1no data
💼 5.16 Ensure that 'Guest invite restrictions' is set to 'Only users assigned to specific admin roles [...]' or 'No one [..]' (Automated)1no data
💼 5.17 Ensure that 'Restrict access to Microsoft Entra admin center' is set to 'Yes' (Manual)1no data
💼 5.18 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes' (Manual)1no data
💼 5.19 Ensure that 'Users can create security groups in Azure portals, API or PowerShell' is set to 'No' (Manual)1no data
💼 5.20 Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No' (Manual)1no data
💼 5.21 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No' (Manual)1no data
💼 5.22 Ensure that 'Require Multifactor Authentication to register or join devices with Microsoft Entra' is set to 'Yes' (Manual)1no data
💼 5.23 Ensure that no custom subscription administrator roles exist (Automated)1no data
💼 5.24 Ensure that a custom role is assigned permissions for administering resource locks (Manual)1no data
💼 5.25 Ensure that 'Subscription leaving Microsoft Entra tenant' and 'Subscription entering Microsoft Entra tenant' is set to 'Permit no one' (Manual)1no data
💼 5.26 Ensure fewer than 5 users have global administrator assignment (Manual)1no data
💼 5.27 Ensure there are between 2 and 3 subscription owners (Automated)1no data
💼 5.28 Ensure passwordless authentication methods are considered (Manual)1no data