
Tests authored
- CISA.MS.AAD.2.1Users detected as high risk SHALL be blocked.
- CISA.MS.AAD.2.3Sign-ins detected as high risk SHALL be blocked.
- MT.1001At least one Conditional Access policy is configured with device compliance.
- MT.1003At least one Conditional Access policy is configured with All Apps.
- MT.1004At least one Conditional Access policy is configured with All Apps and All Users.
- MT.1021Security Defaults are enabled.
- MT.1034MT.1034.$($EmergencyAccessUsers.IndexOf($_)): Emergency access users should not be blocked ($($_.userPrincipalName))
- MT.1037Only users with Presenter role are allowed to present in Teams meetings
- MT.1038Conditional Access policies should not include or exclude deleted groups.
- MT.1055Microsoft 365 Group (and Team) creation should be restricted to approved users.
Also contributed to
- CIS.M365.1.1.3(L1) Ensure that between two and four global admins are designated
- CIS.M365.1.3.1(L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
- CIS.M365.1.3.3(L2) Ensure 'External sharing' of calendars is not available
- CIS.M365.1.3.5Ensure internal phishing protection for Forms is enabled
- CIS.M365.1.3.7Ensure
- CIS.M365.4.1Ensure devices without a compliance policy are marked
- CIS.M365.5.1.2.2Ensure third party integrated applications are not allowed
- CIS.M365.5.1.2.3Ensure
- CIS.M365.5.1.3.1Ensure a dynamic group for guest users is created
- CIS.M365.5.1.5.1Ensure user consent to apps accessing company data on their behalf is not allowed
- CIS.M365.5.1.5.2Ensure the admin consent workflow is enabled
- CIS.M365.5.1.6.2Ensure that guest user access is restricted
- CIS.M365.5.2.3.5Ensure weak authentication methods are disabled
- CIS.M365.8.1.1(L2) Ensure external file sharing in Teams is enabled for only approved cloud storage services
- CIS.M365.8.2.2(L1) Ensure communication with unmanaged Teams users is disabled
- CIS.M365.8.2.3Ensure external Teams users cannot initiate conversations
- CIS.M365.8.4.1(L1) Ensure all or a majority of third-party and custom apps are blocked
- CIS.M365.8.5.3(L1) Ensure only people in my org can bypass the lobby
- CIS.M365.8.6.1(L1) Ensure users can report security concerns in Teams to internal destination
- CISA.MS.AAD.1.1Legacy authentication SHALL be blocked.
- CISA.MS.AAD.2.2A notification SHOULD be sent to the administrator when high-risk users are detected.
- CISA.MS.AAD.3.4The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.
- CISA.MS.AAD.3.5The authentication methods SMS, Voice Call, and Email One-Time Passcode (OTP) SHALL be disabled.
- CISA.MS.AAD.3.6Phishing-resistant MFA SHALL be required for highly privileged roles.
- CISA.MS.AAD.5.1Only administrators SHALL be allowed to register applications.
- CISA.MS.AAD.5.2Only administrators SHALL be allowed to consent to applications.
- CISA.MS.AAD.5.3An admin consent workflow SHALL be configured for applications.
- CISA.MS.AAD.5.4Group owners SHALL NOT be allowed to consent to applications.
- CISA.MS.AAD.6.1User passwords SHALL NOT expire.
- CISA.MS.AAD.7.1A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role.
- CISA.MS.AAD.7.2Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.
- CISA.MS.AAD.7.3Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers.
- CISA.MS.AAD.8.1Guest users SHOULD have limited or restricted access to Azure AD directory objects.
- CISA.MS.EXO.1.1Automatic forwarding to external domains SHALL be disabled.
- CISA.MS.EXO.3.1DKIM SHOULD be enabled for all domains.
- CISA.MS.EXO.5.1SMTP AUTH SHALL be disabled.
- CISA.MS.EXO.6.1Contact folders SHALL NOT be shared with all domains.
- CISA.MS.EXO.7.1External sender warnings SHALL be implemented.
- CISA.MS.EXO.8.1A DLP solution SHALL be used.
- CISA.MS.EXO.8.2The DLP solution SHALL protect personally identifiable information (PII) and sensitive information, as defined by the agency.
- CISA.MS.EXO.12.1IP allow lists SHOULD NOT be created.
- CISA.MS.EXO.12.2Safe lists SHOULD NOT be enabled.
- CISA.MS.EXO.13.1Mailbox auditing SHALL be enabled.
- CISA.MS.EXO.17.2Microsoft Purview Audit (Premium) logging SHALL be enabled.
- CISA.MS.SHAREPOINT.1.1External sharing for SharePoint SHALL be limited to Existing guests or Only People in your organization.
- EIDSCA.AF01Authentication Method - FIDO2 security key - State.
- EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set up.
- EIDSCA.AF03Authentication Method - FIDO2 security key - Enforce attestation.
- EIDSCA.AF04Authentication Method - FIDO2 security key - Enforce key restrictions.
- EIDSCA.AF05Authentication Method - FIDO2 security key - Restricted.
- EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keys.
- EIDSCA.AG01Authentication Method - General Settings - Manage migration.
- EIDSCA.AG02Authentication Method - General Settings - Report suspicious activity - State.
- EIDSCA.AG03Authentication Method - General Settings - Report suspicious activity - Included users/groups.
- EIDSCA.AM01Authentication Method - Microsoft Authenticator - State.
- EIDSCA.AM02Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP.
- EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notifications.
- EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications.
- EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications.
- EIDSCA.AM07Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications.
- EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications.
- EIDSCA.AM10Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications.
- EIDSCA.AP01Default Authorization Settings - Enabled Self service password reset for administrators.
- EIDSCA.AP04Default Authorization Settings - Guest invite restrictions.
- EIDSCA.AP05Default Authorization Settings - Sign-up for email based subscription.
- EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validation.
- EIDSCA.AP07Default Authorization Settings - Guest user access.
- EIDSCA.AP08Default Authorization Settings - User consent policy assigned for applications.
- EIDSCA.AP09Default Authorization Settings - Allow user consent on risk-based apps.
- EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create Apps.
- EIDSCA.AP14Default Authorization Settings - Default User Role Permissions - Allowed to read other users.
- EIDSCA.AS04Authentication Method - SMS - Use for sign-in.
- EIDSCA.AT01Authentication Method - Temporary Access Pass - State.
- EIDSCA.AT02Authentication Method - Temporary Access Pass - One-time.
- EIDSCA.AV01Authentication Method - Voice call - State.
- EIDSCA.CP01Default Settings - Consent Policy Settings - Group owner consent for apps accessing data.
- EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky apps.
- EIDSCA.CP04Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to.
- EIDSCA.CR01Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature.
- EIDSCA.CR02Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests.
- EIDSCA.CR03Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire.
- EIDSCA.CR04Consent Framework - Admin Consent Request - Consent request duration (days).
- EIDSCA.PR01Default Settings - Password Rule Settings - Password Protection - Mode.
- EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory.
- EIDSCA.PR03Default Settings - Password Rule Settings - Enforce custom list.
- EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds.
- EIDSCA.PR06Default Settings - Password Rule Settings - Smart Lockout - Lockout threshold.
- EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner.
- EIDSCA.ST09Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content.
- MT.1002App management restrictions on applications and service principals is configured and enabled.
- MT.1005All Conditional Access policies are configured to exclude at least one emergency/break glass account or group.
- MT.1006At least one Conditional Access policy is configured to require MFA for admins.
- MT.1007At least one Conditional Access policy is configured to require MFA for all users.
- MT.1008At least one Conditional Access policy is configured to require MFA for Azure management.
- MT.1009At least one Conditional Access policy is configured to block other legacy authentication.
- MT.1010At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync.
- MT.1011At least one Conditional Access policy is configured to secure security info registration only from a trusted location.
- MT.1012At least one Conditional Access policy is configured to require MFA for risky sign-ins.
- MT.1013At least one Conditional Access policy is configured to require new password when user risk is high.
- MT.1014At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for admins.
- MT.1015At least one Conditional Access policy is configured to block access for unknown or unsupported device platforms.
- MT.1016At least one Conditional Access policy is configured to require MFA for guest access.
- MT.1017At least one Conditional Access policy is configured to enforce non persistent browser session for non-corporate devices.
- MT.1018At least one Conditional Access policy is configured to enforce sign-in frequency for non-corporate devices.
- MT.1019At least one Conditional Access policy is configured to enable application enforced restrictions.
- MT.1020All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope them.
- MT.1022All users utilizing a P1 license should be licensed.
- MT.1023All users utilizing a P2 license should be licensed.
- MT.1024MT.1024.$($RecommendationId -replace
- MT.1029Stale accounts are not assigned to privileged roles.
- MT.1030Eligible role assignments on Control Plane are in use by administrators.
- MT.1031Privileged role on Control Plane are managed by PIM only.
- MT.1032Limited number of Global Admins are assigned.
- MT.1033MT.1033.$($RegularUsers.IndexOf($_)): User should be blocked from using legacy authentication ($($_.userPrincipalName))
- MT.1042Restrict dial-in users from bypassing a meeting lobby
- MT.1045Only invited users should be automatically admitted to Teams meetings
- MT.1046Restrict anonymous users from joining meetings
- MT.1047Restrict anonymous users from starting Teams meetings
- MT.1048Limit external participants from having control in a Teams meeting
- MT.1049Conditional Access policies for User Risk and Sign-in Risk should be configured separately.
- MT.1050Apps with high-risk permissions having a direct path to Global Admin
- MT.1051Apps with high-risk permissions having an indirect path to Global Admin
- MT.1052At least one Conditional Access policy is targeting the Device Code authentication flow.
- MT.1053Ensure intune device clean-up rule is configured
- MT.1054Ensure built-in Device Compliance Policy marks devices with no compliance policy assigned as 'Not compliant'
- MT.1056Ensure that no person has permanent access to all Azure subscriptions at the root scope
- MT.1057Ensure Microsoft 365 Group (and Team) expiration is configured to notify users.
- MT.1058Ensure Microsoft 365 Group (and Team) expiration is configured to auto-expire groups.
- ORCA.100Bulk Complaint Level threshold is between 4 and 6.
- ORCA.101Bulk is marked as spam.
- ORCA.102Advanced Spam filter options are turned off.
- ORCA.103Outbound spam filter policy settings configured.
- ORCA.104High Confidence Phish action set to Quarantine message.
- ORCA.105Safe Links Synchronous URL detonation is enabled.
- ORCA.106Quarantine retention period is 30 days.
- ORCA.107End-user spam notification is enabled.
- ORCA.108DKIM signing is set up for all your custom domains.
- ORCA.108.1DNS Records have been set up to support DKIM.
- ORCA.109Senders are not being allow listed in an unsafe manner.
- ORCA.110Internal Sender notifications are disabled.
- ORCA.111Anti-phishing policy exists and EnableUnauthenticatedSender is true.
- ORCA.112Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy.
- ORCA.113AllowClickThrough is disabled in Safe Links policies.
- ORCA.114No IP Allow Lists have been configured.
- ORCA.115Mailbox intelligence based impersonation protection is enabled in anti-phishing policies.
- ORCA.116Mailbox intelligence based impersonation protection action set to move message to junk mail folder.
- ORCA.118.1Domains are not being allow listed in an unsafe manner in Anti-Spam Policies.
- ORCA.118.2Domains are not being allow listed in an unsafe manner in Transport Rules.
- ORCA.118.3Your own domains are not being allow listed in an unsafe manner in Anti-Spam Policies.
- ORCA.118.4Your own domains are not being allow listed in an unsafe manner in Transport Rules.
- ORCA.119Similar Domains Safety Tips is enabled.
- ORCA.120.1Zero Hour Autopurge Enabled for Phish.
- ORCA.120.2Zero Hour Autopurge Enabled for Malware.
- ORCA.120.3Zero Hour Autopurge Enabled for Spam.
- ORCA.121Supported filter policy action used.
- ORCA.123Unusual Characters Safety Tips is enabled.
- ORCA.124Safe attachments unknown malware response set to block messages.
- ORCA.139Spam action set to move message to junk mail folder or quarantine.
- ORCA.140High Confidence Spam action set to Quarantine message.
- ORCA.141Bulk action set to Move message to Junk Email Folder.
- ORCA.142Phish action set to Quarantine message.
- ORCA.143Safety Tips are enabled.
- ORCA.156Safe Links Policies are tracking when user clicks on safe links.
- ORCA.158Safe Attachments is enabled for SharePoint and Teams.
- ORCA.179Safe Links is enabled intra-organization.
- ORCA.180Anti-phishing policy exists and EnableSpoofIntelligence is true.
- ORCA.189Safe Attachments is not bypassed.
- ORCA.189.2Safe Links is not bypassed.
- ORCA.205Common attachment type filter is enabled.
- ORCA.220Advanced Phish filter Threshold level is adequate.
- ORCA.221Mailbox intelligence is enabled in anti-phishing policies.
- ORCA.222Domain Impersonation action is set to move to Quarantine.
- ORCA.223User impersonation action is set to move to Quarantine.
- ORCA.224Similar Users Safety Tips is enabled.
- ORCA.225Safe Documents is enabled for Office clients.
- ORCA.226Each domain has a Safe Link policy applied to it.
- ORCA.227Each domain has a Safe Attachments policy applied to it.
- ORCA.228No trusted senders in Anti-phishing policy.
- ORCA.229No trusted domains in Anti-phishing policy.
- ORCA.230Each domain has a Anti-phishing policy applied to it, or the default policy is being used.
- ORCA.231Each domain has a anti-spam policy applied to it, or the default policy is being used.
- ORCA.232Each domain has a malware filter policy applied to it, or the default policy is being used.
- ORCA.233Domains are pointed directly at EOP or enhanced filtering is used.
- ORCA.233.1Domains are pointed directly at EOP or enhanced filtering is configured on all default connectors.
- ORCA.234Click through is disabled for Safe Documents.
- ORCA.235SPF records is set up for all your custom domains.
- ORCA.236Safe Links is enabled for emails.
- ORCA.237Safe Links is enabled for teams messages.
- ORCA.238Safe Links is enabled for office documents.
- ORCA.239No exclusions for the built-in protection policies.
- ORCA.240Outlook is configured to display external tags for external emails.
- ORCA.241Anti-phishing policy exists and EnableFirstContactSafetyTips is true.
- ORCA.242Important protection alerts responsible for AIR activities are enabled.
- ORCA.243Authenticated Receive Chain is set up for domains not pointing to EOP/MDO, or all domains point to EOP/MDO.
- ORCA.244Policies are configured to honor sending domains DMARC.