
Also contributed to
- CISA.MS.AAD.3.6Phishing-resistant MFA SHALL be required for highly privileged roles.
- CISA.MS.AAD.3.7Managed devices SHOULD be required for authentication.
- CISA.MS.AAD.3.8Managed Devices SHOULD be required to register MFA.
- CISA.MS.AAD.5.3An admin consent workflow SHALL be configured for applications.
- CISA.MS.AAD.5.4Group owners SHALL NOT be allowed to consent to applications.
- CISA.MS.AAD.6.1User passwords SHALL NOT expire.
- CISA.MS.AAD.7.1A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role.
- CISA.MS.AAD.7.4Permanent active role assignments SHALL NOT be allowed for highly privileged roles.
- CISA.MS.AAD.7.5Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system.
- CISA.MS.AAD.7.6Activation of the Global Administrator role SHALL require approval.
- CISA.MS.AAD.7.7Eligible and Active highly privileged role assignments SHALL trigger an alert.
- CISA.MS.AAD.7.8User activation of the Global Administrator role SHALL trigger an alert.
- CISA.MS.AAD.7.9User activation of other highly privileged roles SHOULD trigger an alert.
- CISA.MS.AAD.8.1Guest users SHOULD have limited or restricted access to Azure AD directory objects.
- CISA.MS.AAD.8.2Only users with the Guest Inviter role SHOULD be able to invite guest users.
- MT.1007At least one Conditional Access policy is configured to require MFA for all users.
- MT.1012At least one Conditional Access policy is configured to require MFA for risky sign-ins.
- MT.1033MT.1033.$($RegularUsers.IndexOf($_)): User should be blocked from using legacy authentication ($($_.userPrincipalName))
