
Michael Soule
Co-creator of Maester
Tests authored
- CIS.M365.1.1.1(L1) Ensure Administrative accounts are cloud-only
- CIS.M365.1.3.3(L2) Ensure 'External sharing' of calendars is not available
- CISA.MS.AAD.1.1Legacy authentication SHALL be blocked.
- CISA.MS.AAD.2.2A notification SHOULD be sent to the administrator when high-risk users are detected.
- CISA.MS.AAD.3.1Phishing-resistant MFA SHALL be enforced for all users.
- CISA.MS.AAD.3.2If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.
- CISA.MS.AAD.3.3If Microsoft Authenticator is enabled, it SHALL be configured to show login context information.
- CISA.MS.AAD.3.4The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.
- CISA.MS.AAD.3.5The authentication methods SMS, Voice Call, and Email One-Time Passcode (OTP) SHALL be disabled.
- CISA.MS.AAD.3.6Phishing-resistant MFA SHALL be required for highly privileged roles.
- CISA.MS.AAD.3.7Managed devices SHOULD be required for authentication.
- CISA.MS.AAD.3.8Managed Devices SHOULD be required to register MFA.
- CISA.MS.AAD.4.1Security logs SHALL be sent to the agency's security operations center for monitoring.
- CISA.MS.AAD.5.1Only administrators SHALL be allowed to register applications.
- CISA.MS.AAD.5.2Only administrators SHALL be allowed to consent to applications.
- CISA.MS.AAD.5.3An admin consent workflow SHALL be configured for applications.
- CISA.MS.AAD.5.4Group owners SHALL NOT be allowed to consent to applications.
- CISA.MS.AAD.6.1User passwords SHALL NOT expire.
- CISA.MS.AAD.7.1A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role.
- CISA.MS.AAD.7.2Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.
- CISA.MS.AAD.7.3Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers.
- CISA.MS.AAD.7.4Permanent active role assignments SHALL NOT be allowed for highly privileged roles.
- CISA.MS.AAD.7.5Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system.
- CISA.MS.AAD.7.6Activation of the Global Administrator role SHALL require approval.
- CISA.MS.AAD.7.7Eligible and Active highly privileged role assignments SHALL trigger an alert.
- CISA.MS.AAD.7.8User activation of the Global Administrator role SHALL trigger an alert.
- CISA.MS.AAD.7.9User activation of other highly privileged roles SHOULD trigger an alert.
- CISA.MS.AAD.8.1Guest users SHOULD have limited or restricted access to Azure AD directory objects.
- CISA.MS.AAD.8.2Only users with the Guest Inviter role SHOULD be able to invite guest users.
- CISA.MS.AAD.8.3Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes.
- CISA.MS.EXO.1.1Automatic forwarding to external domains SHALL be disabled.
- CISA.MS.EXO.2.1A list of approved IP addresses for sending mail SHALL be maintained.
- CISA.MS.EXO.2.2An SPF policy SHALL be published for each domain, designating only these addresses as approved senders.
- CISA.MS.EXO.3.1DKIM SHOULD be enabled for all domains.
- CISA.MS.EXO.4.1A DMARC policy SHALL be published for every second-level domain.
- CISA.MS.EXO.4.2The DMARC message rejection option SHALL be p=reject.
- CISA.MS.EXO.4.3The DMARC point of contact for aggregate reports SHALL include reports@dmarc.cyber.dhs.gov.
- CISA.MS.EXO.5.1SMTP AUTH SHALL be disabled.
- CISA.MS.EXO.6.1Contact folders SHALL NOT be shared with all domains.
- CISA.MS.EXO.6.2Calendar details SHALL NOT be shared with all domains.
- CISA.MS.EXO.7.1External sender warnings SHALL be implemented.
- CISA.MS.EXO.8.1A DLP solution SHALL be used.
- CISA.MS.EXO.8.2The DLP solution SHALL protect personally identifiable information (PII) and sensitive information, as defined by the agency.
- CISA.MS.EXO.8.3The selected DLP solution SHOULD offer services comparable to the native DLP solution offered by Microsoft.
- CISA.MS.EXO.8.4At a minimum, the DLP solution SHALL restrict sharing credit card numbers, U.S. Individual Taxpayer Identification Numbers (ITIN), and U.S. Social Security numbers (SSN) via email.
- CISA.MS.EXO.9.1Emails SHALL be filtered by attachment file types.
- CISA.MS.EXO.9.2The attachment filter SHOULD attempt to determine the true file type and assess the file extension.
- CISA.MS.EXO.9.3Disallowed file types SHALL be determined and enforced.
- CISA.MS.EXO.9.4Alternatively chosen filtering solutions SHOULD offer services comparable to Microsoft Defender's Common Attachment Filter.
- CISA.MS.EXO.9.5At a minimum, click-to-run files SHOULD be blocked (e.g., .exe, .cmd, and .vbe).
- CISA.MS.EXO.10.1Emails SHALL be scanned for malware.
- CISA.MS.EXO.10.2Emails identified as containing malware SHALL be quarantined or dropped.
- CISA.MS.EXO.10.3Email scanning SHALL be capable of reviewing emails after delivery.
- CISA.MS.EXO.11.1Impersonation protection checks SHOULD be used.
- CISA.MS.EXO.11.2User warnings, comparable to the user safety tips included with EOP, SHOULD be displayed.
- CISA.MS.EXO.11.3The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence.
- CISA.MS.EXO.12.1IP allow lists SHOULD NOT be created.
- CISA.MS.EXO.12.2Safe lists SHOULD NOT be enabled.
- CISA.MS.EXO.13.1Mailbox auditing SHALL be enabled.
- CISA.MS.EXO.14.1A spam filter SHALL be enabled.
- CISA.MS.EXO.14.2Spam and high confidence spam SHALL be moved to either the junk email folder or the quarantine folder.
- CISA.MS.EXO.14.3Allowed domains SHALL NOT be added to inbound anti-spam protection policies.
- CISA.MS.EXO.14.4If a third-party party filtering solution is used, the solution SHOULD offer services comparable to the native spam filtering offered by Microsoft.
- CISA.MS.EXO.15.1URL comparison with a block-list SHOULD be enabled.
- CISA.MS.EXO.15.2Direct download links SHOULD be scanned for malware.
- CISA.MS.EXO.15.3User click tracking SHOULD be enabled.
- CISA.MS.EXO.16.1Alerts SHALL be enabled.
- CISA.MS.EXO.16.2Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system.
- CISA.MS.EXO.17.1Microsoft Purview Audit (Standard) logging SHALL be enabled.
- CISA.MS.EXO.17.2Microsoft Purview Audit (Premium) logging SHALL be enabled.
- CISA.MS.EXO.17.3Audit logs SHALL be maintained for at least the minimum duration dictated by OMB M-21-31 (Appendix C).
- CISA.MS.SHAREPOINT.1.1External sharing for SharePoint SHALL be limited to Existing guests or Only People in your organization.
- CISA.MS.SHAREPOINT.1.3External sharing SHALL be restricted to approved external domains and/or users in approved security groups per interagency collaboration needs.
- MT.1042Restrict dial-in users from bypassing a meeting lobby
- MT.1045Only invited users should be automatically admitted to Teams meetings
- MT.1046Restrict anonymous users from joining meetings
- MT.1047Restrict anonymous users from starting Teams meetings
- MT.1048Limit external participants from having control in a Teams meeting
- MT.1076MOERA SHOULD NOT be used for sent mail.
- ORCA.100Bulk Complaint Level threshold is between 4 and 6.
- ORCA.101Bulk is marked as spam.
- ORCA.102Advanced Spam filter options are turned off.
- ORCA.103Outbound spam filter policy settings configured.
- ORCA.104High Confidence Phish action set to Quarantine message.
- ORCA.105Safe Links Synchronous URL detonation is enabled.
- ORCA.106Quarantine retention period is 30 days.
- ORCA.107End-user spam notification is enabled.
- ORCA.108DKIM signing is set up for all your custom domains.
- ORCA.109Senders are not being allow listed in an unsafe manner.
- ORCA.110Internal Sender notifications are disabled.
- ORCA.111Anti-phishing policy exists and EnableUnauthenticatedSender is true.
- ORCA.112Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy.
- ORCA.113AllowClickThrough is disabled in Safe Links policies.
- ORCA.114No IP Allow Lists have been configured.
- ORCA.115Mailbox intelligence based impersonation protection is enabled in anti-phishing policies.
- ORCA.116Mailbox intelligence based impersonation protection action set to move message to junk mail folder.
- ORCA.119Similar Domains Safety Tips is enabled.
- ORCA.121Supported filter policy action used.
- ORCA.123Unusual Characters Safety Tips is enabled.
- ORCA.124Safe attachments unknown malware response set to block messages.
- ORCA.139Spam action set to move message to junk mail folder or quarantine.
- ORCA.140High Confidence Spam action set to Quarantine message.
- ORCA.141Bulk action set to Move message to Junk Email Folder.
- ORCA.142Phish action set to Quarantine message.
- ORCA.143Safety Tips are enabled.
- ORCA.156Safe Links Policies are tracking when user clicks on safe links.
- ORCA.158Safe Attachments is enabled for SharePoint and Teams.
- ORCA.179Safe Links is enabled intra-organization.
- ORCA.180Anti-phishing policy exists and EnableSpoofIntelligence is true.
- ORCA.189Safe Attachments is not bypassed.
- ORCA.205Common attachment type filter is enabled.
- ORCA.220Advanced Phish filter Threshold level is adequate.
- ORCA.221Mailbox intelligence is enabled in anti-phishing policies.
- ORCA.222Domain Impersonation action is set to move to Quarantine.
- ORCA.223User impersonation action is set to move to Quarantine.
- ORCA.224Similar Users Safety Tips is enabled.
- ORCA.225Safe Documents is enabled for Office clients.
- ORCA.226Each domain has a Safe Link policy applied to it.
- ORCA.227Each domain has a Safe Attachments policy applied to it.
- ORCA.228No trusted senders in Anti-phishing policy.
- ORCA.229No trusted domains in Anti-phishing policy.
- ORCA.230Each domain has a Anti-phishing policy applied to it, or the default policy is being used.
- ORCA.231Each domain has a anti-spam policy applied to it, or the default policy is being used.
- ORCA.232Each domain has a malware filter policy applied to it, or the default policy is being used.
- ORCA.233Domains are pointed directly at EOP or enhanced filtering is used.
- ORCA.234Click through is disabled for Safe Documents.
- ORCA.235SPF records is set up for all your custom domains.
- ORCA.236Safe Links is enabled for emails.
- ORCA.237Safe Links is enabled for teams messages.
- ORCA.238Safe Links is enabled for office documents.
- ORCA.239No exclusions for the built-in protection policies.
- ORCA.240Outlook is configured to display external tags for external emails.
- ORCA.241Anti-phishing policy exists and EnableFirstContactSafetyTips is true.
- ORCA.242Important protection alerts responsible for AIR activities are enabled.
- ORCA.243Authenticated Receive Chain is set up for domains not pointing to EOP/MDO, or all domains point to EOP/MDO.
- ORCA.244Policies are configured to honor sending domains DMARC.
Also contributed to
- CISA.MS.AAD.2.1Users detected as high risk SHALL be blocked.
- CISA.MS.AAD.2.3Sign-ins detected as high risk SHALL be blocked.
- MT.1021Security Defaults are enabled.
- MT.1036All excluded objects should have a fallback include in another policy.
- ORCA.108.1DNS Records have been set up to support DKIM.
- ORCA.118.1Domains are not being allow listed in an unsafe manner in Anti-Spam Policies.
- ORCA.118.2Domains are not being allow listed in an unsafe manner in Transport Rules.
- ORCA.118.3Your own domains are not being allow listed in an unsafe manner in Anti-Spam Policies.
- ORCA.118.4Your own domains are not being allow listed in an unsafe manner in Transport Rules.
- ORCA.120.1Zero Hour Autopurge Enabled for Phish.
- ORCA.120.2Zero Hour Autopurge Enabled for Malware.
- ORCA.120.3Zero Hour Autopurge Enabled for Spam.
- ORCA.189.2Safe Links is not bypassed.
- ORCA.233.1Domains are pointed directly at EOP or enhanced filtering is configured on all default connectors.