
Stefan Wey
➔ _ Microsoft 365 _ | _ MCT (Trainer) _ , _ 🪪 Identity (Entra),✉ Mail (Exchange), 👥Collaboration (
🇨🇭 Switzerland
Also contributed to
- CIS.M365.2.1.1(L2) Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy)
- CIS.M365.2.1.4(L2) Ensure Safe Attachments policy is enabled (Only Checks Default Policy)
- CIS.M365.2.1.5(L2) Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled
- CISA.MS.AAD.1.1Legacy authentication SHALL be blocked.
- CISA.MS.AAD.2.1Users detected as high risk SHALL be blocked.
- CISA.MS.AAD.2.3Sign-ins detected as high risk SHALL be blocked.
- CISA.MS.AAD.3.1Phishing-resistant MFA SHALL be enforced for all users.
- CISA.MS.AAD.3.2If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.
- CISA.MS.AAD.3.6Phishing-resistant MFA SHALL be required for highly privileged roles.
- CISA.MS.AAD.3.7Managed devices SHOULD be required for authentication.
- CISA.MS.AAD.3.8Managed Devices SHOULD be required to register MFA.
- CISA.MS.AAD.5.4Group owners SHALL NOT be allowed to consent to applications.
- CISA.MS.EXO.2.1A list of approved IP addresses for sending mail SHALL be maintained.
- CISA.MS.EXO.2.2An SPF policy SHALL be published for each domain, designating only these addresses as approved senders.
- CISA.MS.EXO.6.2Calendar details SHALL NOT be shared with all domains.
- CISA.MS.EXO.7.1External sender warnings SHALL be implemented.
- MT.1001At least one Conditional Access policy is configured with device compliance.
- MT.1003At least one Conditional Access policy is configured with All Apps.
- MT.1004At least one Conditional Access policy is configured with All Apps and All Users.
- MT.1005All Conditional Access policies are configured to exclude at least one emergency/break glass account or group.
- MT.1008At least one Conditional Access policy is configured to require MFA for Azure management.
- MT.1010At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync.
- MT.1016At least one Conditional Access policy is configured to require MFA for guest access.
- MT.1020All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope them.
- MT.1021Security Defaults are enabled.
- MT.1024MT.1024.$($RecommendationId -replace
- MT.1035All security groups assigned to Conditional Access Policies should be protected by RMAU.
- MT.1036All excluded objects should have a fallback include in another policy.
- MT.1038Conditional Access policies should not include or exclude deleted groups.
- MT.1042Restrict dial-in users from bypassing a meeting lobby
- MT.1045Only invited users should be automatically admitted to Teams meetings
- MT.1046Restrict anonymous users from joining meetings
- MT.1047Restrict anonymous users from starting Teams meetings
- MT.1048Limit external participants from having control in a Teams meeting