Skip to content

Microsoft 365 Security Checks

All security checks Aether365 performs for Microsoft 365.

IDTitleSeverityFramework
AE.1001At least one Conditional Access policy is configured with device complianceMediumOther
AE.1002Enforce credential configurations on apps and service principalsMediumOther
AE.1003At least one Conditional Access policy is configured with All cloud appsMediumOther
AE.1004At least one Conditional Access policy is configured with All Cloud Apps and All UsersMediumOther
AE.1005All Conditional Access policies are configured to exclude at least one emergency account or group.MediumOther
AE.1006At least one Conditional Access policy is configured to require MFA for users with administrator rolesMediumOther
AE.1007At least one Conditional Access policy is configured to require MFA for all usersMediumOther
AE.1008At least one Conditional Access policy is configured to require MFA for Azure managementMediumOther
AE.1009At least one Conditional Access policy is configured to block other legacy authenticationMediumOther
AE.1010At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSyncMediumOther
AE.1011At least one Conditional Access policy is configured to secure security info registration only from a trusted locationMediumOther
AE.1012At least one Conditional Access policy is configured to require MFA for risky sign-insMediumOther
AE.1013At least one Conditional Access policy is configured to require new password when user risk is highMediumOther
AE.1014At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for adminsMediumOther
AE.1015At least one Conditional Access policy is configured to block access for unknown or unsupported device platformsMediumOther
AE.1016At least one Conditional Access policy is configured to require MFA for guest accessMediumOther
AE.1017At least one Conditional Access policy is configured to enforce non persistent browser session for non-corporate devicesMediumOther
AE.1018At least one Conditional Access policy is configured to enforce sign-in frequency for non-corporate devicesMediumOther
AE.1019At least one Conditional Access policy is configured to enable application enforced restrictionsMediumOther
AE.1020All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope themMediumOther
AE.1021Security Defaults are enabledMediumOther
AE.1022All users utilizing a P1 license should be licensedMediumOther
AE.1023All users utilizing a P2 license should be licensedMediumOther
AE.1024Microsoft Entra recommendationsMediumOther
AE.1025No external user with permanent role assignment on Control PlaneMediumOther
AE.1026No hybrid user with permanent role assignment on Control PlaneMediumOther
AE.1027No Service Principal with Client Secret and permanent role assignment on Control PlaneMediumOther
AE.1028No user with mailbox and permanent role assignment on Control PlaneMediumOther
AE.1029Stale accounts are not assigned to privileged rolesMediumOther
AE.1030Eligible role assignments on Control Plane are in use by administratorsMediumOther
AE.1031Privileged role on Control Plane are managed by PIM onlyMediumOther
AE.1032Limited number of Global Admins are assignedMediumOther
AE.1033User should be blocked from using legacy authenticationMediumOther
AE.1034Emergency access users should not be blockedMediumOther
AE.1035All security groups assigned to Conditional Access Policies should be protected by RMAUMediumOther
AE.1036All excluded objects should have a fallback include in another policy.MediumOther
AE.1038Conditional Access policies should not include or exclude deleted groups.MediumOther
AE.1039Ensure MailTips are enabled for end usersMediumOther
AE.1041Ensure users installing Outlook add-ins is not allowedMediumOther
AE.1043Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domainsMediumOther
AE.1044Ensure modern authentication for Exchange Online is enabledMediumOther
AE.1049Sign-in risk and user risk conditions should be configured in separate Conditional Access policiesMediumOther
AE.1050Apps with high-risk permissions having a direct path to Global AdminMediumOther
AE.1051Apps with high-risk permissions having an indirect path to Global AdminMediumOther
AE.1052At least one Conditional Access policy is targeting the Device Code authentication flow.MediumOther
AE.1055Microsoft 365 Group (and Team) creation should be restricted to approved usersMediumOther
AE.1056User Access Administrator permission should not be permanently assigned on the root scopeMediumOther
AE.1057App registrations should no longer use secretsMediumOther
AE.1058Exchange Application Access Policies should be configuredMediumOther
AE.1059Microsoft Defender for Identity health issues should be resolvedMediumOther
AE.1060Drift testsMediumOther
AE.1061Device registration MFA control conflicts with Conditional Access policies.MediumOther
AE.1062Ensure Direct Send is set to be rejectedMediumOther
AE.1064Ensure that write permissions are required to create new management groupsMediumOther
AE.1065Ensure all Recovery Services Vaults have soft delete enabledMediumOther
AE.1066Conditional Access policies should not reference non-existent users, groups, or roles.MediumOther
AE.1067Authentication method policies should not reference non-existent groups.MediumOther
AE.1071At least one Conditional Access policy explicitly includes Azure DevOps.MediumOther
AE.1072No conditional access policy should require an approved client app.MediumOther
AE.1073Soft- and hard-matching of synchronized objects should be blocked.MediumOther
AE.1074Mailbox should not use the .onmicrosoft.com domain as primary SMTP address.MediumOther
AE.1076MOERA SHOULD NOT be used for sent mail.MediumOther
AE.1083Ensure Delicensing Resiliency is enabledMediumOther
AE.1086Devices should not share both critical and non-critical user credentials.MediumOther
AE.1087Devices should not be publicly exposed with remotely exploitable, highly likely to be exploited, high or critical severity CVE's.MediumOther
AE.1088Devices with critical credentials should be protected by TPM.MediumOther
AE.1089Devices with critical credentials should be protected by Credential Guard.MediumOther
AE.1113AI agents should not be shared with broad access control policiesMediumOther
AE.1114AI agents should require user authenticationMediumOther
AE.1115AI agents should not have risky HTTP configurationsMediumOther
AE.1116AI agents should not send email with AI-controlled inputsMediumOther
AE.1117Published AI agents should not be dormantMediumOther
AE.1118AI agents should not use author (maker) authentication for connectionsMediumOther
AE.1119AI agents should not have hard-coded credentials in topicsMediumOther
AE.1120AI agents should not use MCP server tools without reviewMediumOther
AE.1121AI agents with generative orchestration should have custom instructionsMediumOther
AE.1122AI agents should not have orphaned ownershipMediumOther
AE.1147Do not sync krbtgt_AzureAD to Entra IDMediumOther
AZDO.1000Azure DevOps OAuth apps can access resources in your organization through OAuth.MediumOther
AZDO.1001Identities can connect to your organization's Git repos through SSH.MediumOther
AZDO.1002Log Audit Events.MediumOther
AZDO.1003Restrict public projects.MediumOther
AZDO.1004Additional protections when using public package registries.MediumOther
AZDO.1005IP Conditional Access policy validation.MediumOther
AZDO.1006External Users access.MediumOther
AZDO.1007Team and project administrator are allowed to invite new users.MediumOther
AZDO.1008Request access to Azure DevOps by e-mail notifications to administrators.MediumOther
AZDO.1009Feedback Collection.MediumOther
AZDO.1010Audit streaming.MediumOther
AZDO.1011Project Resource Limits.MediumOther
AZDO.1012Work Items Tags Limits.MediumOther
AZDO.1013Organization Owner should not be an individual.MediumOther
AZDO.1014Anonymous access to pipeline badges.MediumOther
AZDO.1015Limit variables that can be set at queue time.MediumOther
AZDO.1016Limit job authorization scope to current project for non-release pipelines.MediumOther
AZDO.1017Limit job authorization scope to current project for classic release pipelines.MediumOther
AZDO.1018Protect access to repositories in YAML pipelines.MediumOther
AZDO.1019Stage chooser.MediumOther
AZDO.1020Creation of classic build pipelines.MediumOther
AZDO.1021Creation of classic release pipelines.MediumOther
AZDO.1022Limit building pull requests from forked GitHub repositories.MediumOther
AZDO.1023Disable Marketplace tasks.MediumOther
AZDO.1024Disable Node 6 tasks.MediumOther
AZDO.1025Enable shell tasks arguments validation.MediumOther
AZDO.1026Enable automatic enrollment to Advanced Security for Azure DevOps.MediumOther
AZDO.1027Disable showing Gravatar images for users outside of your enterprise.MediumOther
AZDO.1028Disable creation of TFVC repositories.MediumOther
AZDO.1029Storage Usage Limit.MediumOther
AZDO.1030Project Collection Administrators.MediumOther
AZDO.1031Validate SSH Key Expiration.MediumOther
AZDO.1032(Tenant) Restrict creation of global Personal Access Tokens.MediumOther
AZDO.1033(Tenant) Enable automatic revocation of leaked Personal Access Tokens.MediumOther
AZDO.1034(Tenant) Restrict creation of new Azure DevOps organizations.MediumOther
AZDO.1035(Tenant) Restrict Personal Access Token lifespan.MediumOther
AZDO.1036(Tenant) Restrict Personal Access Token full scope.MediumOther
AZDO.1037(Organization) Restrict Personal Access Token creation.MediumOther
AZDO.1038(Organization) Disallow extensions from accessing resources on the local network.MediumOther
CIS.M365.1.1.1Ensure Administrative accounts are cloud-onlyMediumCIS
CIS.M365.1.1.3Ensure that between two and four global admins are designatedMediumCIS
CIS.M365.1.2.1Ensure that only organizationally managed/approved public groups existHighCIS
CIS.M365.1.2.2Ensure sign-in to shared mailboxes is blockedMediumCIS
CIS.M365.1.3.1Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'MediumCIS
CIS.M365.1.3.3Ensure 'External sharing' of calendars is not availableHighCIS
CIS.M365.1.3.4Ensure 'User owned apps and services' is restrictedMediumCIS
CIS.M365.1.3.5Ensure internal phishing protection for Forms is enabledMediumCIS
CIS.M365.1.3.6Ensure the customer lockbox feature is enabledMediumOther
CIS.M365.1.3.7Ensure 'third-party storage services' are restricted in 'Microsoft 365 on the web'HighCIS
CIS.M365.2.1.1Ensure Safe Links for Office Applications is Enabled (Only Checks Priority 0 Policy)HighCIS
CIS.M365.2.1.11Ensure comprehensive attachment filtering is appliedHighCIS
CIS.M365.2.1.12Ensure the connection filter IP allow list is not used (Only Checks Default Policy)MediumCIS
CIS.M365.2.1.13Ensure the connection filter safe list is off (Only Checks Default Policy)MediumCIS
CIS.M365.2.1.2Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy)MediumCIS
CIS.M365.2.1.3Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy)MediumCIS
CIS.M365.2.1.4Ensure Safe Attachments policy is enabled (Only Checks Default Policy)HighCIS
CIS.M365.2.1.5Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is EnabledHighCIS
CIS.M365.2.1.6Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy)MediumCIS
CIS.M365.2.1.7Ensure that an anti-phishing policy has been created (Only Checks Default Policy)MediumCIS
CIS.M365.2.1.9Ensure that DKIM is enabled for all Exchange Online DomainsMediumCIS
CIS.M365.2.4.4Ensure Zero-hour auto purge for Microsoft Teams is on (Only Checks ZAP is enabled)MediumCIS
CIS.M365.3.1.1Ensure Microsoft 365 audit log search is EnabledMediumCIS
CIS.M365.4.1Ensure devices without a compliance policy are marked 'not compliant'HighCIS
CIS.M365.5.1.2.2Ensure third party integrated applications are not allowedHighCIS
CIS.M365.5.1.2.3Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes'MediumCIS
CIS.M365.5.1.3.1Ensure a dynamic group for guest users is createdMediumCIS
CIS.M365.5.1.5.1Ensure user consent to apps accessing company data on their behalf is not allowedHighCIS
CIS.M365.5.1.5.2Ensure the admin consent workflow is enabledMediumCIS
CIS.M365.5.1.6.2Ensure that guest user access is restrictedMediumCIS
CIS.M365.5.2.3.5Ensure weak authentication methods are disabledMediumCIS
CIS.M365.6.5.3Ensure additional storage providers are restricted in Outlook on the webHighCIS
CIS.M365.8.1.1Ensure external file sharing in Teams is enabled for only approved cloud storage servicesMediumCIS
CIS.M365.8.2.2Ensure communication with unmanaged Teams users is disabledMediumCIS
CIS.M365.8.2.3Ensure external Teams users cannot initiate conversationsMediumCIS
CIS.M365.8.4.1Ensure all or a majority of third-party and custom apps are blockedMediumCIS
CIS.M365.8.5.3Ensure only people in my org can bypass the lobbyMediumCIS
CIS.M365.8.6.1Ensure users can report security concerns in Teams to internal destinationMediumCIS
CISA.MS.EXO.1.1Automatic forwarding to external domains SHALL be disabled.MediumCIS
CISA.MS.EXO.10.1Emails SHALL be scanned for malware.MediumCIS
CISA.MS.EXO.10.2Emails identified as containing malware SHALL be quarantined or dropped.MediumCIS
CISA.MS.EXO.10.3Email scanning SHALL be capable of reviewing emails after delivery.MediumCIS
CISA.MS.EXO.11.1Impersonation protection checks SHOULD be used.MediumCIS
CISA.MS.EXO.11.2User warnings, comparable to the user safety tips included with EOP, SHOULD be displayed.MediumCIS
CISA.MS.EXO.11.3The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence.MediumCIS
CISA.MS.EXO.12.1IP allow lists SHOULD NOT be created.MediumCIS
CISA.MS.EXO.12.2Safe lists SHOULD NOT be enabled.MediumCIS
CISA.MS.EXO.13.1Mailbox auditing SHALL be enabled.MediumCIS
CISA.MS.EXO.14.1A spam filter SHALL be enabled.MediumCIS
CISA.MS.EXO.14.2Spam and high confidence spam SHALL be moved to either the junk email folder or the quarantine folder.MediumCIS
CISA.MS.EXO.14.3Allowed domains SHALL NOT be added to inbound anti-spam protection policies.MediumCIS
CISA.MS.EXO.14.4If a third-party party filtering solution is used, the solution SHOULD offer services comparable to the native spam filtering offered by Microsoft.MediumCIS
CISA.MS.EXO.15.1URL comparison with a block-list SHOULD be enabled.MediumCIS
CISA.MS.EXO.15.2Direct download links SHOULD be scanned for malware.MediumCIS
CISA.MS.EXO.15.3User click tracking SHOULD be enabled.MediumCIS
CISA.MS.EXO.16.1Alerts SHALL be enabled.MediumCIS
CISA.MS.EXO.16.2Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system.MediumCIS
CISA.MS.EXO.17.1Microsoft Purview Audit (Standard) logging SHALL be enabled.MediumCIS
CISA.MS.EXO.17.2Microsoft Purview Audit (Premium) logging SHALL be enabled.MediumCIS
CISA.MS.EXO.17.3Audit logs SHALL be maintained for at least the minimum duration dictated by OMB M-21-31 (Appendix C).MediumCIS
CISA.MS.EXO.2.1A list of approved IP addresses for sending mail SHALL be maintained.MediumCIS
CISA.MS.EXO.2.2An SPF policy SHALL be published for each domain, designating only these addresses as approved senders.MediumCIS
CISA.MS.EXO.3.1DKIM SHOULD be enabled for all domains.MediumCIS
CISA.MS.EXO.4.1A DMARC policy SHALL be published for every second-level domain.MediumCIS
CISA.MS.EXO.4.2The DMARC message rejection option SHALL be p=reject.MediumCIS
CISA.MS.EXO.4.3The DMARC point of contact for aggregate reports SHALL include reports@dmarc.cyber.dhs.gov.MediumCIS
CISA.MS.EXO.5.1SMTP AUTH SHALL be disabled.MediumCIS
CISA.MS.EXO.6.1Contact folders SHALL NOT be shared with all domains.MediumCIS
CISA.MS.EXO.6.2Calendar details SHALL NOT be shared with all domains.MediumCIS
CISA.MS.EXO.7.1External sender warnings SHALL be implemented.MediumCIS
CISA.MS.EXO.8.1A DLP solution SHALL be used.MediumCIS
CISA.MS.EXO.8.2The DLP solution SHALL protect personally identifiable information (PII) and sensitive information, as defined by the agency.MediumCIS
CISA.MS.EXO.8.3The selected DLP solution SHOULD offer services comparable to the native DLP solution offered by Microsoft.MediumCIS
CISA.MS.EXO.8.4At a minimum, the DLP solution SHALL restrict sharing credit card numbers, U.S. Individual Taxpayer Identification Numbers (ITIN), and U.S. Social Security numbers (SSN) via email.MediumCIS
CISA.MS.EXO.9.1Emails SHALL be filtered by attachment file types.MediumCIS
CISA.MS.EXO.9.2The attachment filter SHOULD attempt to determine the true file type and assess the file extension.MediumCIS
CISA.MS.EXO.9.3Disallowed file types SHALL be determined and enforced.MediumCIS
CISA.MS.EXO.9.4Alternatively chosen filtering solutions SHOULD offer services comparable to Microsoft Defender's Common Attachment Filter.MediumCIS
CISA.MS.EXO.9.5At a minimum, click-to-run files SHOULD be blocked (e.g., .exe, .cmd, and .vbe).MediumCIS
CISA.MS.SHAREPOINT.1.1External sharing for SharePoint SHALL be limited to Existing guests or Only People in your organization.MediumCIS
CISA.MS.SHAREPOINT.1.3External sharing SHALL be restricted to approved external domains and/or users in approved security groups per interagency collaboration needs.MediumCIS
M365.2102Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is EnabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2103Ensure Safe Attachments policy is enabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2104Ensure Safe Links for Office Applications is EnabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2106Ensure the connection filter IP allow list is not usedMediumCIS Microsoft 365 Foundations Benchmark
M365.2107Ensure the connection filter safe list is offMediumCIS Microsoft 365 Foundations Benchmark
M365.2108Ensure Exchange Online Spam Policies are set to notify administratorsMediumCIS Microsoft 365 Foundations Benchmark
M365.2109Ensure inbound anti-spam policies do not contain allowed domainsMediumCIS Microsoft 365 Foundations Benchmark
M365.2110Ensure Microsoft Defender for Cloud Apps is enabled and configuredLowCIS Microsoft 365 Foundations Benchmark
M365.2111Ensure Zero-hour auto purge for Microsoft Teams is onMediumCIS Microsoft 365 Foundations Benchmark
M365.2112Ensure that DKIM is enabled for all Exchange Online DomainsMediumCIS Microsoft 365 Foundations Benchmark
M365.2113Ensure DMARC Records for all Exchange Online domains are publishedMediumCIS Microsoft 365 Foundations Benchmark
M365.2114Ensure that SPF records are published for all Exchange DomainsMediumCIS Microsoft 365 Foundations Benchmark
M365.2115Ensure that an anti-phishing policy has been createdMediumCIS Microsoft 365 Foundations Benchmark
M365.2116Ensure 'AuditDisabled' organizationally is set to 'False'MediumCIS Microsoft 365 Foundations Benchmark
M365.2117Ensure 'External sharing' of calendars is not availableMediumCIS Microsoft 365 Foundations
M365.2118Ensure the customer lockbox feature is enabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2119Ensure MailTips are enabled for end usersMediumCIS Microsoft 365 Foundations Benchmark
M365.2120Ensure modern authentication for Exchange Online is enabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2121Ensure additional storage providers are restricted in Outlook on the webMediumCIS Microsoft 365 Foundations Benchmark
M365.2122Ensure Priority account protection is enabled and configuredMediumCIS Microsoft 365 Foundations Benchmark
M365.2123Ensure Priority accounts have 'Strict protection' presets appliedMediumCIS Microsoft 365 Foundations Benchmark
M365.2124Ensure users installing Outlook add-ins is not allowedMediumCIS Microsoft 365 Foundations Benchmark
M365.2125Ensure 'third-party storage services' are restricted in 'Microsoft 365 on the web'LowCIS Microsoft 365 Foundations Benchmark
M365.2126Ensure email from external senders is identifiedMediumCIS Microsoft 365 Foundations Benchmark
M365.2127Ensure all forms of mail forwarding are blocked and/or disabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2128Ensure mail transport rules do not whitelist specific domainsMediumCIS Microsoft 365 Foundations Benchmark
M365.2129Ensure SMTP AUTH is disabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2130Ensure the Common Attachment Types Filter is enabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2131Ensure comprehensive attachment filtering is appliedLowCIS Microsoft 365 Foundations Benchmark
M365.2132Ensure notifications for internal users sending malware is EnabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2133Ensure Zero-hour auto purge for Microsoft Teams is onMediumCIS Microsoft 365 Foundations Benchmark
M365.2134Ensure the Account Provisioning Activity report is reviewed at least weeklyLowCIS Microsoft 365 Foundations Benchmark
M365.2135Ensure mail forwarding rules are reviewed at least weeklyMediumCIS Microsoft 365 Foundations Benchmark
M365.2136Ensure malware trends are reviewed at least weeklyLowCIS Microsoft 365 Foundations Benchmark
M365.2137Ensure the Account Provisioning Activity report is reviewed at least weeklyLowCIS Microsoft 365 Foundations Benchmark
M365.2138Ensure the 'Restricted entities' report is reviewed weeklyLowCIS Microsoft 365 Foundations Benchmark
M365.2139Ensure the spoofed domains report is reviewed weeklyLowCIS Microsoft 365 Foundations Benchmark
M365.2140Ensure 'AuditBypassEnabled' is not enabled on mailboxesMediumCIS Microsoft 365 Foundations Benchmark
M365.2143Ensure 'User owned apps and services' is restrictedLowCIS Microsoft 365 Foundations Benchmark
M365.2144Ensure emergency access account activity is monitoredMediumCIS Microsoft 365 Foundations Benchmark
M365.2145Ensure 'Allow users to apply sensitivity labels for content' is 'Enabled'MediumCIS Microsoft 365 Foundations Benchmark
M365.2146Ensure 'Block ResourceKey Authentication' is 'Enabled'MediumCIS Microsoft 365 Foundations Benchmark
M365.2147Ensure enabling of external data sharing is restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2148Ensure external user invitations are restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2149Ensure guest access to content is restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2150Ensure guest user access is restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2151Ensure 'Interact with and share R and Python' visuals is 'Disabled'MediumCIS Microsoft 365 Foundations Benchmark
M365.2152Ensure 'Publish to web' is restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2153Ensure shareable links are restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2154Ensure access to APIs by Service Principals is restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2155Ensure Service Principals cannot create and use profilesMediumCIS Microsoft 365 Foundations Benchmark
M365.2156Ensure internal phishing protection for Forms is enabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2157Ensure device enrollment for personally owned devices is blocked by defaultMediumCIS Microsoft 365 Foundations Benchmark
M365.2158Ensure devices without a compliance policy are marked 'not compliant'MediumCIS Microsoft 365 Foundations Benchmark
M365.2159Ensure DLP policies are enabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2160Ensure DLP policies are enabled for Microsoft TeamsMediumCIS Microsoft 365 Foundations Benchmark
M365.2161Ensure Microsoft 365 audit log search is EnabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2163Ensure user role group changes are reviewed at least weeklyLowCIS Microsoft 365 Foundations Benchmark
M365.2164Ensure that Sways cannot be shared with people outside of your organizationMediumCIS Microsoft 365 Foundations Benchmark
M365.2165Ensure anonymous users and dial-in callers can't start a meetingMediumCIS Microsoft 365 Foundations Benchmark
M365.2166Ensure anonymous users can't join a meetingMediumCIS Microsoft 365 Foundations Benchmark
M365.2167Ensure app permission policies are configuredMediumCIS Microsoft 365 Foundations Benchmark
M365.2168Ensure users can't send emails to a channel email addressMediumCIS Microsoft 365 Foundations Benchmark
M365.2169Ensure 'external access' is restricted in the Teams admin centerMediumCIS Microsoft 365 Foundations Benchmark
M365.2170Ensure external domains are restricted in the Teams admin centerMediumCIS Microsoft 365 Foundations Benchmark
M365.2171Ensure external file sharing in Teams is enabled for only approved cloud storage servicesMediumCIS Microsoft 365 Foundations Benchmark
M365.2172Ensure external meeting chat is offMediumCIS Microsoft 365 Foundations Benchmark
M365.2173Ensure external participants can't give or request controlMediumCIS Microsoft 365 Foundations Benchmark
M365.2174Ensure meeting chat does not allow anonymous usersMediumCIS Microsoft 365 Foundations Benchmark
M365.2175Ensure only people in my org can bypass the lobbyMediumCIS Microsoft 365 Foundations Benchmark
M365.2176Ensure only organizers and co-organizers can presentMediumCIS Microsoft 365 Foundations Benchmark
M365.2177Ensure users can report security concerns in TeamsMediumCIS Microsoft 365 Foundations Benchmark
M365.2178Ensure users dialing in can't bypass the lobbyMediumCIS Microsoft 365 Foundations Benchmark
M365.2179Ensure communication with Skype users is disabledMediumCIS Microsoft 365 Foundations Benchmark
M365.2180Ensure external Teams users cannot initiate conversationsMediumCIS Microsoft 365 Foundations Benchmark
M365.2181Ensure meeting recording is off by defaultMediumCIS Microsoft 365 Foundations Benchmark
M365.2182Ensure SharePoint and OneDrive integration with Azure AD B2B is enabledLowCIS Microsoft 365 Foundations Benchmark
M365.2183Ensure custom script execution is restricted on site collectionsMediumCIS Microsoft 365 Foundations Benchmark
M365.2184Ensure custom script execution is restricted on personal sitesMediumCIS Microsoft 365 Foundations Benchmark
M365.2185Ensure external content sharing is restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2186Ensure SharePoint external sharing is managed through domain allow/deny listsMediumCIS Microsoft 365 Foundations Benchmark
M365.2187Ensure external sharing is restricted by security groupMediumCIS Microsoft 365 Foundations Benchmark
M365.2188Ensure guest access to a site or OneDrive will expire automaticallyMediumCIS Microsoft 365 Foundations Benchmark
M365.2189Ensure that SharePoint guest users cannot share items they don't ownMediumCIS Microsoft 365 Foundations Benchmark
M365.2190Ensure link sharing is restricted in SharePoint and OneDriveMediumCIS Microsoft 365 Foundations Benchmark
M365.2191Ensure Office 365 SharePoint infected files are disallowed for downloadMediumCIS Microsoft 365 Foundations Benchmark
M365.2192Ensure modern authentication for SharePoint applications is requiredMediumCIS Microsoft 365 Foundations Benchmark
M365.2193Ensure OneDrive content sharing is restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2194Ensure OneDrive sync is restricted for unmanaged devicesMediumCIS Microsoft 365 Foundations Benchmark
M365.2195Ensure reauthentication with verification code is restrictedMediumCIS Microsoft 365 Foundations Benchmark
M365.2196Ensure the SharePoint default sharing link permission is setMediumCIS Microsoft 365 Foundations Benchmark
ORCA.100Bulk Complaint Level threshold is between 4 and 6.MediumOther
ORCA.101Bulk is marked as spam.MediumOther
ORCA.102Advanced Spam filter options are turned off.MediumOther
ORCA.103Outbound spam filter policy settings configured.MediumOther
ORCA.104High Confidence Phish action set to Quarantine message.MediumOther
ORCA.105Safe Links Synchronous URL detonation is enabled.MediumOther
ORCA.106Quarantine retention period is 30 days.MediumOther
ORCA.107End-user spam notification is enabled.MediumOther
ORCA.108DKIM signing is set up for all your custom domains.MediumOther
ORCA.108.1DNS Records have been set up to support DKIM.MediumOther
ORCA.109Senders are not being allow listed in an unsafe manner.MediumOther
ORCA.110Internal Sender notifications are disabled.MediumOther
ORCA.111Anti-phishing policy exists and EnableUnauthenticatedSender is true.MediumOther
ORCA.112Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy.MediumOther
ORCA.113AllowClickThrough is disabled in Safe Links policies.MediumOther
ORCA.114No IP Allow Lists have been configured.MediumOther
ORCA.115Mailbox intelligence based impersonation protection is enabled in anti-phishing policies.MediumOther
ORCA.116Mailbox intelligence based impersonation protection action set to move message to junk mail folder.MediumOther
ORCA.118.1Domains are not being allow listed in an unsafe manner in Anti-Spam Policies.MediumOther
ORCA.118.2Domains are not being allow listed in an unsafe manner in Transport Rules.MediumOther
ORCA.118.3Your own domains are not being allow listed in an unsafe manner in Anti-Spam Policies.MediumOther
ORCA.118.4Your own domains are not being allow listed in an unsafe manner in Transport Rules.MediumOther
ORCA.119Similar Domains Safety Tips is enabled.MediumOther
ORCA.120.1Zero Hour Autopurge Enabled for Phish.MediumOther
ORCA.120.2Zero Hour Autopurge Enabled for Malware.MediumOther
ORCA.120.3Zero Hour Autopurge Enabled for Spam.MediumOther
ORCA.121Supported filter policy action used.MediumOther
ORCA.123Unusual Characters Safety Tips is enabled.MediumOther
ORCA.124Safe attachments unknown malware response set to block messages.MediumOther
ORCA.139Spam action set to move message to junk mail folder or quarantine.MediumOther
ORCA.140High Confidence Spam action set to Quarantine message.MediumOther
ORCA.141Bulk action set to Move message to Junk Email Folder.MediumOther
ORCA.142Phish action set to Quarantine message.MediumOther
ORCA.143Safety Tips are enabled.MediumOther
ORCA.156Safe Links Policies are tracking when user clicks on safe links.MediumOther
ORCA.158Safe Attachments is enabled for SharePoint and Teams.MediumOther
ORCA.179Safe Links is enabled intra-organization.MediumOther
ORCA.180Anti-phishing policy exists and EnableSpoofIntelligence is true.MediumOther
ORCA.189Safe Attachments is not bypassed.MediumOther
ORCA.189.2Safe Links is not bypassed.MediumOther
ORCA.205Common attachment type filter is enabled.MediumOther
ORCA.220Advanced Phish filter Threshold level is adequate.MediumOther
ORCA.221Mailbox intelligence is enabled in anti-phishing policies.MediumOther
ORCA.222Domain Impersonation action is set to move to Quarantine.MediumOther
ORCA.223User impersonation action is set to move to Quarantine.MediumOther
ORCA.224Similar Users Safety Tips is enabled.MediumOther
ORCA.225Safe Documents is enabled for Office clients.MediumOther
ORCA.226Each domain has a Safe Link policy applied to it.MediumOther
ORCA.227Each domain has a Safe Attachments policy applied to it.MediumOther
ORCA.228No trusted senders in Anti-phishing policy.MediumOther
ORCA.229No trusted domains in Anti-phishing policy.MediumOther
ORCA.230Each domain has a Anti-phishing policy applied to it, or the default policy is being used.MediumOther
ORCA.231Each domain has a anti-spam policy applied to it, or the default policy is being used.MediumOther
ORCA.232Each domain has a malware filter policy applied to it, or the default policy is being used.MediumOther
ORCA.233Domains are pointed directly at EOP or enhanced filtering is used.MediumOther
ORCA.233.1Domains are pointed directly at EOP or enhanced filtering is configured on all default connectors.MediumOther
ORCA.234Click through is disabled for Safe Documents.MediumOther
ORCA.235SPF records is set up for all your custom domains.MediumOther
ORCA.236Safe Links is enabled for emails.MediumOther
ORCA.237Safe Links is enabled for teams messages.MediumOther
ORCA.238Safe Links is enabled for office documents.MediumOther
ORCA.239No exclusions for the built-in protection policies.MediumOther
ORCA.240Outlook is configured to display external tags for external emails.MediumOther
ORCA.241Anti-phishing policy exists and EnableFirstContactSafetyTips is true.MediumOther
ORCA.242Important protection alerts responsible for AIR activities are enabled.MediumOther
ORCA.243Authenticated Receive Chain is set up for domains not pointing to EOP/MDO, or all domains point to EOP/MDO.MediumOther
ORCA.244Policies are configured to honor sending domains DMARC.MediumOther
readmeEntra ID - Security Config Analyzer TestsMediumOther
War diese Seite hilfreich?