Skip to content

Microsoft Entra ID Security Checks

All security checks Aether365 performs for Microsoft Entra ID.

IDTitleSeverityFramework
AE.1068Restrict non-admin users from creating tenants.MediumOther
AE.1069Restrict non-admin users from creating security groups.MediumOther
AE.1070Restrict device join to selected users/groups or none.MediumOther
AE.1077App registrations with privileged API permissions should have no ownersMediumOther
AE.1078App registrations with highly privileged directory roles should not have ownersMediumOther
AE.1079Privileged API permissions on service principals should not remain unusedMediumOther
AE.1080Credentials, tokens, or cookies from highly privileged users should not be exposed on vulnerable endpointsMediumOther
AE.1081Hybrid users should not be assigned Entra ID role assignmentsMediumOther
AE.1084Seamless Single SignOn should be disabled for all domains in EntraID Connect servers.MediumOther
AE.1085Pending approvals for Critical Asset Management should not be presentMediumOther
AE.1090Global administrator role should not be added as local administrator on the device during Microsoft Entra joinMediumOther
AE.1091Registering user should not be added as local administrator on the device during Microsoft Entra joinMediumOther
AE.1106Catalog resources must have valid roles (no stale / removed app roles or SPNs)MediumOther
AE.1107Access packages and catalogs should not reference deleted groupsMediumOther
AE.1108Access packages should not reference inactive or orphaned assignment policiesMediumOther
AE.1109Access package approval workflows must have valid approversMediumOther
AE.1110No catalog should contain resources without any associated access packagesMediumOther
AE.1111High privileged user should be linked to an identity.MediumOther
AE.1112Privileged user accounts should not remain enabled when the linked primary account is disabled.MediumOther
CISA.MS.AAD.1.1Legacy authentication SHALL be blocked.MediumCIS
CISA.MS.AAD.2.1Users detected as high risk SHALL be blocked.MediumCIS
CISA.MS.AAD.2.2A notification SHOULD be sent to the administrator when high-risk users are detected.MediumCIS
CISA.MS.AAD.2.3Sign-ins detected as high risk SHALL be blocked.MediumCIS
CISA.MS.AAD.3.1Phishing-resistant MFA SHALL be enforced for all users.MediumCIS
CISA.MS.AAD.3.2If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.MediumCIS
CISA.MS.AAD.3.3If Microsoft Authenticator is enabled, it SHALL be configured to show login context information.MediumCIS
CISA.MS.AAD.3.4The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.MediumCIS
CISA.MS.AAD.3.5The authentication methods SMS, Voice Call, and Email One-Time Passcode (OTP) SHALL be disabled.MediumCIS
CISA.MS.AAD.3.6Phishing-resistant MFA SHALL be required for highly privileged roles.MediumCIS
CISA.MS.AAD.3.7Managed devices SHOULD be required for authentication.MediumCIS
CISA.MS.AAD.3.8Managed Devices SHOULD be required to register MFA.MediumCIS
CISA.MS.AAD.4.1Security logs SHALL be sent to the agency's security operations center for monitoring.MediumCIS
CISA.MS.AAD.5.1Only administrators SHALL be allowed to register applications.MediumCIS
CISA.MS.AAD.5.2Only administrators SHALL be allowed to consent to applications.MediumCIS
CISA.MS.AAD.5.3An admin consent workflow SHALL be configured for applications.MediumCIS
CISA.MS.AAD.5.4Group owners SHALL NOT be allowed to consent to applications.MediumCIS
CISA.MS.AAD.6.1User passwords SHALL NOT expire.MediumCIS
CISA.MS.AAD.7.1A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role.MediumCIS
CISA.MS.AAD.7.2Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.MediumCIS
CISA.MS.AAD.7.3Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers.MediumCIS
CISA.MS.AAD.7.4Permanent active role assignments SHALL NOT be allowed for highly privileged roles.MediumCIS
CISA.MS.AAD.7.5Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system.MediumCIS
CISA.MS.AAD.7.6Activation of the Global Administrator role SHALL require approval.MediumCIS
CISA.MS.AAD.7.7Eligible and Active highly privileged role assignments SHALL trigger an alert.MediumCIS
CISA.MS.AAD.7.8User activation of the Global Administrator role SHALL trigger an alert.MediumCIS
CISA.MS.AAD.7.9User activation of other highly privileged roles SHOULD trigger an alert.MediumCIS
CISA.MS.AAD.8.1Guest users SHOULD have limited or restricted access to Entra ID directory objects.MediumCIS
CISA.MS.AAD.8.2Only users with the Guest Inviter role SHOULD be able to invite guest users.MediumCIS
CISA.MS.AAD.8.3Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes.MediumCIS
EIDSCA.AF01Authentication Method - FIDO2 security key - StateMediumEIDSCA
EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set upMediumEIDSCA
EIDSCA.AF03Authentication Method - FIDO2 security key - Enforce attestationMediumEIDSCA
EIDSCA.AF04Authentication Method - FIDO2 security key - Enforce key restrictionsMediumEIDSCA
EIDSCA.AF05Authentication Method - FIDO2 security key - RestrictedMediumEIDSCA
EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keysMediumEIDSCA
EIDSCA.AG01Authentication Method - General Settings - Manage migrationMediumEIDSCA
EIDSCA.AG02Authentication Method - General Settings - Report suspicious activity - StateMediumEIDSCA
EIDSCA.AG03Authentication Method - General Settings - Report suspicious activity - Included users/groupsMediumEIDSCA
EIDSCA.AM01Authentication Method - Microsoft Authenticator - StateMediumEIDSCA
EIDSCA.AM02Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTPMediumEIDSCA
EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notificationsMediumEIDSCA
EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notificationsMediumEIDSCA
EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notificationsMediumEIDSCA
EIDSCA.AM07Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notificationsMediumEIDSCA
EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notificationsMediumEIDSCA
EIDSCA.AM10Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notificationsMediumEIDSCA
EIDSCA.AP01Default Authorization Settings - Enabled Self service password reset for administratorsMediumEIDSCA
EIDSCA.AP04Default Authorization Settings - Guest invite restrictionsMediumEIDSCA
EIDSCA.AP05Default Authorization Settings - Sign-up for email based subscriptionMediumEIDSCA
EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validationMediumEIDSCA
EIDSCA.AP07Default Authorization Settings - Guest user accessMediumEIDSCA
EIDSCA.AP08Default Authorization Settings - User consent policy assigned for applicationsMediumEIDSCA
EIDSCA.AP09Default Authorization Settings - Allow user consent on risk-based appsMediumEIDSCA
EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create AppsMediumEIDSCA
EIDSCA.AP14Default Authorization Settings - Default User Role Permissions - Allowed to read other usersMediumEIDSCA
EIDSCA.AS04Authentication Method - SMS - Use for sign-inMediumEIDSCA
EIDSCA.AT01Authentication Method - Temporary Access Pass - StateMediumEIDSCA
EIDSCA.AT02Authentication Method - Temporary Access Pass - One-timeMediumEIDSCA
EIDSCA.AV01Authentication Method - Voice call - StateMediumEIDSCA
EIDSCA.CP01Default Settings - Consent Policy Settings - Group owner consent for apps accessing dataMediumEIDSCA
EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky appsMediumEIDSCA
EIDSCA.CP04Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent toMediumEIDSCA
EIDSCA.CR01Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request featureMediumEIDSCA
EIDSCA.CR02Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requestsMediumEIDSCA
EIDSCA.CR03Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expireMediumEIDSCA
EIDSCA.CR04Consent Framework - Admin Consent Request - Consent request duration (days)MediumEIDSCA
EIDSCA.PR01Default Settings - Password Rule Settings - Password Protection - ModeMediumEIDSCA
EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active DirectoryMediumEIDSCA
EIDSCA.PR03Default Settings - Password Rule Settings - Enforce custom listMediumEIDSCA
EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in secondsMediumEIDSCA
EIDSCA.PR06Default Settings - Password Rule Settings - Smart Lockout - Lockout thresholdMediumEIDSCA
EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group OwnerMediumEIDSCA
EIDSCA.ST09Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups contentMediumEIDSCA
ENTRA.1101Ensure 'User consent for applications' Is Set To 'Allow for Verified Publishers'MediumCIS Microsoft Azure Foundations
ENTRA.1102Ensure 'User consent for applications' is set to 'Do not allow user consent'MediumCIS Microsoft Azure Foundations
ENTRA.1103Ensure That 'Users Can Register Applications' Is Set to 'No'MediumCIS Microsoft Azure Foundations
ENTRA.1104Ensure the admin consent workflow is enabledMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1106Ensure Multi-factor Authentication is Required to access Microsoft Admin PortalsMediumCIS Microsoft Azure Foundations
ENTRA.1107Ensure Multi-factor Authentication is Required for Azure ManagementMediumCIS Microsoft Azure Foundations
ENTRA.1108Ensure multifactor authentication is enabled for all users in administrative rolesMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1109Ensure Multi-factor Authentication is Required for Risky Sign-insMediumCIS Microsoft Azure Foundations
ENTRA.1110Ensure multifactor authentication is enabled for all usersMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1111Ensure that an exclusionary Device code flow policy is consideredMediumCIS Microsoft Azure Foundations
ENTRA.1112Ensure that an exclusionary Geographic Access Policy is consideredMediumCIS Microsoft Azure Foundations
ENTRA.1113Ensure 'Idle session timeout' is set to '3 hours (or less)' for unmanaged devicesMediumCIS Microsoft Azure Foundations
ENTRA.1114Ensure Trusted Locations Are DefinedMediumCIS Microsoft Azure Foundations
ENTRA.1115Enable Azure AD Identity Protection sign-in risk policiesMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1116Enable Conditional Access policies to block legacy authenticationMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1117Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative usersMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1118Enable Identity Protection sign-in risk policiesMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1119Enable Entra ID Identity Protection user risk policiesMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1120Ensure that a phishing-resistant Multi-factor Authentication Policy Exists for High-Privileged UsersMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1123Ensure 'LinkedIn account connections' is disabledLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1124Ensure that 'Restrict non-admin users from creating tenants' is set to 'Yes'MediumCIS Microsoft Azure Foundations
ENTRA.1125Ensure that 'Require Multifactor Authentication to register or join devices with Microsoft Entra' is set to 'Yes'MediumCIS Microsoft Azure Foundations
ENTRA.1126Ensure That 'Restrict access to Microsoft Entra admin center' is Set to 'Yes'MediumCIS Microsoft Azure Foundations
ENTRA.1127Ensure that password hash sync is enabled for hybrid deploymentsMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1128Ensure approval is required for Global Administrator role activationMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1129Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No'MediumCIS Microsoft Azure Foundations
ENTRA.1130Ensure that 'Restrict user ability to access groups features in the Access Pane' is Set to 'Yes'MediumCIS Microsoft Azure Foundations
ENTRA.1131Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No'MediumCIS Microsoft Azure Foundations
ENTRA.1132Ensure that 'Users can create security groups in Azure portals, API or PowerShell' is set to 'No'MediumCIS Microsoft Azure Foundations
ENTRA.1134Ensure that only organizationally managed/approved public groups existMediumCIS Microsoft Azure Foundations
ENTRA.1135Ensure that 'Guest invite restrictions' is set to 'Only users assigned to specific admin roles can invite guest users'MediumCIS Microsoft Azure Foundations
ENTRA.1136Ensure that guest user access is restrictedMediumCIS Microsoft Azure Foundations
ENTRA.1137Ensure 'Access reviews' for Guest Users are configuredLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1138Ensure Guest Users are reviewed at least biweeklyMediumCIS Microsoft Azure Foundations
ENTRA.1139Ensure fewer than ARG_0 users have global administrator assignmentMediumCIS Microsoft Microsoft 365 Foundations
ENTRA.1140Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Privileged UsersMediumCIS Microsoft Azure Foundations
ENTRA.1141Ensure administrative accounts use licenses with a reduced application footprintMediumCIS Microsoft Azure Foundations
ENTRA.1142Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged UsersMediumCIS Microsoft Azure Foundations
ENTRA.1143Ensure two emergency access accounts have been definedMediumCIS Microsoft Azure Foundations
ENTRA.1144Ensure 'Access reviews' for high privileged Entra ID roles are configuredLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1145Ensure Administrative accounts are separate and cloud-onlyMediumCIS Microsoft Microsoft 365 Foundations
ENTRA.1146Ensure Microsoft Authenticator is configured to protect against MFA fatigueMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1147Ensure all member users are 'MFA capable'MediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1148Ensure weak authentication methods are disabledMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1149Ensure 'Privileged Identity Management' is used to manage rolesMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1150Ensure that account 'Lockout duration in seconds' is greater than or equal to '60'LowCIS Microsoft Azure Foundations
ENTRA.1151Ensure that account 'Lockout Threshold' is less than or equal to '10'LowCIS Microsoft Azure Foundations
ENTRA.1153Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'MediumCIS Microsoft 365 Foundations
ENTRA.1154Ensure the option to remain signed in is hiddenLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1155Ensure password protection is enabled for on-prem Active DirectoryMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1156Ensure that collaboration invitations are sent to allowed domains onlyLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1157Ensure the Application Usage report is reviewed at least weeklyLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1158Ensure the Entra ID 'Risky sign-ins' report is reviewed at least weeklyLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1159Ensure the self-service password reset activity report is reviewed at least weeklyLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1160Ensure Security Defaults is enabled on Microsoft Entra IDMediumCIS Microsoft 365 Foundations
ENTRA.1161Ensure Security Defaults is enabled on Microsoft Entra IDMediumCIS Microsoft Azure Foundations Benchmark
ENTRA.1162Ensure that 'Allow users to remember multi-factor authentication on devices they trust' is DisabledMediumCIS Microsoft Azure Foundations
ENTRA.1163Ensure That 'Notify all admins when other admins reset their password?' is set to 'Yes'MediumCIS Microsoft Azure Foundations
ENTRA.1164Ensure that 'Notify users on password resets?' is set to 'Yes'MediumCIS Microsoft Azure Foundations
ENTRA.1165Ensure that 'Number of days before users are asked to reconfirm their authentication information' is not set to '0'MediumCIS Microsoft Azure Foundations
ENTRA.1166Ensure That 'Number of methods required to reset' is set to '2'MediumCIS Microsoft Azure Foundations
ENTRA.1167Ensure 'Self service password reset enabled' is set to 'All'MediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1168Ensure 'Per-user MFA' is disabledLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1170Ensure administrative accounts use licenses with a reduced application footprintMediumCIS Microsoft Azure Foundations
ENTRA.1171Ensure 'User owned apps and services' is restrictedLowCIS Microsoft 365 Foundations Benchmark
ENTRA.1173Ensure the device code sign-in flow is blockedMediumCIS Microsoft 365 Foundations Benchmark
ENTRA.1174Ensure approval is required for Privileged Role Administrator activationMediumCIS Microsoft 365 Foundations Benchmark
M365.2197Ensure sign-in to shared mailboxes is blockedMediumCIS Microsoft Azure Foundations
Kas sellest lehest oli abi?