Microsoft Entra ID Security Checks
All security checks Aether365 performs for Microsoft Entra ID.
| ID | Title | Severity | Framework |
|---|---|---|---|
| AE.1068 | Restrict non-admin users from creating tenants. | Medium | Other |
| AE.1069 | Restrict non-admin users from creating security groups. | Medium | Other |
| AE.1070 | Restrict device join to selected users/groups or none. | Medium | Other |
| AE.1077 | App registrations with privileged API permissions should have no owners | Medium | Other |
| AE.1078 | App registrations with highly privileged directory roles should not have owners | Medium | Other |
| AE.1079 | Privileged API permissions on service principals should not remain unused | Medium | Other |
| AE.1080 | Credentials, tokens, or cookies from highly privileged users should not be exposed on vulnerable endpoints | Medium | Other |
| AE.1081 | Hybrid users should not be assigned Entra ID role assignments | Medium | Other |
| AE.1084 | Seamless Single SignOn should be disabled for all domains in EntraID Connect servers. | Medium | Other |
| AE.1085 | Pending approvals for Critical Asset Management should not be present | Medium | Other |
| AE.1090 | Global administrator role should not be added as local administrator on the device during Microsoft Entra join | Medium | Other |
| AE.1091 | Registering user should not be added as local administrator on the device during Microsoft Entra join | Medium | Other |
| AE.1106 | Catalog resources must have valid roles (no stale / removed app roles or SPNs) | Medium | Other |
| AE.1107 | Access packages and catalogs should not reference deleted groups | Medium | Other |
| AE.1108 | Access packages should not reference inactive or orphaned assignment policies | Medium | Other |
| AE.1109 | Access package approval workflows must have valid approvers | Medium | Other |
| AE.1110 | No catalog should contain resources without any associated access packages | Medium | Other |
| AE.1111 | High privileged user should be linked to an identity. | Medium | Other |
| AE.1112 | Privileged user accounts should not remain enabled when the linked primary account is disabled. | Medium | Other |
| CISA.MS.AAD.1.1 | Legacy authentication SHALL be blocked. | Medium | CIS |
| CISA.MS.AAD.2.1 | Users detected as high risk SHALL be blocked. | Medium | CIS |
| CISA.MS.AAD.2.2 | A notification SHOULD be sent to the administrator when high-risk users are detected. | Medium | CIS |
| CISA.MS.AAD.2.3 | Sign-ins detected as high risk SHALL be blocked. | Medium | CIS |
| CISA.MS.AAD.3.1 | Phishing-resistant MFA SHALL be enforced for all users. | Medium | CIS |
| CISA.MS.AAD.3.2 | If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users. | Medium | CIS |
| CISA.MS.AAD.3.3 | If Microsoft Authenticator is enabled, it SHALL be configured to show login context information. | Medium | CIS |
| CISA.MS.AAD.3.4 | The Authentication Methods Manage Migration feature SHALL be set to Migration Complete. | Medium | CIS |
| CISA.MS.AAD.3.5 | The authentication methods SMS, Voice Call, and Email One-Time Passcode (OTP) SHALL be disabled. | Medium | CIS |
| CISA.MS.AAD.3.6 | Phishing-resistant MFA SHALL be required for highly privileged roles. | Medium | CIS |
| CISA.MS.AAD.3.7 | Managed devices SHOULD be required for authentication. | Medium | CIS |
| CISA.MS.AAD.3.8 | Managed Devices SHOULD be required to register MFA. | Medium | CIS |
| CISA.MS.AAD.4.1 | Security logs SHALL be sent to the agency's security operations center for monitoring. | Medium | CIS |
| CISA.MS.AAD.5.1 | Only administrators SHALL be allowed to register applications. | Medium | CIS |
| CISA.MS.AAD.5.2 | Only administrators SHALL be allowed to consent to applications. | Medium | CIS |
| CISA.MS.AAD.5.3 | An admin consent workflow SHALL be configured for applications. | Medium | CIS |
| CISA.MS.AAD.5.4 | Group owners SHALL NOT be allowed to consent to applications. | Medium | CIS |
| CISA.MS.AAD.6.1 | User passwords SHALL NOT expire. | Medium | CIS |
| CISA.MS.AAD.7.1 | A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role. | Medium | CIS |
| CISA.MS.AAD.7.2 | Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator. | Medium | CIS |
| CISA.MS.AAD.7.3 | Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers. | Medium | CIS |
| CISA.MS.AAD.7.4 | Permanent active role assignments SHALL NOT be allowed for highly privileged roles. | Medium | CIS |
| CISA.MS.AAD.7.5 | Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system. | Medium | CIS |
| CISA.MS.AAD.7.6 | Activation of the Global Administrator role SHALL require approval. | Medium | CIS |
| CISA.MS.AAD.7.7 | Eligible and Active highly privileged role assignments SHALL trigger an alert. | Medium | CIS |
| CISA.MS.AAD.7.8 | User activation of the Global Administrator role SHALL trigger an alert. | Medium | CIS |
| CISA.MS.AAD.7.9 | User activation of other highly privileged roles SHOULD trigger an alert. | Medium | CIS |
| CISA.MS.AAD.8.1 | Guest users SHOULD have limited or restricted access to Entra ID directory objects. | Medium | CIS |
| CISA.MS.AAD.8.2 | Only users with the Guest Inviter role SHOULD be able to invite guest users. | Medium | CIS |
| CISA.MS.AAD.8.3 | Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes. | Medium | CIS |
| EIDSCA.AF01 | Authentication Method - FIDO2 security key - State | Medium | EIDSCA |
| EIDSCA.AF02 | Authentication Method - FIDO2 security key - Allow self-service set up | Medium | EIDSCA |
| EIDSCA.AF03 | Authentication Method - FIDO2 security key - Enforce attestation | Medium | EIDSCA |
| EIDSCA.AF04 | Authentication Method - FIDO2 security key - Enforce key restrictions | Medium | EIDSCA |
| EIDSCA.AF05 | Authentication Method - FIDO2 security key - Restricted | Medium | EIDSCA |
| EIDSCA.AF06 | Authentication Method - FIDO2 security key - Restrict specific keys | Medium | EIDSCA |
| EIDSCA.AG01 | Authentication Method - General Settings - Manage migration | Medium | EIDSCA |
| EIDSCA.AG02 | Authentication Method - General Settings - Report suspicious activity - State | Medium | EIDSCA |
| EIDSCA.AG03 | Authentication Method - General Settings - Report suspicious activity - Included users/groups | Medium | EIDSCA |
| EIDSCA.AM01 | Authentication Method - Microsoft Authenticator - State | Medium | EIDSCA |
| EIDSCA.AM02 | Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP | Medium | EIDSCA |
| EIDSCA.AM03 | Authentication Method - Microsoft Authenticator - Require number matching for push notifications | Medium | EIDSCA |
| EIDSCA.AM04 | Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications | Medium | EIDSCA |
| EIDSCA.AM06 | Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications | Medium | EIDSCA |
| EIDSCA.AM07 | Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications | Medium | EIDSCA |
| EIDSCA.AM09 | Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications | Medium | EIDSCA |
| EIDSCA.AM10 | Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications | Medium | EIDSCA |
| EIDSCA.AP01 | Default Authorization Settings - Enabled Self service password reset for administrators | Medium | EIDSCA |
| EIDSCA.AP04 | Default Authorization Settings - Guest invite restrictions | Medium | EIDSCA |
| EIDSCA.AP05 | Default Authorization Settings - Sign-up for email based subscription | Medium | EIDSCA |
| EIDSCA.AP06 | Default Authorization Settings - User can join the tenant by email validation | Medium | EIDSCA |
| EIDSCA.AP07 | Default Authorization Settings - Guest user access | Medium | EIDSCA |
| EIDSCA.AP08 | Default Authorization Settings - User consent policy assigned for applications | Medium | EIDSCA |
| EIDSCA.AP09 | Default Authorization Settings - Allow user consent on risk-based apps | Medium | EIDSCA |
| EIDSCA.AP10 | Default Authorization Settings - Default User Role Permissions - Allowed to create Apps | Medium | EIDSCA |
| EIDSCA.AP14 | Default Authorization Settings - Default User Role Permissions - Allowed to read other users | Medium | EIDSCA |
| EIDSCA.AS04 | Authentication Method - SMS - Use for sign-in | Medium | EIDSCA |
| EIDSCA.AT01 | Authentication Method - Temporary Access Pass - State | Medium | EIDSCA |
| EIDSCA.AT02 | Authentication Method - Temporary Access Pass - One-time | Medium | EIDSCA |
| EIDSCA.AV01 | Authentication Method - Voice call - State | Medium | EIDSCA |
| EIDSCA.CP01 | Default Settings - Consent Policy Settings - Group owner consent for apps accessing data | Medium | EIDSCA |
| EIDSCA.CP03 | Default Settings - Consent Policy Settings - Block user consent for risky apps | Medium | EIDSCA |
| EIDSCA.CP04 | Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to | Medium | EIDSCA |
| EIDSCA.CR01 | Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature | Medium | EIDSCA |
| EIDSCA.CR02 | Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests | Medium | EIDSCA |
| EIDSCA.CR03 | Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire | Medium | EIDSCA |
| EIDSCA.CR04 | Consent Framework - Admin Consent Request - Consent request duration (days) | Medium | EIDSCA |
| EIDSCA.PR01 | Default Settings - Password Rule Settings - Password Protection - Mode | Medium | EIDSCA |
| EIDSCA.PR02 | Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory | Medium | EIDSCA |
| EIDSCA.PR03 | Default Settings - Password Rule Settings - Enforce custom list | Medium | EIDSCA |
| EIDSCA.PR05 | Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds | Medium | EIDSCA |
| EIDSCA.PR06 | Default Settings - Password Rule Settings - Smart Lockout - Lockout threshold | Medium | EIDSCA |
| EIDSCA.ST08 | Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner | Medium | EIDSCA |
| EIDSCA.ST09 | Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content | Medium | EIDSCA |